SOC 2 switching dictionary: 38 terms explained

Short answer

Plain definitions of the terms that come up when you compare or change SOC 2 platforms. Where a term comes from a standard, we link the source.

Add-on

A feature or allowance sold on top of a plan rather than included in it. Drata, for example, lists additional frameworks and user access reviews as add-ons on its Foundation plan.

Source: Drata plans · read 2026-09-29

Agentic AI

AI software that carries out multi-step tasks, such as collecting evidence or drafting a policy, rather than only answering a prompt. Several SOC 2 platforms now describe named agents on their own pages.

ASV scan

An external vulnerability scan performed by a PCI SSC Approved Scanning Vendor, required for many PCI DSS assessments. Thoropass lists certified ASV scans.

Source: Thoropass homepage · read 2026-09-29

Audit hub

A workspace inside a compliance platform where the auditor and the company exchange requests and evidence. Scytale describes one on its audit management page.

Source: Scytale audit management · read 2026-09-29

Auditor independence

The requirement that an auditor is free of relationships that could affect their judgment. When a platform offers its own audit route, ask how independent the auditor is from the tool vendor; the AICPA published Ethics Staff Insights titled "Business arrangements with SOC tool providers" on 13 April 2026.

Source: AICPA SOC suite of services · read 2026-09-29

Bridge letter

A letter from the service organization, not the auditor, covering the gap between the end of its last report period and the present. It is a statement by the company, not an audit opinion.

Bring your own auditor (BYOA)

Using an audit firm you choose rather than one supplied or referred by the platform. Sprinto lists BYOA on its Foundation plan.

Source: Sprinto pricing · read 2026-09-29

Changeover note

Our term for a short dated record of a platform switch: what moved, when, where the exported evidence is stored and who signed it off. It answers most auditor questions about a switch.

Common control framework

A single set of controls mapped to several frameworks, so one control and its evidence count for each. Sprinto describes one; Scrut calls its version a Unified Control Framework.

Source: Sprinto frameworks · read 2026-09-29

Continuous monitoring

Automated, repeated checks that controls are still working, run through integrations rather than once a year.

Control

Something an organization does to meet a requirement, such as reviewing user access every quarter or encrypting data at rest.

Control cross-mapping

Linking one control to every framework requirement it satisfies, so evidence collected once can be used for several frameworks.

CPA firm

A licensed accounting firm. SOC reports are a suite of services that CPAs may provide, according to the AICPA.

Source: AICPA SOC suite of services · read 2026-09-29

Evidence collection

Gathering the records that prove a control operated, such as screenshots, logs, tickets or system exports. Platforms automate part of it through integrations.

Exception

A finding in an audit where a control did not operate as described for some or all of the period. Exceptions appear in a Type II report with the auditor's description.

FTE

Full-time equivalent, a headcount measure some vendors use for plan limits. Drata's Foundation plan covers up to 50 FTEs.

Source: Drata plans · read 2026-09-29

Integration

A connection between a compliance platform and another system, such as a cloud provider or identity provider, used to collect evidence and run tests automatically.

ISO/IEC 27001:2022

The international standard for information security management systems. The current edition is Edition 3, published in October 2022.

Source: ISO/IEC 27001:2022 · read 2026-09-29

ISO/IEC 42001

An international standard for AI management systems. Several platforms in our lineup name it on their framework pages.

Least privilege

Giving a user or integration only the access it needs to do its job. Relevant when you connect a new platform to your systems.

MCP (Model Context Protocol)

An open protocol that lets AI assistants connect to external tools and data. Scrut says its AI Teammates work in MCP-compatible clients.

Source: Scrut homepage · read 2026-09-29

Observation period

The period of time a SOC 2 Type II report covers. The auditor tests whether controls operated throughout it, so evidence must cover the whole period.

Peer review

The AICPA program in which CPA firms have their own audit quality reviewed by other firms. Ask whether your auditor is enrolled.

Source: AICPA SOC suite of services · read 2026-09-29

Penetration test

An authorized simulated attack on a system to find exploitable weaknesses. A black box test starts with no inside knowledge; a gray box test starts with some. Scytale's bundles name both.

Source: Scytale pricing · read 2026-09-29

Plan limit

A published cap on what a plan covers, such as headcount, number of frameworks or questionnaires a year.

Policy

A written, approved statement of how the organization handles an area of security, such as access control or incident response. Auditors check both the policy and its approval history.

Questionnaire allowance

The number of security questionnaires a plan's automation covers each year, where a vendor publishes one. Vanta lists 25 on Plus and 144 on Professional; Sprinto lists 20 on Foundation.

Source: Vanta pricing · read 2026-09-29

Readiness assessment

A review before an audit that compares current controls against the framework and lists the gaps to close.

Risk register

A record of identified risks, their likelihood and impact, the owner and the treatment. Most frameworks expect one.

Security questionnaire

A set of questions a customer sends to assess a supplier's security, often during a sale or renewal.

SOC 2

An examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy, reported by a CPA firm.

Source: AICPA SOC suite of services · read 2026-09-29

SOC 2 Type I

A SOC 2 report on the design of controls at a specific point in time.

SOC 2 Type II

A SOC 2 report on whether controls operated effectively over a period of time.

System description

The section of a SOC report in which the company describes the system, its boundaries and its controls. The auditor reports against it.

TPRM

Third-party risk management, the process of assessing and monitoring the vendors you depend on. Several platforms launched or expanded TPRM products in 2026.

Trust center

A public or gated web page where a company shares its security posture, reports and policies with customers.

Trust Services Criteria

The criteria a SOC 2 examination uses, covering security, availability, processing integrity, confidentiality and privacy.

Source: AICPA SOC suite of services · read 2026-09-29

vCISO

A virtual chief information security officer, usually a consultant or partner firm providing part-time security leadership. Vanta and Drata both describe vCISO partners.

Source: Vanta service providers · read 2026-09-29

Questions people ask

What is the difference between SOC 2 Type I and Type II?

Type I covers the design of controls at a point in time. Type II covers whether they operated over a period, which is why the timing of a platform switch matters for Type II. Timing a switch around your audit window

What is a bridge letter?

A letter from your company, not your auditor, covering the gap between your last report period and today. Bridge letter

Is 'changeover note' a standard term?

No, it is our name for a simple dated record of a switch. Your auditor may have their own template. What your auditor needs when you change tools