SOLUTIONS / SOC 2

SOC 2, without
the evidence scramble.

SOC 2 asks you to prove that changes were reviewed, approved, and controlled. CDK generates that proof continuously, so audit season isn't a scramble to reconstruct history.

TRUST SERVICES CATEGORIES

Where CDK evidence applies.

SOC 2 covers five categories. CDK's delivery evidence speaks directly to four of them.

Security

Evidence that access, changes, and deployments were authorized and controlled.

Availability

Deployment and rollback history that demonstrates operational commitments were met.

Processing Integrity

Proof that what was built matches what was approved, without unauthorized modification.

Confidentiality

Access control evidence for systems handling confidential information.

CONTROL MAPPING

What auditors actually ask for.

CC6.1
Logical Access. Every approval and deployment is tied to a verified identity.
CC7.2
System Monitoring. Evidence is generated continuously, not reconstructed during audit season.
CC8.1
Change Management. Every production change is linked to its approval, policy evaluation, and deployment record.
FOR AUDITORS

Direct access. Not a folder of screenshots.

The same Audit Workspace your enterprise plan includes lets assessors review evidence directly — without engineering pulling exports the week before the audit.

  • Read-only, scoped access for external auditors
  • Every record independently verifiable, no CDK account required
  • Full history — not just the point-in-time sample requested
  • No engineering time spent assembling evidence packets

Ready for your next SOC 2 audit?

See how CDK evidence maps to your existing controls.