SOC 2
SOC 2 evidence from your asset inventory
When your auditor asks for the asset inventory, access reviews, and offboarding proof behind the CC6 criteria, that evidence should fall out of the system you already run. OnTrackio generates it from live ITAM data: who holds what, who can access what, and what happened when they left.
What this is, honestly. OnTrackio produces an evidence contribution for the ITAM-shaped part of a SOC 2 audit. It is not a SOC 2 report, and using it does not make you SOC 2 compliant: your auditor, your policies, and the rest of your control environment do that. Our own SOC 2 Type II is targeted for H2 2026 and our current posture is public on the security page.
The logical-access evidence pack
One click in the compliance hub exports a SOC 2 CC6 pack built from your live user, license, and assignment tables:
- Generated live from your workspace data, not a static template
- Covers the logical-access criteria: CC6.1, CC6.2, CC6.3
- Counts that auditors circle first: users without MFA, offboarded people still holding assets, orphaned licenses
- Exports as a dated PDF your auditor can file as supporting evidence
One asset register, mapped to the Trust Services Criteria
The platform keeps one evidence engine and speaks your framework's vocabulary. EU teams read the same controls as NIS2 Article 21; US teams read them as SOC 2 common criteria. This is the built-in crosswalk, exactly as it renders in the product:
| SOC 2 | Criterion | What OnTrackio contributes |
|---|---|---|
| CC3.2 | Risk identification across the asset inventory | Classified asset register with owner, criticality, and lifecycle state |
| CC6.1 | Logical access over protected information assets | Role-based access with per-tenant isolation, IP allowlists, audit trail |
| CC6.2 / CC6.3 | Credential issue, access modification and removal | SCIM 2.0 joiner-mover-leaver sync, offboarding checks, access log |
| CC6.6 | Authentication, including MFA | Enforced TOTP + WebAuthn passkeys, MFA enrolment reporting |
| CC6.7 / CC6.8 | Endpoint management and software restriction | Endpoint agent inventory: installed software, OS version, device state |
| CC7.2 | System monitoring and audit-log retention | Tamper-evident activity log with configurable retention and export |
| CC7.3 / CC7.4 | Security-event evaluation and incident response | Incident workflow with deadlines, notification templates, evidence trail |
| CC8.1 | Change management for acquired components | Software catalog with version history and vendor lifecycle tracking |
| CC9.2 | Vendor and third-party risk management | Software vendor inventory tied to spend, contracts, and renewal dates |
Contribution scope varies by criterion: for some (CC6.2, CC6.3) the inventory is primary evidence; for others (CC7.3, CC9.2) it is one input to a control your team owns end to end.
The identity stack behind CC6
Access-control evidence is only as good as the access control. The platform ships the identity features a US buyer expects on day one: SAML 2.0 single sign-on, SCIM 2.0 provisioning against Okta and Microsoft Entra with automatic joiner-mover-leaver role sync, enforced MFA with TOTP and WebAuthn passkeys, and per-tenant plus per-token IP allowlists. Every grant and revoke lands in the audit log with its provenance.
Go deeper on SOC 2 asset evidence
Start with the free SOC 2 asset inventory template (hardware, SaaS, and cloud sheets plus a review log), then three guides unpack the asset side of a SOC 2 audit in working detail:
-
SOC 2 asset inventory: what auditors actually ask for
The evidence request behind CC6.1: ownership, reconciliation, and the export formats auditors accept.
-
Offboarding evidence for SOC 2: proving devices came back
Leaver-by-leaver proof that hardware was recovered and access revoked, tied to dates.
-
SOC 2 Type II: evidence across the observation window
Why a snapshot export fails a Type II sample, and what continuous records look like.
See your CC6 evidence in 30 minutes
Bring your auditor's evidence request list. We'll walk through the pack, the crosswalk, and the identity stack against a live workspace.