Settings
Organization, notifications, audit periods, and framework currency.
SOC 2 Type II requires a defined observation window (typically 6–12 months). Create a period before your audit starts.
Create new period
Your Scorifya Controls license key. Check runs and attestations are paused when inactive.
Keys are validated against your LICENSE_VALIDATION_URL. Without a validation server, keys stay inactive unless LICENSE_DEV_MODE=1 is set for local development.
Generate a time-limited read-only link to share with your auditor or CPA firm. Each link shows all automated check results, manual control attestations, and RFC 3161 timestamps.
Generate new link
The framework versions your Controls instance is mapped against, when Scorifya last confirmed them, and where the canonical source lives.
AICPA Trust Services Criteria. Base is 2017; points of focus were revised in 2022 without a version bump (still referred to as TSC 2017).
Released June 2024. All future-dated 4.0 requirements have been enforceable since 31 March 2025.
Third edition. Annex A restructured to 93 controls in 4 themes (Organizational, People, Physical, Technological). Companion guidance is ISO/IEC 27002:2022. Amendment 1:2024 (climate action) is published and acknowledged in the framework-watch baseline; it adds no Annex A controls and does not affect mappings.
Omnibus Final Rule baseline. A December 2024 NPRM proposes making all addressable implementation specifications required; re-check for the final rule at every review and bump the version if it lands. Breach Notification Rule (Subpart D, 164.400-414) citations are included for manual controls.
32 CFR Part 170 final rule. Level 1 is the 17 practices from FAR 52.204-21 basic safeguarding of Federal Contract Information (FCI), met by annual self-assessment plus an affirmation recorded in SPRS. Level 2 (110 NIST SP 800-171 controls, mostly C3PAO-assessed) is deliberately out of scope; revisit if L1 sees adoption.
When the authority publishes a new version, Scorifya updates the registry, refreshes the check mappings, and ships a Controls release. Upgrade with docker compose pull && docker compose up -d.
Checks should be reviewed against the current AICPA TSC 2017 (SOC 2), PCI DSS 4.0.1, and CIS Benchmarks at least quarterly.
Days until a new finding is due, by severity. These are your organization's policy, not framework requirements; auditors will ask whether you met your own targets, so pick numbers you can keep.
Every outbound connection this instance can make. Nothing else leaves your server: check results, evidence files, and cloud credentials stay local.
Probes the license server and timestamp authorities only. Cloud connectivity is tested per-integration on the Integrations page.