SOC 2 Compliance

SOC 2 CC7.5 — Automated DR test evidence for Kubernetes

SOC 2 Trust Services Criteria CC7.5 requires that organizations “test recovery plan procedures supporting system recovery to meet its objectives.” Most Kubernetes teams produce this evidence manually — once a year, scrambling before the audit.

Without Kymaros

  • Annual DR test — a painful, manual, multi-day exercise
  • Evidence is screenshots, Confluence pages, and Slack threads
  • No way to prove continuous testing between audits
  • Auditor asks 'what about the other 364 days?' — no answer
  • Team scrambles 2 weeks before the audit to produce evidence

With Kymaros

  • Nightly automated restore tests — 365 per year
  • Every test produces a timestamped RestoreReport CRD
  • Confidence score, validation details, RTO measurement
  • 90-day heatmap calendar shows continuous coverage
  • Export compliance dashboard to PDF — audit-ready in seconds

What your auditor receives

A single compliance dashboard with everything they need. No digging through Jira tickets or Slack messages.

Tests executed

Total number of restore tests in the audit period

Average confidence score

Mean score across all tests — target > 85

Namespace coverage

X/X namespaces = 100% — no blind spots

Days with passing tests

365/365 — continuous, not annual

Incidents detected & resolved

Score drops caught and fixed before they mattered

Average RTO vs target

Actual restore time measured against your SLA

365
documented DR tests per year

Generated automatically. No manual effort. No consultants.

20h
saved per audit cycle

No more reconstructing DR evidence from memory and Confluence pages.

0
audit findings for DR testing

Every test is timestamped, scored, and traceable. Auditors love it.

How Kymaros maps to SOC 2 CC7.5

Each SOC 2 requirement is addressed by a specific Kymaros capability — automatically, not manually.

Test recovery plan procedures
Nightly automated restore tests with cron scheduling
Document test results
Timestamped RestoreReport CRDs with full validation details
Verify system recovery meets objectives
Confidence score (0-100) and real RTO vs SLA measurement
Identify and remediate deficiencies
Regression detection, score drop alerts, per-check failure details
Retain evidence for audit review
90-day dashboard history, CSV export, PDF compliance reports

Generate your first compliance report tonight

Install Kymaros, create a RestoreTest, and wake up to audit-ready DR evidence. No credit card for the Community tier.

Compliance reports available in the Team tier. The Community tier includes the full operator and scoring engine.