Skip to content
OnTrackio

SOC 2

SOC 2 evidence from your asset inventory

When your auditor asks for the asset inventory, access reviews, and offboarding proof behind the CC6 criteria, that evidence should fall out of the system you already run. OnTrackio generates it from live ITAM data: who holds what, who can access what, and what happened when they left.

What this is, honestly. OnTrackio produces an evidence contribution for the ITAM-shaped part of a SOC 2 audit. It is not a SOC 2 report, and using it does not make you SOC 2 compliant: your auditor, your policies, and the rest of your control environment do that. Our own SOC 2 Type II is targeted for H2 2026 and our current posture is public on the security page.

The logical-access evidence pack

One click in the compliance hub exports a SOC 2 CC6 pack built from your live user, license, and assignment tables:

  • Generated live from your workspace data, not a static template
  • Covers the logical-access criteria: CC6.1, CC6.2, CC6.3
  • Counts that auditors circle first: users without MFA, offboarded people still holding assets, orphaned licenses
  • Exports as a dated PDF your auditor can file as supporting evidence

One asset register, mapped to the Trust Services Criteria

The platform keeps one evidence engine and speaks your framework's vocabulary. EU teams read the same controls as NIS2 Article 21; US teams read them as SOC 2 common criteria. This is the built-in crosswalk, exactly as it renders in the product:

SOC 2 Criterion What OnTrackio contributes
CC3.2 Risk identification across the asset inventory Classified asset register with owner, criticality, and lifecycle state
CC6.1 Logical access over protected information assets Role-based access with per-tenant isolation, IP allowlists, audit trail
CC6.2 / CC6.3 Credential issue, access modification and removal SCIM 2.0 joiner-mover-leaver sync, offboarding checks, access log
CC6.6 Authentication, including MFA Enforced TOTP + WebAuthn passkeys, MFA enrolment reporting
CC6.7 / CC6.8 Endpoint management and software restriction Endpoint agent inventory: installed software, OS version, device state
CC7.2 System monitoring and audit-log retention Tamper-evident activity log with configurable retention and export
CC7.3 / CC7.4 Security-event evaluation and incident response Incident workflow with deadlines, notification templates, evidence trail
CC8.1 Change management for acquired components Software catalog with version history and vendor lifecycle tracking
CC9.2 Vendor and third-party risk management Software vendor inventory tied to spend, contracts, and renewal dates

Contribution scope varies by criterion: for some (CC6.2, CC6.3) the inventory is primary evidence; for others (CC7.3, CC9.2) it is one input to a control your team owns end to end.

The identity stack behind CC6

Access-control evidence is only as good as the access control. The platform ships the identity features a US buyer expects on day one: SAML 2.0 single sign-on, SCIM 2.0 provisioning against Okta and Microsoft Entra with automatic joiner-mover-leaver role sync, enforced MFA with TOTP and WebAuthn passkeys, and per-tenant plus per-token IP allowlists. Every grant and revoke lands in the audit log with its provenance.

Go deeper on SOC 2 asset evidence

Start with the free SOC 2 asset inventory template (hardware, SaaS, and cloud sheets plus a review log), then three guides unpack the asset side of a SOC 2 audit in working detail:

See your CC6 evidence in 30 minutes

Bring your auditor's evidence request list. We'll walk through the pack, the crosswalk, and the identity stack against a live workspace.