Skip to main content
Skip to main content
← Back to Blog
Security

What SOC 2 Alignment Actually Requires

Aligned and certified are different words with different consequences. What the Security and Availability criteria ask for, where alignment work stalls, and what evidence has to look like to survive sampling.

November 22, 2025
9 min read

Aligned is not certified, and the difference matters

Alignment means the controls a framework describes are modelled in your systems and can produce evidence on demand. Certification means an independent auditor has examined those controls and issued a report. A vendor that says aligned when it means certified will be caught the first time a buyer asks for the report.

FormaOS is aligned to SOC 2 and says so plainly. Our infrastructure providers hold their own reports. Anyone can ask us for our position during procurement and get the same answer that is published on this site.

Start with scope, because scope is what runs over

Most first efforts scope to the Security criteria, adding Availability where uptime is contractual. Confidentiality and Privacy pull in data classification and retention work that is worth doing deliberately rather than under audit pressure.

Write the scope down before you start collecting anything. An undocumented scope quietly expands, and the expansion is what makes timelines slip.

Where alignment work usually stalls

None of these are documentation problems. Policies are usually fine. The gap is operational: the control runs, and nothing durable records that it ran.

  • Access reviews happen, but nothing records who reviewed what, or when
  • Vendor assessments are spread across email, spreadsheets, and a drive folder
  • Evidence is assembled after the fact, so it proves the artefact existed, not that the control ran
  • Controls have an owner in a document and no owner in practice

A sequence that holds up

Treat the work as operational change with owners and dates, not a documentation sprint before an audit window.

  1. Put every control in one taxonomy so a control referenced by three frameworks is one record, not three.
  2. Give each control a named owner and a stated evidence requirement.
  3. Capture evidence where the work happens, so the artefact is a by-product of the task rather than a separate chore.
  4. Review control health on a fixed cadence and log exceptions instead of quietly closing them.
  5. Generate the audit export early, while there is still time to fix what it shows.

What evidence has to survive

An auditor samples. They pick a period, ask for the records, and check that the record was created when the control ran rather than the week before the request. Evidence that cannot show its own timing is weak evidence.

  • Access review records tied to the identity system and the date of the review
  • Deployment approvals captured from the pipeline, not retyped afterwards
  • Audit entries that cannot be edited after the fact, so the timeline is checkable

What to take from this

SOC 2 alignment is a way of operating, not an annual project. Capture evidence inside everyday workflows, keep ownership explicit, and protect control changes with role-based access.

And keep the language honest. Aligned, certified, and in progress mean different things to a security reviewer, and using them precisely costs nothing.

Written by

FormaOS Team

Standing byline for the FormaOS blog

More from this byline →

Every post on the FormaOS blog is published under this byline rather than an individual name, so citations have one stable entity to point at. Posts cover compliance frameworks, audit readiness, and how the platform works. Where a post states a regulatory requirement, the regulator or standard it comes from is named in the text so you can check it.

Ready to operationalize compliance?

See how FormaOS connects controls, evidence, and teams in one platform.