Acme Corp's codebase was assessed against the AICPA Trust Services Criteria (2017, with 2022 revisions) (SOC 2 Type II Type II) using automated code-level analysis. The assessment covers 13 controls, of which 6 are testable at the code level (46% coverage).
CC5.1 Technology General Controls — 2 finding(s), severity MediumCC6.6 System Boundaries — 2 finding(s), severity MediumThis assessment covers CODE-LEVEL controls only. The following areas require separate, organizational assessment:
CC1.1 COSO Principle 1 — Integrity & EthicsCC2.1 Information for Internal UseCC3.1 Risk AssessmentCC4.1 Design & Operate Monitoring ControlsCC6.3 Access RemovalCC7.1 Monitoring of ControlsCC8.1 Change ManagementDisclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
I, the undersigned, have reviewed the above assessment and confirm that:
Name: Dana Lee
Title: Chief Information Security Officer
Signature: ____________________
Date: ____________________