SOC 2’s control coverage concept
This article explains the SOC 2 concept of "reasonable" control coverage
Written By Micah
What is reasonable coverage?
The SOC 2 framework is not prescriptive. There is no checklist of controls that will work for every organization. However, the SOC 2 framework will always include the Common Criteria (a.k.a the Security Trust Services Criteria), and organizations are required to demonstrate how they meet the criteria statements by applying their own, organization-specific controls.
The Common Criteria is comprised of 33* criteria statements, which are further broken down into 206 points of focus. The SOC 2 framework, which can be accessed via the Compliance Dashboard, shows a visual representation of the entire SOC 2 framework.
*If your organization includes Availability, Confidentiality, Processing Integrity, and/or Privacy in your SOC 2, there will be more than 33 criteria statements to meet.

Strike Graph maps controls to the 'point of focus' level. Think of the 'points of focus' as hints or suggestions on how to meet each 'parent' criteria.
While organizations are not required to identify, activate, and implement a control for every single point of focus, organizations must demonstrate adequate control coverage at the criteria level.
A control gap occurs when there is not adequate coverage; control gaps will cause issues when it's time to pass an audit.
As a general rule of thumb...
For CC.1.1 through CC.5.3:
Activate 2-3 controls for each of these criteria using the points of focus as your hints.
Activating the suggested controls will set you up nicely for coverage of these criteria.
For CC.6.1 through CC.9.2:
Try to activate a control for each point of focus; a control can be used more than once! Look at Fig. 3 below as an example.
Try for 100% coverage of all points of focus, but know that 80% might be the best you can do.
Tip: Auditors will test every control that you have activated, so only activate controls that are operating as intended and for which you are confident you can provide evidence.
How to determine whether you have adequate or reasonable coverage
Activating the Strike Graph suggested controls will start you off with reasonable control coverage. However, because every organization is unique and has its own risk appetite, there may be more work to do to ensure that control coverage truly is adequate.
Look over the criteria that are applicable to your SOC 2 efforts. Have you mapped a few controls to each of the criteria? Anywhere you see that there are no controls that align with the criteria or there are too few, you have a “gap” in coverage. Close these gaps by looking at the underlying points of focus (remember, these are hints or strong suggestions), and linking an existing control or adding a control not yet in your library.
Fig 1. Common Criteria
This image from the Compliance Dashboard SOC 2 framework illustrates Common Criteria CC.1.1 through CC.2.3.

Fig 2. Points of Focus
This image shows the points of focus for CC.1.1 . Each criteria is made up of points of focus.

Fig 3. Controls at the Point of Focus Level
This snapshot shows how controls are mapped to points of focus. Take note that the Change Management Policy control maps to both CC.8.1.2 and CC.8.1.3, which demonstrates that one control can be used for multiple points of focus.
