Checklist · 28 items · Updated July 2026

SOC 2 Compliance Checklist

Every box, in order.

This is the sequence we actually run for clients, condensed to a checklist. Work top to bottom: scoping mistakes are the expensive ones, and evidence problems surface last but start early.

01 Scope the program

  • Pick your report type: Type I (point in time) or Type II (observation period) — most enterprise buyers expect Type II
  • Select trust services criteria: Security is mandatory; add Availability or Confidentiality only if customers demand them
  • Define the system boundary: which products, environments, and teams are in scope
  • Set the deadline backwards from the deal that's driving this, including a 3-month observation window for a first Type II
  • Assign an internal owner with real authority — a name, not a committee

02 Establish governance and policies

  • Write and approve the core policy set: information security, access control, change management, incident response, vendor management, business continuity, data classification, acceptable use
  • Tailor every policy to how you actually operate — auditors test against your own words
  • Get executive sign-off and record it; ungoverned policies are findings
  • Set an annual policy review cadence with named owners
  • Roll out security awareness training and track completion

03 Implement technical controls

  • Enforce SSO and MFA across production systems and the identity provider
  • Implement least-privilege access with documented, quarterly access reviews
  • Turn on audit logging for production infrastructure and retain logs
  • Encrypt data at rest and in transit; document key management
  • Stand up vulnerability scanning with severity-based remediation SLAs
  • Establish change management: PRs, reviews, CI checks enforced by the pipeline
  • Deploy endpoint management (MDM) covering disk encryption and screen lock
  • Schedule an annual penetration test with a qualified independent tester

04 Operationalize evidence

  • Connect cloud, identity, HR, and repo integrations to collect evidence automatically
  • Map each control to its evidence source and owner
  • Run onboarding/offboarding checklists that produce records, not just outcomes
  • Track vendor security reviews with documented risk tiers
  • Fix control drift as it happens — gaps during the observation window become exceptions in the report

05 Run the audit

  • Select a CPA firm your buyers will recognize; get quotes early — good firms book out
  • Complete a readiness assessment and close every gap before the window opens
  • Freeze scope: no new products or environments mid-window without a plan
  • Respond to auditor sample requests within days, not weeks
  • Review the draft report for accuracy before it's finalized — especially system description and exceptions

Two notes from the field before you start. First: the most common failure mode isn’t a missing control — it’s an unowned program. Every stalled SOC 2 we’ve rescued had software, policies-in-progress, and no one whose job it was to finish. Second: auditors sample; they don’t inspect everything. What they sample, they expect to be boring — complete records, no surprises. Build for boring.

If a deal deadline makes the timeline impossible, read our guide to what SOC 2 actually costs and consider whether a done-for-you program beats hiring.

Don't Want to Run This Yourself?

SOC 2 Compliance Services

Hands-on SOC 2 compliance services: gap assessment, control implementation, evidence collection, and audit support — platform included, experts driving.

Book a Call
Frequently Asked
How long does this checklist take to complete?

With an owner and automation: 8–12 weeks to audit-ready for most startups, plus the observation window for Type II. Without an owner, this checklist is where programs stall — usually at the policy and evidence stages.

Do I need every item for a Type I?

Nearly all — Type I tests the same controls at a point in time instead of over a period. Skipping the operational-evidence section is what makes a Type I feel easier, and it's exactly the gap a Type II then exposes.

Can software do this checklist for me?

Automation covers evidence collection and monitoring — roughly a third of the items. Policies, scoping, access decisions, and the audit itself need people. That split is exactly why we ship both.