Tabletop exercise
SOC 2 (Trust Services Criteria) tabletop exercise
Trust service criteria for service providers handling customer data.
We can run the SOC 2 (Trust Services Criteria) exercise for your team, or set you up as a facilitator to run it yourself.
What the room works through
AICPA SOC 2 Trust Services Criteria (2017, 2022 revision)
SaaS service provider. Cover all five trust service criteria: security, availability, processing integrity, confidentiality, privacy. Use TSC references such as CC1.1, A1.2, PI1.1, C1.1, P2.1 and set domain to the criterion name.
- Clauses
- 40
- Rounds
- 10 across two stages
- Room size
- Up to 20 participants
Stage 1 — assess
Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a SOC 2 (Trust Services Criteria) clause.
Stage 2 — survive
Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.
What you take away
- Clause-by-clause coverage across SOC 2 (Trust Services Criteria)
- A gap list ranked by what the room could not defend
- Per-table divergence, so you can see where opinion split
- Word and CSV exports plus a drafted findings narrative
New to facilitating? Start with the facilitator manual or read the session walkthrough.