Compliance Coverage

See how XploitScan maps to SOC2, ISO 27001, OWASP Top 10, and CWE controls

SOC 2 (Service Organization Control 2)

A US-based audit framework that evaluates how well a company protects customer data. Created by the AICPA, it covers five trust services categories: security, availability, processing integrity, confidentiality and privacy.

Why it matters: Many B2B customers and enterprise buyers require a SOC 2 report before signing. Mapping findings to the criteria a scanner can evidence gives you a head start on the code-level half of that review — it is not a SOC 2 report and does not make you compliant.

What we map: SOC 2's 2017 Trust Services Criteria define 33 common criteria (CC1.1 through CC9.2). XploitScan maps the ones a code scanner can actually evidence — logical access, system operations and change management. The rest are organizational controls an auditor assesses by interviewing people and reading policies, not by reading source.

9 of 33 common criteria mapped27% of the framework
Control
Description
Rules
Status
3+ rules mapped
1–2 rules mapped
Not Covered