SIG Lite
Control CEK-08
Extractive Review Standard
How to answer 'What cryptographic algorithms are used for password and credential hashing?' on a SIG Lite
Reviewer Guidance & Pitfalls
Specify salted, adaptive hashing algorithms (Argon2id, bcrypt with work factor ≥ 12, or PBKDF2). State that MD5 and SHA-1 are strictly banned.
Example Answer Passing Enterprise Audit
Compliant Response Template
Internal passwords and auth tokens are hashed using bcrypt with a work factor of 12 or Argon2id with unique cryptographic salts per record; legacy hash functions (MD5, SHA-1) are prohibited.
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.