Tabletop exercise

SOC 2 (Trust Services Criteria) tabletop exercise

Trust service criteria for service providers handling customer data.

We can run the SOC 2 (Trust Services Criteria) exercise for your team, or set you up as a facilitator to run it yourself.

What the room works through

AICPA SOC 2 Trust Services Criteria (2017, 2022 revision)

SaaS service provider. Cover all five trust service criteria: security, availability, processing integrity, confidentiality, privacy. Use TSC references such as CC1.1, A1.2, PI1.1, C1.1, P2.1 and set domain to the criterion name.

Clauses
40
Rounds
10 across two stages
Room size
Up to 20 participants

Stage 1 — assess

Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a SOC 2 (Trust Services Criteria) clause.

Stage 2 — survive

Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.

What you take away

  • Clause-by-clause coverage across SOC 2 (Trust Services Criteria)
  • A gap list ranked by what the room could not defend
  • Per-table divergence, so you can see where opinion split
  • Word and CSV exports plus a drafted findings narrative

New to facilitating? Start with the facilitator manual or read the session walkthrough.

Other standards