Define the system boundary and choose the criteria
- Security
SOC 2 reports on a defined system: the product, the infrastructure it runs on, the people and processes that operate it, and the data it handles. A tight, honest boundary is the single biggest lever on cost and timeline.
- What the auditor tests
- That the system description matches what is actually in scope, and that controls cover everything inside the boundary.
- Do this first
- Draw the boundary on one page: the product, production cloud accounts, supporting SaaS tools, teams and data flows. Start with Security only unless a contract demands more.
- Evidence produced
- Scope and boundary document
- Data flow and architecture diagram
- List of in-scope systems and subservice organisations
Framework mapping
SOC 2 (2017 TSC)
- DC 200 Description criteria
- Security (Common Criteria) required in every report
ISO/IEC 27001:2022
- Clause 4.3 Determining the scope of the ISMS
Watch out
Leaving a system out of scope does not hide it from buyers. If customer data touches it, expect the question in due diligence. Scope to what customers rely on, not to what is easy.