34 of 61 Trust Services Criteria, from 53 mapping points, concentrated where an auditor samples hardest.
A Type II examination tests whether controls operated across an observation window of six months to a year, sampled on dates the auditor picks after the fact. A control that runs when someone remembers to run it will not survive that. Controls that run continuously produce their own evidence continuously.

Privacy is carried by CIAM, covering notice, consent capture, self-service access and correction, retention and disposal, disclosure records and breach notification. That accounts for 16 of the 18 Privacy criteria. The remainder of the Common Criteria is COSO governance: control environment, board oversight, communication, vendor risk.
| Module | Criteria | Count |
|---|---|---|
| CIAM Consent Manager | CC6.1, CC6.6, P1.1, P2.1, P3.1, P3.2, P4.1, P4.2, P4.3, P5.1, P5.2, P6.1, P6.2, P6.3, P6.4, P6.6, P6.7, P8.1 | 18 |
| IAM | CC5.2, CC6.1, CC6.2, CC6.3, CC6.6, CC7.2, CC7.3, CC7.4 | 8 |
| IGA | CC3.3, CC4.1, CC5.2, CC6.2, CC6.3, CC7.4 | 6 |
| DLP | CC3.2, CC6.7, CC7.3, C1.1, PI1.5, P6.3 | 6 |
| PAM | CC3.3, CC5.2, CC6.1, CC7.2, CC7.3 | 5 |
| UEM | CC3.2, CC6.8, CC7.1, CC7.2, CC7.3 | 5 |
| MDM | CC3.2, CC6.5, CC7.1, CC7.4, C1.2 | 5 |
The rest of SOC 2 is organisational: HR policies and background checks, board oversight, physical facility security, and the vendor risk process. Availability, three criteria covering recovery and capacity, sits with your infrastructure rather than with Akku.
Akku Cybersecurity Solutions itself holds SOC 2 Type II certification.