📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

SOC 2 2024

SOC 2 Trust Services Criteria — Type I (point-in-time design assessment) and Type II (operating effectiveness over a period, typically 6-12 months).

Covers Security (required), plus optional Availability, Processing Integrity, Confidentiality, and Privacy criteria. Type I verifies controls are suitably designed.

Type II verifies controls operated effectively over the audit period.

Assessment tiers & levels Lavawall supports

Lavawall assesses SOC 2 at every level below, so you can start where you are and step up as your program matures.

Tier / levelWhat it coversBuilds on lower
Security (Common Criteria)The system is protected against unauthorized access, use, or modification. Required for all SOC 2 reports.—
AvailabilityThe system is available for operation and use as committed or agreed.—
Processing IntegritySystem processing is complete, valid, accurate, timely, and authorized.—
ConfidentialityInformation designated as confidential is protected as committed or agreed.—
PrivacyPersonal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice.—

How Lavawall® helps you get to SOC 2 compliance

Most of SOC 2 comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to SOC 2, and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against SOC 2 in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Lavawall® supports SOC 2 as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.

At a glance

Framework
SOC 2 2024
Category
Security
Region
Global
Levels
5 assessment tiers

Official source →


Map this framework freeTalk to our team