Prepare for SOC 2 with PurpleWASP
Use PurpleWASP to structure SOC 2 readiness from engagement scope through criteria, control coverage, implementation, evidence, testing, remediation and audit preparation.
What PurpleWASP SOC 2 does today
PurpleWASP provides a structured SOC 2 readiness management and audit-preparation workspace. It connects the engagement scope to applicable Trust Services Criteria, organisation Controls, implementation, assessments, evidence, testing, issues, exceptions and readiness decisions.
| Capability | Current PurpleWASP support |
|---|---|
| Engagement setup | Define the service, examination type, Trust Services Categories, system boundary and engagement scope. |
| Criteria workspace | Review the criteria included in the confirmed engagement and the Control candidates associated with them. |
| Control coverage | Adopt relevant Controls and explicitly decide which organisation Controls management intends to rely on for each criterion. |
| Implementation and assessment | Track implementation and record design or operating-effectiveness assessment conclusions for selected organisation Controls. |
| Evidence and testing | Link current evidence, define tests, record test runs and evaluate whether evidence/testing is relevant to the engagement period. |
| Issues, exceptions and remediation | Record deficiencies, exceptions and remediation activity that affect Control or engagement readiness. |
| Operational and audit readiness | Review readiness signals at Control, criterion and engagement level and document management readiness decisions. |
Current capability boundary
PurpleWASP supports the organisation's SOC 2 readiness programme. It does not replace the independent SOC 2 examination or issue the service auditor's report.
- PurpleWASP does not issue a SOC 2 report.
- PurpleWASP readiness indicators are management/internal readiness signals, not an auditor opinion.
- Candidate mappings are PurpleWASP intelligence suggestions, not a mandatory checklist that must all be adopted.
- Automated evidence integrations and broad continuous Control monitoring are not yet the whole SOC 2 operating model; use the records and integrations actually configured for your organisation.
1. Set up and confirm the SOC 2 engagement
Start from Compliance, select SOC 2 and work through the setup flow. The setup establishes the scope that every later readiness calculation depends on.
- Select the Trust Services Categories relevant to the service. Security is foundational; add other categories only where they are part of the intended examination scope.
- Describe the service/system and discover the people, processes, technology, data, infrastructure and dependencies that form the system boundary.
- Choose Type I or Type II and establish the engagement period where applicable.
- Review subservice organisations, complementary user entity considerations and relevant boundary assumptions.
- Review and confirm the engagement before treating the downstream criteria and readiness views as authoritative.
2. Review the Criteria Workspace
The Criteria Workspace shows the criteria in the confirmed engagement together with candidate and selected Control coverage. Keep the matrix collapsed for scanning and expand a criterion when you need to review its Control details.
- Candidate means PurpleWASP has a potential Control-to-criterion mapping.
- Adopted candidate means the Control exists in the organisation's Control Management workspace.
- Selected means management has explicitly chosen that organisation Control as part of the criterion coverage plan.
Do not interpret the number of candidates as a required number of Controls. Management determines the Control set that is appropriate to the actual system and operating model.
3. Decide the organisation Control coverage plan
Open the Control Coverage Plan to decide which adopted organisation Controls management will rely on for each criterion.
- Review candidate Controls and their mapping strength.
- If a useful candidate has not yet been adopted, review/adopt it in Control Management.
- For an adopted Control, choose Use for coverage when management intends to rely on it.
- Choose Do not use when the candidate is not part of the organisation's intended coverage approach.
- Use Clear decision if the mapping should return to an unreviewed state.
A Control marked Not Applicable in Control Management cannot be selected for SOC 2 coverage until its applicability position is changed.
4. Implement and assess the selected Controls
Selected coverage is only a plan. Open the implementation workbench and confirm how each selected organisation Control is implemented in the scoped system.
- Confirm ownership and implementation status.
- Connect relevant system/Asset implementation context where available.
- Perform design assessment to determine whether the Control is suitably designed for its intended purpose.
- For operating-effectiveness readiness, record the appropriate final assessment conclusion based on the operating evidence available.
Do not mark a Control ready merely because its documentation exists. The readiness view uses implementation and assurance records as separate signals.
5. Build the evidence and testing record
Use Evidence and Testing to support the selected Controls with traceable operating proof and repeatable assurance activity.
- Link evidence to the organisation Control it supports and record enough source/date/validity context for a reviewer.
- For Type II, confirm that the evidence validity or collection period overlaps the engagement window where that evidence is intended to support operating effectiveness.
- Define active tests for Controls that require testing.
- Record test runs and results rather than treating the existence of a test definition as proof that a Control was tested during the period.
- Raise an issue when assessment, evidence or testing identifies a deficiency requiring follow-up.
6. Resolve issues, exceptions and remediation
Use the Issues & Exceptions workspace when the selected Control environment does not fully meet the intended operating position.
- Record active issues and their severity, ownership and remediation state.
- Use exceptions where a temporary approved departure is being governed rather than silently accepted.
- Track remediation to evidence-based closure and reassess readiness after the underlying state changes.
- Pay particular attention to high/critical issues and unresolved exceptions when preparing the engagement for auditor review.
7. Review Operational Readiness and Audit Readiness
Operational Readiness summarises whether selected Controls have the implementation, assessment, evidence, testing and issue state needed to support the engagement. Audit Readiness then brings those signals together at the engagement level.
Use the readiness views—and the available Drivers / Improve Score detail—to identify the specific blockers reducing the internal readiness position, then return to the owning workspace to correct them. A readiness percentage or status should never be treated as a substitute for reviewing the underlying evidence, test result, assessment, issue or exception.
Type I and Type II readiness
Type I
Use PurpleWASP to establish the system description/scope, applicable criteria, selected Control design and supporting evidence at the relevant point in time. Focus on whether the Control environment is suitably designed and represented at that date.
Type II
In addition to design, manage the evidence and test record across the defined examination period. Period-relevant evidence and completed test runs become especially important because the readiness question concerns operation over time rather than only a point-in-time design position.
Prepare for the independent service auditor
Before auditor handoff, review the engagement as a connected chain:
Scope → Criteria → Selected Controls → Implementation → Assessments → Evidence → Tests → Issues/Exceptions → Readiness decisions.
Use PurpleWASP to make that chain traceable and to identify gaps before fieldwork. The independent service auditor determines the examination procedures, evaluates evidence and issues the SOC 2 report/opinion.
Full SOC 2 implementation guide
For a detailed beginner-friendly walkthrough of the complete current PurpleWASP SOC 2 readiness workflow, download the implementation guide.
Common problems
No confirmed engagement is available
Return to SOC 2 setup, complete the scope and engagement details and confirm the engagement before using the downstream workspace.
A candidate Control cannot be selected
Confirm the candidate has been adopted into Control Management and is not marked Not Applicable. Candidate catalogue intelligence alone is not an organisation coverage decision.
Evidence exists but readiness still shows a gap
Confirm the evidence is linked to the selected organisation Control, is current, and—where Type II period relevance matters—its collection/validity overlaps the engagement period. Also check whether a required final assessment or completed test run is still missing.
A readiness indicator looks positive but an issue remains open
Follow the readiness signal back to the underlying Control and issue records. Readiness is a management summary; unresolved issues and exceptions still require explicit review and disposition.