There Is No List of SOC 2 Controls
SOC 2 publishes 61 criteria and 330 points of focus, and exactly zero controls. What the standard actually contains, and how to run readiness against it.
Every readiness engagement starts the same way. Someone forwards a security questionnaire, someone else forwards a quote from an audit firm, and then a message arrives asking for the list of SOC 2 controls.
There is no list.
TSP Section 100 says so directly. The trust services criteria set out the outcomes an entity's controls should ordinarily meet, and the standard explicitly contrasts this with frameworks that mandate a specific set of controls. It goes further: no fixed set of controls can mitigate every threat an entity faces, so each entity establishes its own objectives, assesses its own risks, and designs its own controls.
The checklist is your job.

Three levels, often conflated
Criteria. Fixed and published. Sixty one of them, thirty three of which are shared across all five trust services categories. The opinion in your report is given against these and nothing else.
Points of focus. Three hundred and thirty across the standard, sitting beneath the criteria as guidance. The standard says plainly that assessing whether each one is addressed is not required.
Controls. Yours. Designed off your own risk assessment.
That is why every compliance platform and audit firm ships a different control library, and why all of them can be defensible at the same time. When an interviewer asks how many controls SOC 2 has, the answer is that the framework specifies none.
Two things that catch people
Security adds no criteria of its own. Its complete set is the common criteria, which is why the CC series is named for being common across categories rather than for Security. A Security only report is 33 criteria. Adding confidentiality takes you to 35. Adding privacy takes you to 51.

Privacy is not only the P series. Teams work the eighteen P criteria, call privacy done, then meet CC7.4 during fieldwork and get asked for the breach response procedure. Sixteen privacy tagged points of focus sit inside the common criteria, in CC2.2, CC7.4, CC8.1 and elsewhere. The real privacy footprint is 74, not 58.

What actually works
Decide scope in writing, with a reason recorded for every exclusion. An assertion you cannot demonstrate is in scope until proven otherwise.
Map controls to criteria rather than the reverse. A control that maps to nothing is work you did not need. A criterion that maps to no control is the finding.
Test yourself between audits. In a Type 2, evidence has to exist across the whole period, and you cannot reconstruct a quarterly access review for a quarter that already closed. Notice the miss in July and you can fix the process and keep the rest of the period clean. Notice it in March, when the auditor pulls four quarters and gets three, and it is an exception in the report. That self testing log doubles as your evidence for CC4.1 and CC4.2.
Download the workbook
SOC 2 Trust Services Criteria Full Register is free on the utilities page of this site: heyshahrukh.me/control-room/utils
All 61 criteria and 330 points of focus, a scope engine, suggested controls, evidence guidance, a scope definition document, thirty eight spot checks and an executive dashboard. One Excel file, nothing to sign up for.
The companion ISO 27001 to SOC 2 Coverage Tool is on the same page if you already hold an ISMS.
Related posts
- You Have ISO 27001. How Much SOC 2 Is Already Done?
All 93 Annex A controls mapped to SOC 2. A complete ISMS covers 36 of 61 criteria and 231 of 330 points of focus. The gap is almost entirely privacy.
- Email Security Best Practices for Modern Organizations
Explore modern email threats, phishing risks, BEC attacks, and practical security controls to protect your organization from compromise