SOC 2: Trust Services Criteria¶
Framework version: 2017 Trust Services Criteria, with revised points of focus (2022).
Criterion identifiers are AICPA's; the titles are short paraphrases. passmcp evidences criteria for the MCP servers it tests. It cannot make an organisation SOC 2 compliant: only a CPA firm's attestation over an audit period does that.
Every finding in a JSON report carries the controls it evidences under
controls.soc2. passmcp verify --framework soc2 reads an attestation offline
and reports each one below as evidenced, failing or not assessed, and passmcp evidence --framework soc2
builds a dated evidence bundle from attestations over an audit period.
Controls¶
| Control | Title | Evidenced by |
|---|---|---|
| CC1.1 | Commitment to integrity and ethical values | Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it. |
| CC1.2 | Board independence and oversight of internal control | Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it. |
| CC1.3 | Structures, reporting lines, authorities and responsibilities | Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it. |
| CC1.4 | Commitment to attract, develop and retain competent individuals | Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it. |
| CC1.5 | Accountability for internal control responsibilities | Not covered by passmcp: The control environment (governance, ethics, competence, accountability) is an organisational matter; no test of a server can evidence it. |
| CC2.1 | Relevant, quality information to support internal control | Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server. |
| CC2.2 | Internal communication of objectives and responsibilities | Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server. |
| CC2.3 | Communication with external parties | Not covered by passmcp: Information and communication within the organisation are organisational processes, not properties of an MCP server. |
| CC3.1 | Objectives specified to identify and assess risks | Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself. |
| CC3.2 | Identification and analysis of risks | Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself. |
| CC3.3 | Potential for fraud in assessing risks | Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself. |
| CC3.4 | Identification and assessment of significant changes | Not covered by passmcp: Risk assessment is performed by the organisation. passmcp's findings can be an input to it, but they do not evidence the assessment itself. |
| CC4.1 | Ongoing and separate evaluations of internal control | Not covered by passmcp: Monitoring of internal control is the organisation's evaluation process; a scheduled passmcp run can support it, but no single check evidences it. |
| CC4.2 | Evaluation and communication of internal control deficiencies | Not covered by passmcp: Monitoring of internal control is the organisation's evaluation process; a scheduled passmcp run can support it, but no single check evidences it. |
| CC5.1 | Control activities that mitigate risks | Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process. |
| CC5.2 | General control activities over technology | Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process. |
| CC5.3 | Control activities deployed through policies and procedures | Not covered by passmcp: Selecting and deploying control activities through policy is an organisational process. |
| CC6.1 | Logical access security software, infrastructure and architectures | a2a.unauthenticated, auth.rejects_garbage, auth.token, auth.token.expiry, auth.token.type, auth.unauthenticated_tools, auth.wrong_audience, discovery.as, discovery.as.grants, discovery.as.https, discovery.as.pkce, discovery.challenge, discovery.dpop, discovery.first_contact, discovery.prm, discovery.prm.resource, fs.credential_probe, handshake.session, protocol.bogus_session, resilience.token_refresh, stdio.environment |
| CC6.2 | Registration and authorisation of new users before access | auth.registration, discovery.enterprise_managed, discovery.registration |
| CC6.3 | Authorisation, modification and removal of access, by role and least privilege | auth.token.scope, catalog.tools.annotation_honesty, catalog.tools.annotations, catalog.tools.idempotency, discovery.challenge.scope |
| CC6.4 | Restriction of physical access to facilities and assets | Not covered by passmcp: Physical access is outside what a network or process test can observe. |
| CC6.5 | Discontinuation of logical and physical protections over assets | Not covered by passmcp: Disposal and discontinuation of protections over assets are not observable from a live server. |
| CC6.6 | Security measures against threats from outside the system boundaries | a2a.unauthenticated, auth.unauthenticated_tools, egress.hosts, egress.undeclared_host, performance.rate_limit, protocol.origin, stdio.bind_all |
| CC6.7 | Restriction of the transmission, movement and removal of information | a2a.transport, catalog.toxic_combination, discovery.as.https, egress.hosts, egress.undeclared_host, fs.canary_exfiltrated, net.scheme, net.tls, net.tls.cert, net.tls.version, stdio.post_init_connections |
| CC6.8 | Prevention or detection of unauthorised or malicious software | stdio.post_init_processes, stdio.post_init_writes |
| CC7.1 | Detection of configuration changes and newly discovered vulnerabilities | catalog.baseline, catalog.names.confusable, catalog.text.comments, catalog.text.cross_server_shadowing, catalog.text.encoded, catalog.text.hidden, catalog.text.instructions, catalog.text.secret_paths, catalog.text.shadowing, execution.output_injection, handshake.instructions, protocol.invalid_params, protocol.malformed_json, protocol.unknown_method, protocol.unknown_tool |
| CC7.2 | Monitoring of system components for anomalies | Not covered by passmcp: Anomaly monitoring of production systems is the operator's monitoring, not a point-in-time test. |
| CC7.3 | Evaluation of security events | Not covered by passmcp: Evaluating security events is an incident process run by people. |
| CC7.4 | Response to identified security incidents | Not covered by passmcp: Incident response is an organisational process. |
| CC7.5 | Recovery from identified security incidents | Not covered by passmcp: Recovery from incidents is an organisational process. |
| CC8.1 | Authorisation, design, testing, approval and implementation of changes | catalog.baseline, stdio.launch_config |
| CC9.1 | Risk mitigation for business disruptions | Not covered by passmcp: Business-disruption risk mitigation (insurance, continuity planning) is organisational. |
| CC9.2 | Assessment and management of risks from vendors and business partners | a2a.card_signature, supply.buildinfo, supply.provenance |
| A1.1 | Management of processing capacity to meet demand | execution.payload_size, performance.concurrency, performance.ping, performance.rate_limit, performance.throttle, performance.tools, performance.warmup, resilience.soak_memory |
| A1.2 | Environmental protections, backup and recovery infrastructure | resilience.session_reinit, resilience.stateless, resilience.upstream_down |
| A1.3 | Testing of recovery plan procedures | Not covered by passmcp: Testing recovery plans is an exercise run by the organisation, not by passmcp. |
| C1.1 | Identification and maintenance of confidential information | catalog.personal_data |
| C1.2 | Disposal of confidential information | Not covered by passmcp: Disposal of confidential information is not observable from a live server. |
Checks¶
| Check | Controls |
|---|---|
a2a.card_schema |
None: protocol conformance and interoperability: it shows the agent card is valid A2A, which no control in this framework requires |
a2a.card_signature |
CC9.2 |
a2a.transport |
CC6.7 |
a2a.unauthenticated |
CC6.1, CC6.6 |
auth.mode |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
auth.registration |
CC6.2 |
auth.rejects_garbage |
CC6.1 |
auth.source.* |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
auth.token |
CC6.1 |
auth.token.expiry |
CC6.1 |
auth.token.scope |
CC6.3 |
auth.token.type |
CC6.1 |
auth.unauthenticated_tools |
CC6.1, CC6.6 |
auth.wrong_audience |
CC6.1 |
catalog.baseline |
CC7.1, CC8.1 |
catalog.budget.tokens |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.cache_hints |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.empty |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.names.confusable |
CC7.1 |
catalog.personal_data |
C1.1 |
catalog.prompts.descriptions |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.prompts.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.mime |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.templates |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.resources.uris |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.semantic.ambiguity |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.text.comments |
CC7.1 |
catalog.text.cross_server_shadowing |
CC7.1 |
catalog.text.encoded |
CC7.1 |
catalog.text.hidden |
CC7.1 |
catalog.text.instructions |
CC7.1 |
catalog.text.secret_paths |
CC7.1 |
catalog.text.shadowing |
CC7.1 |
catalog.tools.annotation_honesty |
CC6.3 |
catalog.tools.annotations |
CC6.3 |
catalog.tools.descriptions |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.idempotency |
CC6.3 |
catalog.tools.input_schema |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.list |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.output_schema |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.title |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.tools.unique |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
catalog.toxic_combination |
CC6.7 |
discovery.as |
CC6.1 |
discovery.as.grants |
CC6.1 |
discovery.as.https |
CC6.1, CC6.7 |
discovery.as.pkce |
CC6.1 |
discovery.assemble |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.challenge |
CC6.1 |
discovery.challenge.scope |
CC6.3 |
discovery.creds_unused |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.dpop |
CC6.1 |
discovery.enterprise_managed |
CC6.2 |
discovery.first_contact |
CC6.1 |
discovery.override |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.override.build |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
discovery.prm |
CC6.1 |
discovery.prm.resource |
CC6.1 |
discovery.registration |
CC6.2 |
egress.hosts |
CC6.6, CC6.7 |
egress.undeclared_host |
CC6.6, CC6.7 |
execution.content |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.error_guidance |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.output_injection |
CC7.1 |
execution.payload_size |
A1.1 |
execution.policy |
None: records how passmcp ran (its configuration, mode or the credentials it was given), which says nothing about the server's controls |
execution.prompts |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.resources |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.tools |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
execution.validation |
None: catalogue or response quality: it affects how well an agent can use the server, not a security or privacy control |
fs.canary_exfiltrated |
CC6.7 |
fs.credential_probe |
CC6.1 |
handshake.capabilities |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.initialize |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.instructions |
CC7.1 |
handshake.protocol_era |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.protocol_version |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.server_info |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
handshake.session |
CC6.1 |
handshake.stateless |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
net.dns |
None: a connectivity precondition for every other check, not evidence of a control |
net.scheme |
CC6.7 |
net.tcp |
None: a connectivity precondition for every other check, not evidence of a control |
net.tls |
CC6.7 |
net.tls.cert |
CC6.7 |
net.tls.version |
CC6.7 |
performance.concurrency |
A1.1 |
performance.ping |
A1.1 |
performance.rate_limit |
A1.1, CC6.6 |
performance.throttle |
A1.1 |
performance.tools |
A1.1 |
performance.warmup |
A1.1 |
protocol.accept_header |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.bogus_session |
CC6.1 |
protocol.deprecated_features |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.extensions |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.get_stream |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.id_echo |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.invalid_params |
CC7.1 |
protocol.malformed_json |
CC7.1 |
protocol.mrtr |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.origin |
CC6.6 |
protocol.ping |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.routing_headers |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.capability |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.lifecycle |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.undeclared |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.tasks.unknown_id |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
protocol.unknown_method |
CC7.1 |
protocol.unknown_tool |
CC7.1 |
protocol.version_header |
None: protocol conformance and interoperability: it shows the server speaks MCP correctly, which no control in this framework requires |
resilience.session_reinit |
A1.2 |
resilience.soak_memory |
A1.1 |
resilience.stateless |
A1.2 |
resilience.token_refresh |
CC6.1 |
resilience.upstream_down |
A1.2 |
stdio.alive |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.bind_all |
CC6.6 |
stdio.clean_exit |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.environment |
CC6.1 |
stdio.launch_config |
CC8.1 |
stdio.no_zombie |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.post_init_connections |
CC6.7 |
stdio.post_init_processes |
CC6.8 |
stdio.post_init_writes |
CC6.8 |
stdio.process |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.stderr |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
stdio.stdout_clean |
None: process hygiene of the server as a child program: it matters for running it reliably, not for a control in this framework |
supply.buildinfo |
CC9.2 |
supply.provenance |
CC9.2 |