SOC 2 controls and the receipts that map evidence to them.
Every SOC 2 control Déjà's control table lists, with the receipt types that map evidence to each. Where none does, the row says so: that control is evidenced outside Déjà. References and titles are from AICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria.
7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.
What a receipt covers, and what is not.
7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà.
The common criteria, CC1 to CC9, of the Trust Services Criteria. The additional criteria for availability, processing integrity, confidentiality and privacy are not listed here, and are evidenced outside Déjà.
- Edition
- AICPA 2017 Trust Services Criteria (revised points of focus, 2022), common criteria
- Controls listed
- 33
- A receipt type maps evidence
- 7
- Evidenced outside Déjà
- 26
A receipt is evidence for a control, never the whole of it: the rest of each control is tested outside Déjà.
SOC 2, in the standard's own words.
Control environment
0 of 5 with a receipt type
- CC1.1Commitment to integrity and ethical valuesEvidenced outside Déjà
- CC1.2Board independence and oversight of internal controlEvidenced outside Déjà
- CC1.3Structures, reporting lines, authorities and responsibilitiesEvidenced outside Déjà
- CC1.4Attracting, developing and retaining competent individualsEvidenced outside Déjà
- CC1.5Accountability for internal control responsibilitiesEvidenced outside Déjà
Communication and information
1 of 3 with a receipt type
Risk assessment
0 of 4 with a receipt type
- CC3.1Objectives specified clearly enough to identify and assess risksEvidenced outside Déjà
- CC3.2Identification and analysis of risksEvidenced outside Déjà
- CC3.3Potential for fraud in assessing risksEvidenced outside Déjà
- CC3.4Changes that could significantly impact internal controlEvidenced outside Déjà
Monitoring activities
0 of 2 with a receipt type
- CC4.1Ongoing and separate evaluations of internal controlEvidenced outside Déjà
- CC4.2Evaluation and communication of internal control deficienciesEvidenced outside Déjà
Control activities
0 of 3 with a receipt type
- CC5.1Control activities that mitigate risksEvidenced outside Déjà
- CC5.2General control activities over technologyEvidenced outside Déjà
- CC5.3Control activities deployed through policies and proceduresEvidenced outside Déjà
Logical and physical access controls
0 of 8 with a receipt type
- CC6.1Logical access security software, infrastructure and architecturesEvidenced outside Déjà
- CC6.2Registration and authorization of users, and removal of credentialsEvidenced outside Déjà
- CC6.3Authorization, modification and removal of accessEvidenced outside Déjà
- CC6.4Restriction of physical accessEvidenced outside Déjà
- CC6.5Discontinuing protections over physical assetsEvidenced outside Déjà
- CC6.6Protection against threats from outside system boundariesEvidenced outside Déjà
- CC6.7Restriction of transmission, movement and removal of informationEvidenced outside Déjà
- CC6.8Prevention or detection of unauthorized or malicious softwareEvidenced outside Déjà
System operations
4 of 5 with a receipt type
- CC7.1Detection of configuration changes and new vulnerabilitiesEvidenced outside Déjà
- CC7.2Monitoring of system components for anomaliesEvidenced by R1R1-L
- CC7.3Evaluation of security eventsEvidenced by R1R1-LR1-N
- CC7.4 (evidenced only by an R2)Response to identified security incidentsEvidenced by R2
- CC7.5 (evidenced only by an R2)Recovery from identified security incidentsEvidenced by R2
Change management
1 of 1 with a receipt type
- CC8.1Authorization, design, testing, approval and implementation of changesEvidenced by R1
Risk mitigation
1 of 2 with a receipt type
- CC9.1Risk mitigation for potential business disruptionsEvidenced outside Déjà
- CC9.2Vendor and business partner risk managementEvidenced by RG
† CC7.4 and CC7.5 get evidence from a resolution receipt (R2) only. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic. Until one is issued, they get no evidence from Déjà.
The evidence, and what each one is.
The receipt types that map evidence to at least one SOC 2 control. The fields each one carries in its signed or hashed bytes are listed under receipt types.
R1Signed
Attribution Receipt
Incident attributed to a causal PR with CCS above threshold.
Maps evidence to CC2.2, CC7.2, CC7.3 and CC8.1 · what R1 records
R1-LSigned
Low-Confidence Attribution
Candidate PRs identified but CCS in the low-confidence range (0.60–0.79).
Maps evidence to CC7.2 and CC7.3 · what R1-L records
R1-NSigned
No-Attribution Receipt
Examined, and neither an R1 nor an R1-L was issued.
Maps evidence to CC7.3 · what R1-N records
R2Signed
Resolution Receipt
An incident marked resolved, with its five gate scores and whether they passed. References its R1.
Maps evidence to CC2.2, CC7.4 and CC7.5 · what R2 records
RGSigned
Governance Receipt
Configuration change to the vault's custody infrastructure.
Maps evidence to CC2.2 and CC9.2 · what RG records
Checked on the auditor's own machine.
An audit engagement opened for SOC 2 covers the receipt types that map evidence to its controls: R1, R1-L, R1-N, R2 and RG. The auditor gets a token link, sees the receipts in scope, downloads a signed period report and checks it on their own machine with dsr-verifier-cli, against Déjà's published keys.
The period report packs R1, R1-L and R1-N. R2 and RG are listed in the auditor's portal and not packed.
Déjà's integrity monitor, every 15 minutes, checks R1, R2 and RG; it does not check R1-L or R1-N.
What Déjà does not do for you.
- Determine root cause
- An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
- Certify a control
- A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
- Attest
- Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.
Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.
Walk the list with us, control by control.
Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.