Agentic compliance for SOC 2

SOC 2 Type II, with evidence for every day of the period.

A SOC 2 report is an attestation by a licensed CPA firm on your controls against the AICPA Trust Services Criteria. Teddy's agents define the system, map your controls and collect evidence across the whole observation period. A compliance engineer takes you to the auditor.

Every dayEvidence collected for the full audit period
Type II reportPlanned from scope to fieldwork
Before the auditMissing evidence found in time to fix it
What SOC 2 examines

Six parts of a SOC 2 report.
Each one has a home in Teddy.

SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report your customers can read. Here is what goes into it and where it lives in Teddy.

Trust Services CriteriaSecurity plus what customers need

Security, with the common criteria CC1 to CC9, is always in scope. Availability, confidentiality, processing integrity and privacy are added when they matter to your customers.

In TeddyScope chosen with the Certification Agent
Description criteriaSystem description

Your services, infrastructure, software, people, data and procedures in scope, including subservice organizations such as your cloud provider.

In TeddyDrafted from your company model and connections
CC1 to CC5Control environment and risk

Control environment, communication and information, risk assessment, monitoring activities and control activities. The base the technical controls rest on.

In TeddyPolicies and risk register, linked to the criteria
CC6 to CC9Access, operations and change

Logical and physical access, system operations, change management and risk mitigation, including vendors and business disruption.

In TeddyEvidence Agent collects proof from connected tools
Type I and Type IIOne date or a whole period

A Type I report covers the design of controls as of one date. A Type II report also tests whether they operated effectively over a period, typically three to twelve months.

In TeddyObservation period tracked day by day
The reportOpinion, assertion and tests

The auditor’s opinion, management’s assertion and the system description. A Type II report adds the tests performed and any deviations found.

In TeddyAuditor package prepared, deviations documented
Before the auditReadinessGap audit and remediation
OptionalType I reportDesign as of one date
Typically 3 to 12 monthsObservation periodControls operate and leave records
After the periodType II reportThen the next period begins
The problem

Six months of evidence.
One missing record.

A Type II report looks back over the whole period. A control that did not run cannot be evidenced afterwards, and every deviation the auditor finds is described in the report your customers read.

01The report your customers read

Teddy drafts the description of your system from how your product actually runs.

02Controls that work all year

The Evidence Agent collects proof for every month the auditor will check.

03Evidence from many tools

Connect your cloud, login, HR and code tools once. Access is read-only.

04Screenshots for the auditor and logs nobody kept. Still no clean report.

Someone takes screenshots the week before fieldwork, the June logs have expired and the access review lives in a spreadsheet. ChatGPT can explain CC7.2, but it cannot see whether you ran it. Teddy collects evidence from your systems throughout the period and flags a missing record while you can still respond.

How it works

From scope to a report your customers trust

Teddy's agents prepare and run the program. You approve, the audit firm examines, and a compliance engineer is with you through fieldwork.

01 Certification Agent

Choose the criteria and the scope

Teddy asks what your customers expect and which systems deliver your service, then proposes the Trust Services Criteria, the report type and the observation period.

SOC 2 scope · Acme Inc.Draft
Security (common criteria)Always included
AvailabilitySelected
ConfidentialitySelected
Report typeType II · 6 months
02 Gap Audit Agent

Map controls to the criteria

Teddy maps your controls to each criterion you selected and shows where a criterion has no control yet or a control has no owner.

Control mapping64 controls
CC1 to CC521 controls
CC6 to CC939 controls
A1 Availability4 controls
Teddy: Every selected criterion is covered. Two controls still need an owner.
03 Policy Agent

Policies and the system description

The Policy Agent drafts policies and the system description from your setup, so both describe how your service actually runs.

DocumentsFor the report
Information security policyApproved
Change management policyDraft
System descriptionDraft
Teddy: AWS is listed as a subservice organization using the carve-out method. Its own SOC 2 report is linked.
04 Evidence Agent

Evidence for every day of the period

The Evidence Agent collects records from connected tools on a schedule. A missing record shows up while you can still document it, not during fieldwork.

EvidenceDay 112 of 183
AWS CloudTrail exportDaily
Entra ID access reviewsMonthly
CC7.2 Alert review · JuneMissing
Teddy: The June review did not happen and stays a deviation. I drafted a management response, and the review runs on schedule again.
05 Gap Audit Agent

Map once, comply many

Controls you already run for ISO 27001, TISAX® or NIS2 count for SOC 2 too. Teddy maps every framework onto one control set and shows only what is new.

Shared controlsOne control set
Shared with ISO 2700158
Shared with TISAX®49
New for SOC 2 only6
Teddy: Your ISO 27001 evidence counts here. SOC 2 adds the system description and testing over the period.
Never stuck

Ask Teddy before the auditor does.

Ask in plain language what the auditor will test. Teddy answers from your live program and does the work. For fieldwork, our compliance engineers are at your side.

1

Ask TeddyWhich criteria do we need? What will the auditor sample? Teddy knows the criteria and your controls.

2

Agents do the workMapping, system description, evidence and management responses arrive ready for your approval, each with its source.

3

Our team backs you upCompliance engineers help you choose an audit firm and join you through fieldwork.

TeddyAcme Inc. · SOC 2
What will the auditor sample from us?
For recurring controls, expect samples from across the period. Here is where you stand:
  • Access reviews · monthly6 of 6
  • Change approvals · per change212 linked
  • Alert review · JuneMissing
Shall I finalize the management response for June?
Review responseAsk our team
CEYour compliance engineer joins the readiness review and fieldwork.
FAQ

Questions about SOC 2

Is SOC 2 a certification?

No. SOC 2 is an attestation report. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and gives its opinion. Teddy prepares the program and the evidence, the audit firm forms the opinion.

Type I or Type II?

A Type I report covers the design of your controls as of one date. A Type II report also tests whether they operated effectively over a period. Enterprise customers usually ask for Type II.

We already have ISO 27001. How much can we reuse?

A lot. Teddy maps both onto one control set. SOC 2 adds the system description, the criteria you select and testing over the observation period.

What happens after the first report?

A Type II report covers one period. Most companies start the next period right away, so their reports follow each other without a gap. For the time until the next report, management can issue a bridge letter. Teddy keeps collecting evidence throughout.

Your SOC 2 Type II, with evidence for every day.

Start with a gap audit against the Trust Services Criteria.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long SOC 2 takes, and how Teddy cuts the preparation to weeks

TypicalSeveral months

Readiness work takes months before the observation period even starts. First-time remediation and evidence often take 4 to 16 weeks on their own.

With TeddyReady within weeks

Your observation period can start right away. Controls are mapped to the Trust Services Criteria and evidence runs from day one. A Type 1 can follow immediately.

  • What stays fixed: the Type 2 observation period. There is no official minimum, but most CPA firms require at least three months, and many organizations choose six to twelve.
  • Who audits: an independent CPA firm under AICPA attestation standards, independent of the tool you use.
  • Report validity: there is no formal expiry. Many buyers expect a report whose period ended within the last 12 months.
  • Fast readiness, not a fast report: Teddy speeds up the preparation. The auditor's testing stays independent and takes the time it needs.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

Where SOC 2 reports pick up exceptions

  1. One missed access review shows up in the report.

    Skip one quarterly review in a Type 2 period and the report lists it as an exception. Three clean quarters do not cancel it out. Auditors test whether you did what your own policy says, so set a cadence you can keep.

  2. Hotfixes break change management.

    The auditor samples production deployments from the whole period. Emergency changes without a review afterwards are a frequent exception in engineering-heavy teams.

  3. The policy exists, the proof does not.

    Offboarding is written down, but there is no ticket showing access was removed on time. Evidence has to be collected during the period, not reconstructed at the end.