Your SOC 2 system description and control matrix, written to survive the audit
We draft your Section 3 system description against the AICPA description criteria (DC section 200) and build the control matrix your auditor will test against. Senior-led, matched to how your system actually operates, and defensible in fieldwork.
Investment One‑time engagement, fixed scope.
The two documents every SOC 2 audit is built on
Every SOC 2 examination rests on two documents that management, not the auditor, must produce. The system description is Section 3 of the report: your account of the services you provide, the system boundary, the infrastructure, software, people, procedures, and data inside it, your controls, your subservice organizations, and the complementary user entity controls your customers are expected to operate. The control matrix maps every one of those controls to the Trust Services Criteria it satisfies, its owner, its frequency, and the evidence that proves it operated.
Your auditor evaluates the description against the AICPA description criteria in DC section 200 and tests the controls in the matrix. When the description says one thing, the matrix says another, and observed practice says a third, the result is findings before fieldwork even gets moving. That inconsistency, not weak security, is one of the most common ways SOC 2 audits go wrong.
What is included
- A complete Section 3 system description drafted against each applicable DC section 200 criterion, in your voice, matching your actual system.
- System boundary definition: what is in scope, what is not, and why the line is defensible.
- Subservice organization analysis, including the inclusive versus carve-out decision and complementary subservice organization controls.
- Complementary user entity controls (CUECs) drafted so your customers' obligations are clear.
- A full control matrix mapping every control to its Trust Services Criteria, owner, frequency, and required evidence.
- A consistency check across the description, the matrix, your policies, and your GRC platform, so no document contradicts another.
Both documents are delivered audit-ready, in the format your CPA firm expects, with a walkthrough session so your team can stand behind every sentence.
Why this is not a template job
Compliance platforms and cheap consultancies hand you a generic description with your company name substituted in. Auditors have read that exact document hundreds of times, and since the market learned what automated compliance is worth, they read Section 3 more skeptically than ever. A description that does not match observed practice produces exceptions, and a boundary drawn wrong can invalidate the scope of the whole report.
Ledger Audits writes these documents the way an auditor reads them. The work is senior-led, built from interviews with your engineering and security team, and checked against the evidence your controls actually produce. We do readiness work only and never issue the report, which is exactly why our documents hold up when the CPA firm that does issue it starts asking questions.
The auditor does not test your security. The auditor tests whether your system operates the way your description says it does. Write the description wrong and you fail with good controls.
Who it is for
Companies heading into their first SOC 2 Type I or Type II that have never written a Section 3. Companies whose auditor rejected or heavily marked up a platform-generated description. Companies whose environment changed, through new products, acquisitions, or re-architecture, and whose description no longer matches reality. If you are further out from the audit, our SOC 2 readiness assessment covers the description review inside a full gap assessment.
How it runs
The engagement is fixed scope and typically takes two to three weeks. We interview your system owners, review your architecture, policies, and GRC platform, draft the description and matrix, run the consistency check, and walk your team through the final documents. If you want the underlying detail first, our guides to the system description and control matrix, the DC 200 description criteria, and building a control matrix cover what the standards require.
SOC 2 system descriptions, answered
What is a SOC 2 system description?
The system description is Section 3 of a SOC 2 report. It is management's own account of the system being audited: the services provided, the system boundary, the components, the controls, subservice organizations, and complementary user entity controls. The auditor tests what the description says, so an inaccurate description produces findings before fieldwork begins.
Who writes the system description, the company or the auditor?
Management writes it. It is management's assertion, and the CPA firm evaluates whether it is fairly presented against the AICPA description criteria. Auditors cannot write it for you without impairing independence, which is why companies bring in an independent readiness firm to draft it properly.
What are the AICPA description criteria (DC section 200)?
DC section 200 is the AICPA's set of criteria governing what a system description must contain: services provided, system boundary and components, incidents, controls, subservice organizations, complementary user entity controls, and significant changes. Our DC 200 guide walks through each criterion.
What is a SOC 2 control matrix?
The master mapping between your controls and the Trust Services Criteria: for each control, the criterion it satisfies, the owner, how it operates, its frequency, and the evidence that proves it operated. It is the backbone your auditor tests against.
Can a GRC platform generate my system description?
Platforms provide templates, but a template cannot describe your real boundary, subservice organizations, or how controls actually operate. Generic language that does not match observed practice produces exceptions. We use your platform's output as an input, then write a description that matches reality.
How long does it take?
Typically two to three weeks for both deliverables, depending on the size of your environment and what documentation already exists.
How much does it cost?
It is a fixed-scope, one-time engagement, priced by the size of your environment and the criteria in scope. Book a call for pricing and we will confirm a written figure within one business day.
Do you issue the SOC 2 report itself?
No. Ledger Audits provides readiness and internal-audit work only. We prepare the system description and control matrix as management's documents, and you engage an independent licensed CPA firm for the attestation. Keeping those roles separate is what makes the result credible.
Get Section 3 off your plate
Tell us where you are in your SOC 2 journey and when fieldwork starts. We will scope the description and matrix and send a written figure within one business day.