Keel
Live demo · read-onlyStart free →
This is a live, read-only demo. You’re exploring a fictional company, “Tailwind Systems.” Nothing here can be edited, and the data resets nightly. Create a free workspace to build your own program.
Start freeLearn more
33%ready
Audit readiness
SOC 2 (Trust Services Criteria)
20 of 61 requirements covered

Requirement status · SOC 2 (Trust Services Criteria)

How the applicable requirements break down right now.

61applicable
Covered20
In progress2
Gap0
Unaddressed39
SOC 2 (Trust Services Criteria) readiness
33%
20 of 61 requirements covered
Open risks
10
1 high unmitigated · 12 total
Vendors
15
1 review due · 3 critical

Vendors by criticality

15 vendors · 1 review due.

Critical3
High5
Medium4
Low3

Framework readiness

Collect evidence once. The same controls satisfy clauses across frameworks.

SOC 2 (Trust Services Criteria)33% · 20/61
ISO/IEC 27001:202221% · 24/116

Risk heat map

Effective (residual where assessed) likelihood × impact. Closed risks are excluded.

Almost certain·····
Likely···1·
Possible···2·
Unlikely·1231
Rare····1
InsignificantMinorModerateMajorSevere
Low (1-3)Guarded (4-7)Elevated (8-14)High (15-25)Rows = likelihood · Columns = impact

Mapped requirements · SOC 2 (Trust Services Criteria)

ClauseRequirementControlsStatus
CC1.4Commitment to competencesecurity-awareness-training, hr-securityCovered
CC3.1Objectives specifiedrisk-assessmentCovered
CC3.2Risk identification & analysisrisk-assessmentCovered
CC4.1Ongoing & separate evaluationsinternal-audit-program, management-reviewCovered
CC5.3Policies & proceduresinformation-security-policy, document-controlCovered
CC6.1Logical access securityaccess-control-policy, mfa, asset-inventoryCovered
CC6.2User registration & authorizationuser-lifecycleCovered
CC6.3Access based on roles & least privilegeaccess-control-policy, user-lifecycleCovered
CC6.4Physical accessphysical-securityCovered
CC6.6External threat protectionnetwork-securityCovered
CC6.7Transmission & endpointsencryptionCovered
CC6.8Unauthorized/malicious softwaremalware-protectionIn progress
CC7.1Vulnerability & configuration detectionvulnerability-managementCovered
CC7.2Security monitoringlogging-monitoringIn progress
CC7.3Incident evaluationincident-responseCovered
CC7.4Incident responseincident-responseCovered
CC8.1Change managementchange-management, secure-developmentCovered
CC9.2Vendor & partner riskvendor-managementCovered
A1.2Environmental protection & backupbackups, business-continuityCovered
A1.3Recovery testingbusiness-continuityCovered
C1.1Identify & protect confidential informationdata-classificationCovered
C1.2Dispose of confidential informationdata-retention-disposalCovered