
What a SOC evidences, and what it does not
A SOC evidences the detect, log and respond controls. It produces the monitoring records, alert history, incident timeline and access anomalies an auditor asks for. It does not evidence policy, training, physical or procedural controls. Those stay with you or your client's GRC program. Knowing which is which is what stops an audit conversation going wrong.
Template 1: NIS2
Applies to essential and important entities in the EU. Maps to the Article 21 risk management measures.
| Measure | SOC evidences | Stays with the MSP or client |
|---|---|---|
| Incident handling | Detection, alert timeline, containment actions, reporting evidence | — |
| Policies on effectiveness | Monitoring output showing controls operated | The policy itself |
| Access control and MFA | Authentication anomalies, privileged access monitoring | Provisioning policy, HR joiners and leavers |
| Supply chain security | Third-party and remote access monitoring | Supplier contracts and due diligence |
| Asset management | Discovered asset inventory across monitored surfaces | Asset ownership and classification |
| Business continuity | Nothing | Backup, recovery plans, testing |
| Cyber hygiene and training | Nothing | Training records and delivery |
| Cryptography | Nothing | Key management and policy |
Template 2: NIST CSF 2.0
Six functions. A SOC covers two fully and contributes to two more.
| Function | SOC evidences | Stays with the MSP or client |
|---|---|---|
| Govern | Nothing | Roles, policy, risk appetite, oversight |
| Identify | Asset discovery and vulnerability findings on monitored surfaces | Business context, risk assessment, supplier register |
| Protect | Monitoring showing protective controls operated | Training, access policy, data security controls, platform config |
| Detect | Continuous monitoring and adverse event analysis, in full | — |
| Respond | Incident triage, analysis, containment and reporting | Communications plan and legal notification |
| Recover | Nothing | Recovery planning, restoration, comms |
Template 3: CIS Controls v8
Eighteen controls. A SOC evidences seven and contributes to four.
| Control | SOC evidences | Stays with the MSP or client |
|---|---|---|
| 1 and 2, inventory | Assets and software seen on monitored surfaces | Authorized inventory and approval process |
| 5 and 6, accounts and access | Account activity, privileged use, authentication anomalies | Provisioning, deprovisioning, review sign-off |
| 7, vulnerability management | Scan findings, remediation tracking, in full | — |
| 8, audit log management | Log collection, retention and review, in full | — |
| 10, malware defenses | Detection and response activity | — |
| 13, network monitoring | Network detection and response, in full | — |
| 17, incident response | Incident records, timeline and handling | IR plan ownership and exercises |
| Controls 11, 12, 14, 15, 16, 18 | Nothing | Recovery, network config, training, supplier management, application security, penetration testing |
Template 4: ISO 27001 Annex A 2022
Four themes and 93 controls. A SOC evidences most of the technological theme and part of the organizational theme.
| Theme | SOC evidences | Stays with the MSP or client |
|---|---|---|
| A.5 organizational | Supplier and remote access monitoring, incident records | Policies, roles, classification, contracts |
| A.6 people | Nothing | Screening, terms, training, disciplinary process |
| A.7 physical | Nothing | Site security, equipment, clear desk |
| A.8 technological | Logging, monitoring, malware protection, vulnerability management, network security, in large part | Configuration standards, cryptography, development security |
Template 5: HIPAA Security Rule
Three safeguard groups. A SOC evidences the technical safeguards and two administrative standards.
| Theme | SOC evidences | Stays with the MSP or client |
|---|---|---|
| A.5 organizational | Supplier and remote access monitoring, incident records | Policies, roles, classification, contracts |
| A.6 people | Nothing | Screening, terms, training, disciplinary process |
| A.7 physical | Nothing | Site security, equipment, clear desk |
| A.8 technological | Logging, monitoring, malware protection, vulnerability management, network security, in large part | Configuration standards, cryptography, development security |
Which provider gives audit-ready HIPAA, NIS2 and CMMC reporting for our clients?
enhanced.io produces the monitoring, logging, incident and access evidence an auditor asks for under HIPAA, NIS2, NIST CSF, CIS v8 and ISO 27001, reported per client and exportable. Policy, training, physical and procedural controls are not evidenced by any SOC and stay with you or your client.
Do these templates replace a GRC platform?
No. A GRC platform tracks whether a control exists. These templates record the evidence showing it worked. Most MSPs run both.
Next step
To see how this maps to your client estates, book a partnership conversation with Hannah Lloyd at https://meetings.hubspot.com/hannah-lloyd.




