Can I remove or modify a control that doesn't apply to my organization?

Last updated: June 23, 2026

Context

SOC 2 is a flexible framework, and not every default control in your program will be applicable to every organization. You may find that certain controls don't match your current infrastructure, processes, or business model. For example, you may not have a VPN or a board.

Answer

Most of the time, controls can be removed or modified to better fit your organization. SOC 2 is not a prescriptive framework, so there is flexibility in how you meet the underlying requirements. However, before a control is removed, the Oneleet team will verify that the overarching SOC 2 requirement is still satisfied, either through compensating controls or an alternative approach.

To request a control removal or modification, follow these steps:

  1. Identify the control that doesn't apply to your organization.

  2. Reach out to your Security Program Manager (SPM) or vCISO via your shared Slack channel, providing:

    • The name or link to the control in question.

    • A clear rationale explaining why the control is not applicable (e.g., "We don't use IaC; infrastructure changes are managed manually through our platform").

    • If applicable, describe what compensating control or alternative process you have in place.

  3. Your SPM will review your information and either:

    • Remove the control from your program if it is not a hard SOC 2 requirement and the underlying criteria are met elsewhere.

    • Modify the control language to better reflect your actual practices.

    • Suggest a substitute control that satisfies the same SOC 2 requirement.

A few things to keep in mind:

  • Some controls may appear overly prescriptive but are not strict SOC 2 requirements (e.g., Infrastructure-as-Code). Your vCISO can help design a solution that works for you.

  • If you are unsure whether a control applies to you, you can flag it using the activity comments section on the control in the platform. The review team will provide feedback on whether it needs to be included or can be removed.

  • When a control is removed, a substitute control may be added to ensure the underlying SOC 2 criteria remain covered.

If you encounter a monitor failing for assets that are out of scope (e.g., non-production environments or infrastructure not relevant to your audit), you can also ignore specific assets directly from the Assets tab on the monitor, providing a justification for why they are excluded.