On your SOC 2 framework page (Prove → Compliance → Frameworks → SOC 2), the ⋮ menu holds two settings that affect your entire SOC 2 program — both worth understanding before you touch them.
Readiness Milestone: Type 1 vs. Type 2
Edit Milestone controls whether you're working toward a Type 1 (point-in-time) or Type 2 (over a monitoring period) report:
The in-app warning is direct about the blast radius: changing the readiness milestone affects the state of all related tasks and timelines. This isn't a cosmetic label — it's what "SOC 2 Type 2 Readiness: X%" on your Tasks page is actually measuring against. Only change it if you're confident it reflects your current audit goal, and check with support first if you're not sure what switching will do to work already in progress.
Trust Service Criteria
Manage Trust Service Criteria controls which of SOC 2's five criteria you're being assessed against:
Security, Availability, and Confidentiality are selected by default. Processing Integrity and Privacy are optional add-ons you can select if they're relevant to your business (e.g. Privacy if you handle significant personal data). As with the milestone, the in-app warning recommends checking with your customer success manager before changing this — it resyncs your framework's requirements, tests, and controls to match.


