Compliance guide

SOC 2 Compliance Guide

SOC 2 auditors want proof that your security controls, including awareness training, actually operate. Claro produces the recurring, documented evidence a Type II examination relies on.

Regulator
AICPA (Trust Services Criteria)
Applies to
Service organizations that handle customer data

Overview

SOC 2 is an attestation report based on the AICPA Trust Services Criteria. It is widely used by SaaS providers and other service organizations to give customers independent assurance that they manage data responsibly. The report always covers the Security criterion, known as the common criteria, and can optionally include Availability, Processing Integrity, Confidentiality, and Privacy. For many Indonesian exporters selling to international customers, a SOC 2 report has become a routine expectation before a deal closes.

There are two types of SOC 2 report, and the distinction matters for evidence. A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report assesses whether those controls operated effectively over a period, typically several months to a year. Type II is more demanding precisely because it requires evidence that a control ran consistently throughout the period, not just that it existed on paper on one day.

Security awareness training sits within the Security criterion. The common criteria include control-environment and risk-related criteria that address whether personnel are competent, aware of their responsibilities, and trained to support the organization's security commitments. In practice, auditors commonly expect to see that employees complete security awareness training and that the training operates on a regular cadence. Evidence that the control actually ran, and reached the right people, is what a Type II examination scrutinizes.

This page is general guidance, not legal or audit advice. SOC 2 reports are issued only by an independent CPA firm after an examination, so the authoritative source is the AICPA Trust Services Criteria and your chosen auditor. Claro supports the awareness-training controls and produces the recurring evidence an examiner samples, but it does not by itself deliver a SOC 2 report or determine the outcome of an examination. The report reflects your whole control environment as assessed by the CPA.

What the rule expects

Security, the common criteria

Every SOC 2 report covers the Security criterion, which all service organizations must address regardless of which optional categories they add. It sets the baseline expectations for protecting systems and data. Awareness and competence controls live within this criterion.

A trained, aware control environment

The common criteria expect that personnel understand their security responsibilities and are trained to meet the organization's commitments. This is part of the control environment that underpins everything else. Auditors look for a program that keeps employees competent and aware, not a single onboarding slide.

Type I: control design at a point in time

A Type I examination assesses whether controls, including awareness training, are suitably designed as of a specific date. You must be able to describe how the control is meant to work and show it exists. This is often a first step before pursuing a Type II report.

Type II: operating effectiveness over a period

A Type II examination tests whether controls operated effectively throughout a review period, often six to twelve months. For awareness training, that means evidence the program ran on schedule and reached staff across the whole window. A control that lapsed mid-period is a finding.

Sampling and evidence of operation

Auditors sample records to confirm a control actually ran as described, so the evidence must be complete and retrievable. For awareness, this typically means completion records tied to individuals and dates. Gaps or missing records for part of the period undermine the control.

Regular cadence, not a one-time event

Because Type II looks at operation over time, awareness training is generally expected to recur on a defined schedule with coverage of new joiners. A program that happened once at the start of the period will not demonstrate consistent operation. Cadence and coverage both matter.

Reaching new joiners and the full population

The examination expects the control to reach the relevant population, including people who joined during the period. Evidence should show that onboarding training happened and that ongoing training covered current staff. Partial coverage is a common source of exceptions.

How Claro helps you comply

  • Run awareness training on a defined cadence

    Claro delivers security awareness through bilingual micro-modules and learning paths, with assignment rules that repeat on a schedule across the review period. This directly supports the recurring operation a Type II examination tests. SCORM 1.2 import lets you standardize existing courseware in the same system.

  • Produce completion records for sampling

    Claro keeps per-user completion records tied to individuals and dates, which is exactly what auditors sample to confirm a control operated. Records are organized and retrievable rather than scattered across spreadsheets. That reduces the friction of an examination window.

  • Demonstrate effectiveness with simulations

    Localized phishing simulations with per-recipient tracking of opens, clicks, submissions, and reports show that awareness translates into behavior. This gives an examiner more than attendance, evidencing that the control has a real effect. Results accumulate across the whole period.

  • Cover new joiners with assignment rules and JIT

    Assignment rules can enroll new joiners automatically, and just-in-time training triggers when a user fails a simulation. Together these help ensure the control reaches the full population across the period, including people who joined partway through. Coverage gaps are a common SOC 2 exception this addresses.

  • Export recurring evidence packages

    Claro generates evidence packages as ZIP bundles of Claro-style PDF reports and CSV exports, with scheduled delivery that keeps evidence current across the review window. When an examiner requests records for a given month, they are ready. This suits the continuous nature of a Type II period.

  • Keep evidence trustworthy and isolated

    Audit logs, per-tenant data isolation, and AES-256-GCM encryption of PII at rest help ensure the evidence itself is reliable and access-controlled. Per-user and per-department risk scoring adds a management view of the human layer. On-premise or SaaS deployment fits different data-handling needs.

Frequently asked questions

  • No. A SOC 2 report is issued only by an independent CPA firm after it examines your controls. Claro supports the security awareness controls within the Security criterion and produces the recurring evidence an examiner samples. It strengthens and documents part of what the auditor assesses, but it does not deliver the report.

This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.

Build defensible security awareness evidence

Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.

Request a demo