Skip to content

SOC 2 for platform teams

First PublishedByAtif Alam

This is a thin hub for teams who hear “SOC 2” and need to know where to read in this library. Deep framing lives in Compliance quick reference for SREs (matrix + checklists) and Audit fieldwork and evidence for engineers.

Not legal or audit advice. Your GRC owners map Trust Services Criteria to actual controls.

You needStart here
CI/CD change and access evidenceCompliance and audit
What auditors often ask engineersAudit fieldwork and evidence for engineers
Checklists across frameworks (including SOC 2)Compliance quick reference for SREs
Scanning and gatesSecurity scanning (DevSecOps)
Kubernetes production postureProduction platform checklist
Identity and secretsAWS IAM, AWS secrets, Kubeconfig and authentication
Broader DevSecOps routingDevSecOps overview