Checklist · 24 items · Updated July 2026

Security Audit Checklist

Ready for whoever's asking.

SOC 2 auditor, ISO certification body, enterprise security team, or regulator — the questions overlap far more than the frameworks admit. This is the framework-agnostic preparation list that makes any of them boring.

01 Governance and paper

  • Current, approved policy set with dated executive sign-off and named owners
  • Risk assessment completed within the last 12 months, with a living risk register
  • Org chart of security responsibilities — who owns what, in writing
  • Security training completion records for all staff
  • Prior audit findings with remediation status — auditors always ask what the last one found

02 Identity and access

  • SSO and MFA enforced across production and the identity provider
  • Completed access reviews with recorded decisions for the last two cycles
  • Onboarding and offboarding records demonstrating timely provisioning and revocation
  • Privileged access inventory — who has admin, and why
  • Service accounts and API keys inventoried with owners and rotation dates

03 Infrastructure and data

  • Encryption at rest and in transit, with configuration evidence exportable
  • Audit logging enabled and retained per policy on in-scope systems
  • Network security rules documented and reviewed
  • Backups running with a completed restoration test on record
  • Data inventory: what sensitive data exists, where, and its retention schedule

04 Operations

  • Vulnerability scans across the last 12 months with SLA-tracked remediation
  • Current penetration test report with remediation and retest evidence
  • Incident records (or a tabletop exercise record) matching your response plan
  • Change management samples: ticket to review to deploy, traceable end to end
  • Endpoint management coverage report: encryption, screen lock, patching

05 Vendors

  • Vendor register with risk tiers and review dates
  • SOC 2 reports or equivalents on file for critical vendors
  • DPAs and BAAs executed where data categories require them
  • Sub-processor list current and published

The insight that makes audit prep cheap: auditors, enterprise reviewers, and regulators sample from the same underlying evidence pool. Maintain the pool continuously and every examination becomes an export; maintain it per-audit and you rebuild the same evidence annually at panic prices. The platform exists to make the pool self-maintaining; the gap assessment is how you find out where yours stands today.

Don't Want to Run This Yourself?

vCISO Services

Virtual CISO services for startups and scaleups: security strategy, compliance roadmap, enterprise deal support, and board reporting — without the $300K hire.

Book a Call
Frequently Asked
How is this different from the SOC 2 checklist?

The SOC 2 checklist builds a program toward a specific report; this one verifies readiness for any external examination. Run this quarterly as an internal health check and you'll never cram for an audit again.

Who should run this checklist internally?

Whoever owns security — founder, engineering lead, or vCISO. The items requiring judgment (risk register, access decisions) need someone with authority; the evidence items can be delegated or automated.

What if we fail half the items?

That's a normal starting point, not a crisis. Sequence by sampling probability: access controls and governance paper first, operational evidence second, vendor hygiene third. A gap assessment turns this list into a dated plan.