MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-63 — Security Compliance Certifications

SOC 2 Type II, ISO 27001/27017/27018, and PCI DSS scoping where applicable.

MCM-63 — Security Compliance Certifications

← Back to Legal & Compliance Readiness overview

As Compliance & Security Lead,
I want SOC 2 Type II certification in place, with ISO 27001/27017/27018 and PCI DSS scoped where applicable,
so that MCM can pass customer security reviews without ad hoc questionnaires blocking the sales cycle.

Acceptance Criteria

  • A SOC 2 Type II audit is scoped, an observation period is completed, and a report is issued covering, at minimum, the security, availability, and confidentiality trust service criteria.
  • ISO 27001 certification is obtained, or is actively in progress with a committed target date, for the information security management system covering the platform.
  • A scoping assessment determines whether PCI DSS applies — for example, if the finops module ever handles cardholder or payment data — and, if in scope, defines a compliance path.
  • Certification reports and attestations are available to share with prospective customers under NDA as part of the sales cycle.
  • Certification scope is reviewed whenever a new module or major capability (e.g., a new AI-driven action) is added, to confirm it falls within the certified boundary.

Technical Design

Certification scope has to track the platform's actual boundary rather than a fixed list from when the audit was first scoped: the SOC 2/ISO scope statement is reviewed each time a new module or a materially new capability ships, and the Compliance & Security Lead confirms the existing control set still covers it before that capability is folded into a future audit period.

On this page