Compliance·SOC 2

MCP server SOC 2 Type II security: trust service criteria, CC6, and evidence collection

MCP servers deployed as part of a SaaS product or used to process customer data fall within SOC 2 Type II scope. The AICPA's Trust Service Criteria apply — particularly CC6 (logical and physical access), CC7 (system operations and monitoring), and CC8 (change management). Here's how to map your MCP server's security controls to the criteria your auditor will test.

When does an MCP server enter SOC 2 scope?

SOC 2 scope encompasses all systems that store, process, or transmit customer data in support of the services under examination. An MCP server enters scope when it:

CC6: Logical and Physical Access Controls

CC6 is the most directly applicable trust service criterion for MCP servers. The criteria require that access to system resources is restricted to authorized users and that access is granted based on least-privilege principles.

CC7: System Operations and Monitoring

CC7 requires detection and response to security events. For MCP servers:

CC8: Change Management

CC8 requires that changes to system components are authorized, tested, and reviewed before implementation. For MCP servers this means:

Evidence collection: what SOC 2 auditors look for in MCP servers

Your auditor will request evidence demonstrating that controls are operating effectively over the audit period (typically 6–12 months). For MCP servers, collect:

SkillAudit's role in the SOC 2 evidence package

SkillAudit scans provide third-party security assessment evidence for the CC8 (change management) and CC7.1 (vulnerability management) criteria. The Team plan generates a dated, signed audit report for each scan — suitable for inclusion in your SOC 2 evidence package. The report includes finding severity classifications (Blocker/Major/Minor) aligned with CVSS scoring, which auditors can map to your organization's risk tolerance thresholds.

Running SkillAudit on every production MCP server deployment creates an audit trail showing that security testing was performed before each change was promoted — directly satisfying the CC8 testing requirement.

Generate SOC 2 evidence for your MCP server

SkillAudit's Team plan generates dated, exportable audit reports suitable for your SOC 2 evidence package. Free for public repos.

Run a free audit →

Related: MCP server audit trails for SOC 2 and GDPR · MCP server GDPR compliance · MCP security review checklist