Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

We Open Sourced Our SOC 2 Resource Library

Direct answer: We published our SOC 2 resource list on GitHub as awesome-soc2, released into the public domain under CC0. It holds 216 entries across auditor directories, automation platforms, open-source tooling, evidence collection, cloud security, policy templates, training and community. It is free, it does not ask for your email, and you can fork it. This post explains what is in it, how to use it if you are at the start of a first audit, and what we deliberately left out.

Why a list rather than another guide

Search for SOC 2 guidance and you get roughly four things: vendor content that concludes you should buy the vendor, consultancy content that concludes you should book a call, AICPA source material that is authoritative and hard to read cold, and forum threads from people midway through their own audit. All four are useful. None of them tells you what exists.

The gap we kept hitting was inventory. A founder three weeks into a first SOC 2 does not need another explanation of what the Trust Services Criteria are. They need to know which audit firms work with companies their size, which open-source tools collect evidence without a platform subscription, and whether the policy templates they found are worth the download. That is a catalog problem, and catalogs belong in version control where anyone can correct them.

What is in it

The list is organized by what you are trying to do rather than by product category:

  • Official resources and standards. AICPA source material, the Trust Services Criteria, and SSAE 18, so the primary documents are one click away rather than behind somebody else's summary.
  • Readiness guides and checklists. Including our own free SOC 2 readiness checklist, which covers every criterion and is interactive.
  • Policy templates. Both ours and other open sets, so you can compare before adopting.
  • Automation platforms. The commercial GRC tools, listed without ranking, because the right one depends on your stack rather than on a leaderboard.
  • Open-source tools and evidence collection. The part most vendor content skips entirely.
  • Cloud security, split by AWS, Google Cloud, Azure and multi-cloud.
  • Monitoring and logging, access control and identity, vendor risk, penetration testing, incident response. The control areas that generate the most audit questions.
  • Training, books, courses, podcasts, newsletters and communities.
  • Consultants and service providers, split between audit firms and advisory. We are in the advisory section. We are not in the audit firm section, because we are not an audit firm and never will be.
Not sure where you stand? The readiness checklist walks every Trust Services Criterion and tells you what is missing before an auditor does. SOC 2 readiness checklist

How to use it at the start of a first audit

Read three sections and ignore the rest until you need them.

Start with official resources. Twenty minutes with the actual Trust Services Criteria is worth more than a week of secondary explanations, because every argument you will have with an auditor traces back to that document. You do not need to memorize it. You need to have seen it, so that when someone tells you a criterion requires something, you can check.

Then read the readiness guides and work out your gap honestly. The single most common expensive mistake in a first SOC 2 is starting the observation window before the controls actually operate, which produces a report full of exceptions and a second audit you did not budget for.

Then read the audit firm section and get three quotes. Quotes for the same scope vary by more than most people expect, and the variance is not explained by quality. We have saved clients an average of eleven thousand dollars on audit quotes simply by running a structured quote request rather than accepting the first number, and the list exists partly so you can run that process without us.

Everything else in the list is for later. Automation platforms matter once you know your control set. Evidence tooling matters once you know what you are evidencing. Reading them first is how a three month project becomes a nine month one.

What we left out, and why

No affiliate links anywhere. Not one. The moment a resource list earns money per click, its ordering stops being about usefulness, and readers can tell.

No rankings or scores on the commercial platforms. We have opinions about which GRC tools are worth the money, and those opinions depend so heavily on your cloud, your headcount and your framework count that publishing them as a league table would be misleading. If you want the opinion, ask us on a call and we will give it to you with the reasoning attached.

No dead resources. Every link was checked before publishing. Some will rot anyway, which is what the issue tracker is for.

No paywalled content presented as free. If something requires an email address or a credit card, the entry says so.

The honest caveat about lists like this

A curated list is a starting point, not a strategy. Knowing that eleven evidence collection tools exist does not tell you which controls you need evidence for, and a tool bought before the control is designed usually collects the wrong thing very efficiently.

The order that works is: understand the criteria, decide your scope, design the controls, then choose tooling that fits what you decided. Most failed first audits we are called into inverted that order, bought a platform in month one, and spent months eight and nine discovering that the platform's default control set did not match the system they actually run.

Contributing

Pull requests are open. If you maintain a tool that belongs on the list, or you spot a dead link, or you think an entry is described unfairly, open one. The contribution guidelines ask for one entry per pull request with a sentence saying what it does, which keeps review fast.

We will merge additions from competitors. A list that only contains its maintainer's friends is marketing, and the whole point was to publish something that stays useful after we stop paying attention to it.

The repository is at github.com/TrazTech-Inc/awesome-soc2. If it saves you an afternoon, that is the entire return we wanted.

Starting a first SOC 2? We run readiness end to end, hold the evidence record, and hand your auditor a scoped quote request rather than a conversation. First call is free and we will tell you if you are not ready to start.

SOC 2 readinessOr book a free call

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.