Compliance Artifacts

The SOC 2 system description, explained (with outline)

The SOC 2 system description is Section III of your report: a management-written narrative covering your infrastructure, software, people, procedures, and data, plus system boundaries, subservice organizations, and complementary user entity controls (CUECs). Here’s what it must include, who writes it, how auditors evaluate it, and an annotated outline of a strong one.
Talk to a Compliance Engineer
Last updated July 26, 2026