Skip to content

SOC 2: Trust Services Criteria

Framework version: 2017 Trust Services Criteria, with revised points of focus (2022).

Criterion identifiers are AICPA's; the titles are short paraphrases. passmcp evidences criteria for the MCP servers it tests. It cannot make an organisation SOC 2 compliant: only a CPA firm's attestation over an audit period does that.

Every finding in a JSON report carries the controls it evidences under controls.soc2. passmcp verify --framework soc2 reads an attestation offline and reports each one below as evidenced, failing or not assessed, and passmcp evidence --framework soc2 builds a dated evidence bundle from attestations over an audit period.

Controls

Control Title Evidenced by
CC1.1 Commitment to integrity and ethical values Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it.
CC1.2 Board independence and oversight of internal control Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it.
CC1.3 Structures, reporting lines, authorities and responsibilities Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it.
CC1.4 Commitment to attract, develop and retain competent individuals Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it.
CC1.5 Accountability for internal control responsibilities Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it.
CC2.1 Relevant, quality information to support internal control Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server.
CC2.2 Internal communication of objectives and responsibilities Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server.
CC2.3 Communication with external parties Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server.
CC3.1 Objectives specified to identify and assess risks Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself.
CC3.2 Identification and analysis of risks Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself.
CC3.3 Potential for fraud in assessing risks Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself.
CC3.4 Identification and assessment of significant changes Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself.
CC4.1 Ongoing and separate evaluations of internal control Not covered by passmcp: Monitoring of internal control is the organisation's evaluation process; a scheduled passmcp run can support it, but no single check evidences it.
CC4.2 Evaluation and communication of internal control deficiencies Not covered by passmcp: Monitoring of internal control is the organisation's evaluation process; a scheduled passmcp run can support it, but no single check evidences it.
CC5.1 Control activities that mitigate risks Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process.
CC5.2 General control activities over technology Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process.
CC5.3 Control activities deployed through policies and procedures Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process.
CC6.1 Logical access security software, infrastructure and architectures a2a.unauthenticated, auth.rejects_garbage, auth.token, auth.token.expiry, auth.token.type, auth.unauthenticated_tools, auth.wrong_audience, discovery.as, discovery.as.grants, discovery.as.https, discovery.as.pkce, discovery.challenge, discovery.dpop, discovery.first_contact, discovery.prm, discovery.prm.resource, fs.credential_probe, handshake.session, protocol.bogus_session, resilience.token_refresh, stdio.environment
CC6.2 Registration and authorisation of new users before access auth.registration, discovery.enterprise_managed, discovery.registration
CC6.3 Authorisation, modification and removal of access, by role and least privilege auth.token.scope, catalog.tools.annotation_honesty, catalog.tools.annotations, catalog.tools.idempotency, discovery.challenge.scope
CC6.4 Restriction of physical access to facilities and assets Not covered by passmcp: Physical access is outside what a network or process test can observe.
CC6.5 Discontinuation of logical and physical protections over assets Not covered by passmcp: Disposal and discontinuation of protections over assets are not observable from a live server.
CC6.6 Security measures against threats from outside the system boundaries a2a.unauthenticated, auth.unauthenticated_tools, egress.hosts, egress.undeclared_host, performance.rate_limit, protocol.origin, stdio.bind_all
CC6.7 Restriction of the transmission, movement and removal of information a2a.transport, catalog.toxic_combination, discovery.as.https, egress.hosts, egress.undeclared_host, fs.canary_exfiltrated, net.scheme, net.tls, net.tls.cert, net.tls.version, stdio.post_init_connections
CC6.8 Prevention or detection of unauthorised or malicious software stdio.post_init_processes, stdio.post_init_writes
CC7.1 Detection of configuration changes and newly discovered vulnerabilities catalog.baseline, catalog.names.confusable, catalog.text.comments, catalog.text.cross_server_shadowing, catalog.text.encoded, catalog.text.hidden, catalog.text.instructions, catalog.text.secret_paths, catalog.text.shadowing, execution.output_injection, handshake.instructions, protocol.invalid_params, protocol.malformed_json, protocol.unknown_method, protocol.unknown_tool
CC7.2 Monitoring of system components for anomalies Not covered by passmcp: Anomaly monitoring of production systems is the operator's monitoring, not a point-in-time test.
CC7.3 Evaluation of security events Not covered by passmcp: Evaluating security events is an incident process run by people.
CC7.4 Response to identified security incidents Not covered by passmcp: Incident response is an organisational process.
CC7.5 Recovery from identified security incidents Not covered by passmcp: Recovery from incidents is an organisational process.
CC8.1 Authorisation, design, testing, approval and implementation of changes catalog.baseline, stdio.launch_config
CC9.1 Risk mitigation for business disruptions Not covered by passmcp: Business-disruption risk mitigation (insurance, continuity planning) is organisational.
CC9.2 Assessment and management of risks from vendors and business partners a2a.card_signature, supply.buildinfo, supply.provenance
A1.1 Management of processing capacity to meet demand execution.payload_size, performance.concurrency, performance.ping, performance.rate_limit, performance.throttle, performance.tools, performance.warmup, resilience.soak_memory
A1.2 Environmental protections, backup and recovery infrastructure resilience.session_reinit, resilience.stateless, resilience.upstream_down
A1.3 Testing of recovery plan procedures Not covered by passmcp: Testing recovery plans is an exercise run by the organisation, not by passmcp.
C1.1 Identification and maintenance of confidential information catalog.personal_data
C1.2 Disposal of confidential information Not covered by passmcp: Disposal of confidential information is not observable from a live server.

Checks

Check Controls
a2a.card_schema None: protocol conformance and interoperability: it shows the agent card is valid A2A, which no control in this framework requires
a2a.card_signature CC9.2
a2a.transport CC6.7
a2a.unauthenticated CC6.1, CC6.6
auth.mode None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
auth.registration CC6.2
auth.rejects_garbage CC6.1
auth.source.* None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
auth.token CC6.1
auth.token.expiry CC6.1
auth.token.scope CC6.3
auth.token.type CC6.1
auth.unauthenticated_tools CC6.1, CC6.6
auth.wrong_audience CC6.1
catalog.baseline CC7.1, CC8.1
catalog.budget.tokens None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.cache_hints None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.empty None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.names.confusable CC7.1
catalog.personal_data C1.1
catalog.prompts.descriptions None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.prompts.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.mime None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.templates None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.resources.uris None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.semantic.ambiguity None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.text.comments CC7.1
catalog.text.cross_server_shadowing CC7.1
catalog.text.encoded CC7.1
catalog.text.hidden CC7.1
catalog.text.instructions CC7.1
catalog.text.secret_paths CC7.1
catalog.text.shadowing CC7.1
catalog.tools.annotation_honesty CC6.3
catalog.tools.annotations CC6.3
catalog.tools.descriptions None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.idempotency CC6.3
catalog.tools.input_schema None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.list None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.output_schema None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.title None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.tools.unique None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
catalog.toxic_combination CC6.7
discovery.as CC6.1
discovery.as.grants CC6.1
discovery.as.https CC6.1, CC6.7
discovery.as.pkce CC6.1
discovery.assemble None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.challenge CC6.1
discovery.challenge.scope CC6.3
discovery.creds_unused None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.dpop CC6.1
discovery.enterprise_managed CC6.2
discovery.first_contact CC6.1
discovery.override None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.override.build None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
discovery.prm CC6.1
discovery.prm.resource CC6.1
discovery.registration CC6.2
egress.hosts CC6.6, CC6.7
egress.undeclared_host CC6.6, CC6.7
execution.content None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.error_guidance None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.output_injection CC7.1
execution.payload_size A1.1
execution.policy None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls
execution.prompts None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.resources None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.tools None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
execution.validation None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control
fs.canary_exfiltrated CC6.7
fs.credential_probe CC6.1
handshake.capabilities None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.initialize None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.instructions CC7.1
handshake.protocol_era None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.protocol_version None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.server_info None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
handshake.session CC6.1
handshake.stateless None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
net.dns None: a connectivity precondition for every other check, not evidence of a control
net.scheme CC6.7
net.tcp None: a connectivity precondition for every other check, not evidence of a control
net.tls CC6.7
net.tls.cert CC6.7
net.tls.version CC6.7
performance.concurrency A1.1
performance.ping A1.1
performance.rate_limit A1.1, CC6.6
performance.throttle A1.1
performance.tools A1.1
performance.warmup A1.1
protocol.accept_header None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.bogus_session CC6.1
protocol.deprecated_features None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.extensions None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.get_stream None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.id_echo None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.invalid_params CC7.1
protocol.malformed_json CC7.1
protocol.mrtr None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.origin CC6.6
protocol.ping None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.routing_headers None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.capability None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.lifecycle None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.undeclared None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.tasks.unknown_id None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
protocol.unknown_method CC7.1
protocol.unknown_tool CC7.1
protocol.version_header None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires
resilience.session_reinit A1.2
resilience.soak_memory A1.1
resilience.stateless A1.2
resilience.token_refresh CC6.1
resilience.upstream_down A1.2
stdio.alive None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.bind_all CC6.6
stdio.clean_exit None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.environment CC6.1
stdio.launch_config CC8.1
stdio.no_zombie None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.post_init_connections CC6.7
stdio.post_init_processes CC6.8
stdio.post_init_writes CC6.8
stdio.process None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.stderr None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
stdio.stdout_clean None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework
supply.buildinfo CC9.2
supply.provenance CC9.2