Skip to content
Compliance · SOC 2

SOC 2 controls and the receipts that map evidence to them.

Every SOC 2 control Déjà's control table lists, with the receipt types that map evidence to each. Where none does, the row says so: that control is evidenced outside Déjà. References and titles are from AICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria.

7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.

01 · Coverage

What a receipt covers, and what is not.

7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.

The common criteria, CC1 to CC9, of the Trust Services Criteria. The additional criteria for availability, processing integrity, confidentiality and privacy are not listed here, and are evidenced outside Déjà.

Edition
AICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria
Controls listed
33
A receipt type maps evidence
7
Evidenced outside Déjà
26

A receipt is evidence for a control, never the whole of it: the rest of each control is tested outside Déjà.

02 · Every control

SOC 2, in the standard's own words.

Control environment

0 of 5 with a receipt type

  • CC1.1Commitment to integrity and ethical valuesEvidenced outside Déjà
  • CC1.2Board independence and oversight of internal controlEvidenced outside Déjà
  • CC1.3Structures, reporting lines, authorities and responsibilitiesEvidenced outside Déjà
  • CC1.4Attracting, developing and retaining competent individualsEvidenced outside Déjà
  • CC1.5Accountability for internal control responsibilitiesEvidenced outside Déjà

Communication and information

1 of 3 with a receipt type

  • CC2.1Relevant, quality information to support internal controlEvidenced outside Déjà
  • CC2.2Internal communication of objectives and responsibilities for internal controlEvidenced by R1R2RG
  • CC2.3Communication with external partiesEvidenced outside Déjà

Risk assessment

0 of 4 with a receipt type

  • CC3.1Objectives specified clearly enough to identify and assess risksEvidenced outside Déjà
  • CC3.2Identification and analysis of risksEvidenced outside Déjà
  • CC3.3Potential for fraud in assessing risksEvidenced outside Déjà
  • CC3.4Changes that could significantly impact internal controlEvidenced outside Déjà

Monitoring activities

0 of 2 with a receipt type

  • CC4.1Ongoing and separate evaluations of internal controlEvidenced outside Déjà
  • CC4.2Evaluation and communication of internal control deficienciesEvidenced outside Déjà

Control activities

0 of 3 with a receipt type

  • CC5.1Control activities that mitigate risksEvidenced outside Déjà
  • CC5.2General control activities over technologyEvidenced outside Déjà
  • CC5.3Control activities deployed through policies and proceduresEvidenced outside Déjà

Logical and physical access controls

0 of 8 with a receipt type

  • CC6.1Logical access security software, infrastructure and architecturesEvidenced outside Déjà
  • CC6.2Registration and authorization of users, and removal of credentialsEvidenced outside Déjà
  • CC6.3Authorization, modification and removal of accessEvidenced outside Déjà
  • CC6.4Restriction of physical accessEvidenced outside Déjà
  • CC6.5Discontinuing protections over physical assetsEvidenced outside Déjà
  • CC6.6Protection against threats from outside system boundariesEvidenced outside Déjà
  • CC6.7Restriction of transmission, movement and removal of informationEvidenced outside Déjà
  • CC6.8Prevention or detection of unauthorized or malicious softwareEvidenced outside Déjà

System operations

4 of 5 with a receipt type

  • CC7.1Detection of configuration changes and new vulnerabilitiesEvidenced outside Déjà
  • CC7.2Monitoring of system components for anomaliesEvidenced by R1R1-L
  • CC7.3Evaluation of security eventsEvidenced by R1R1-LR1-N
  • CC7.4 (evidenced only by an R2)Response to identified security incidentsEvidenced by R2
  • CC7.5 (evidenced only by an R2)Recovery from identified security incidentsEvidenced by R2

Change management

1 of 1 with a receipt type

  • CC8.1Authorization, design, testing, approval and implementation of changesEvidenced by R1

Risk mitigation

1 of 2 with a receipt type

  • CC9.1Risk mitigation for potential business disruptionsEvidenced outside Déjà
  • CC9.2Vendor and business partner risk managementEvidenced by RG

† CC7.4 and CC7.5 get evidence from a resolution receipt (R2) only. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic. Until one is issued, they get no evidence from Déjà.

03 · The receipt types

The evidence, and what each one is.

The receipt types that map evidence to at least one SOC 2 control. The fields each one carries in its signed or hashed bytes are listed under receipt types.

  • R1Signed

    Attribution Receipt

    Incident attributed to a causal PR with CCS above threshold.

    Maps evidence to CC2.2, CC7.2, CC7.3 and CC8.1 · what R1 records

  • R1-LSigned

    Low-Confidence Attribution

    Candidate PRs identified but CCS in the low-confidence range (0.60–0.79).

    Maps evidence to CC7.2 and CC7.3 · what R1-L records

  • R1-NSigned

    No-Attribution Receipt

    Examined, and neither an R1 nor an R1-L was issued.

    Maps evidence to CC7.3 · what R1-N records

  • R2Signed

    Resolution Receipt

    An incident marked resolved, with its five gate scores and whether they passed. References its R1.

    Maps evidence to CC2.2, CC7.4 and CC7.5 · what R2 records

  • RGSigned

    Governance Receipt

    Configuration change to the vault's custody infrastructure.

    Maps evidence to CC2.2 and CC9.2 · what RG records

04 · How an auditor checks it

Checked on the auditor's own machine.

An audit engagement opened for SOC 2 covers the receipt types that map evidence to its controls: R1, R1-L, R1-N, R2 and RG. The auditor gets a token link, sees the receipts in scope, downloads a signed period report and checks it on their own machine with dsr-verifier-cli, against Déjà's published keys.

The period report packs R1, R1-L and R1-N. R2 and RG are listed in the auditor's portal and not packed.

Déjà's integrity monitor, every 15 minutes, checks R1, R2 and RG; it does not check R1-L or R1-N.

05 · Limits

What Déjà does not do for you.

Determine root cause
An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
Certify a control
A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
Attest
Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.

Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.

Walk the list with us, control by control.

Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.