Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant Common Criteria
Reference version: 2017 TSC (revised points of focus, 2022) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 9 IAM-relevant criteria
SOC 2 is evaluated against the AICPA's 2017 Trust Services Criteria with Revised Points of Focus (2022). The criteria are unchanged since 2017; only the points-of-focus guidance was refreshed, and this remains current in mid-2026. Security (the nine Common Criteria, CC1-CC9) is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional.
The IAM-relevant Common Criteria — logical access (CC6) and the monitoring/incident outcomes in system operations (CC7). This is NOT a full SOC 2 mapping; the rest of CC1-CC9 and the optional categories are out of scope. SOC 2 audits the service organisation's own controls; this shows how SimpliKeys helps a customer meet these criteria in its own report.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
SOC 2 is an attestation report by a licensed CPA firm (Type I on control design; Type II on operating effectiveness) — not a certification, and not something a tool confers. SimpliKeys can help meet specific criteria when appropriately configured, but the organisation's own controls are what the auditor evaluates. Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Logical access security software, infrastructure, and architectures are implemented to protect information assets (authentication, access control, segmentation, encryption, key management).
What SimpliKeys does
Is the logical access-security architecture: authenticates every request and enforces access by policy across the environment from one platform.
Customer responsibility & notes
SimpliKeys provides the access-and-authentication architecture. Encryption and key management for data at rest within this criterion are broader and remain the customer's.
New internal and external users are registered and authorized before credentials are issued; access is removed when no longer authorized; access is reviewed periodically.
What SimpliKeys does
Registers and authorizes identities through request/approval workflows, de-provisions access when no longer authorized, and runs periodic access-review campaigns.
Customer responsibility & notes
Customer defines approvers and review cadence; SimpliKeys provisions, de-provisions and recertifies, including contractor and vendor identities.
Access to data, software, and functions is authorized, modified, and removed based on roles, with least privilege and segregation of duties.
What SimpliKeys does
Authorizes, modifies and removes access by role with least privilege, and enforces segregation of duties at the access-to-application layer.
Customer responsibility & notes
SimpliKeys covers role-based authorization, least privilege and access change/removal. SoD is enforced at the access-to-application layer; SoD within an application is the application's function unless SimpliKeys is fed application data and configured for it.
Physical access to facilities and protected information assets is restricted to authorized personnel.
What SimpliKeys does
n/a — SimpliKeys manages logical access only.
Customer responsibility & notes
Physical / data-center access (badges, locks, visitor logs) is a separate control set outside SimpliKeys.
Logical access security measures protect against threats from sources outside the system boundary.
What SimpliKeys does
Applies strong authentication and policy at every external entry point, with adaptive, context-based decisions and a continuous Zero Trust posture.
Customer responsibility & notes
SimpliKeys is the identity layer at the boundary; network-perimeter controls sit alongside it and remain the customer's.
The transmission, movement, and removal of information is restricted to authorized users and processes, and information is protected in transit.
What SimpliKeys does
Restricts who can reach the data paths, brokering and recording the privileged sessions through which information moves.
Customer responsibility & notes
SimpliKeys controls and records the access paths. Data-loss prevention, data-movement controls and transmission encryption are broader and remain the customer's.
System components are monitored for anomalies that may indicate malicious acts, errors, or other security events, and anomalies are analyzed.
What SimpliKeys does
Monitors all actions taken by any identity on the network — person, non-human identity or AI agent — with behavioural analytics, and can shut down a compromised session immediately.
Customer responsibility & notes
Strong fit for identity/session anomaly detection. Broader infrastructure and application monitoring may use other tooling.
Security events are evaluated to determine whether they represent incidents that could affect the achievement of objectives.
What SimpliKeys does
Supplies the signals, alerts and behavioural-analytics output that feed event evaluation.
Customer responsibility & notes
SimpliKeys provides the telemetry and visibility that make evaluation easier; determining whether an event is an incident affecting objectives is an organisational triage decision the customer owns.
Identified incidents are responded to through a defined program (contain, remediate, communicate, restore).
What SimpliKeys does
Contains at the identity layer: immediately shuts down a compromised session and can revoke access or disable an account.
Customer responsibility & notes
SimpliKeys performs the identity-layer containment step. The full incident-response program — playbooks, communication, remediation and recovery — is broader and remains the customer's.
Mapping reflects the 2017 Trust Services Criteria (revised points of focus, 2022) as understood in mid-2026, reviewed criterion-by-criterion with SimpliKeys. Criterion text is paraphrased, not quoted. 'Supports' = capability provided when appropriately configured; the customer configures and operates its deployment, and its own controls are what the service auditor evaluates. SOC 2 is an attestation, not a certification. Confirm against your environment and your service auditor before relying on it.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo