SOC 2 Compliance Checklist
Every box, in order.This is the sequence we actually run for clients, condensed to a checklist. Work top to bottom: scoping mistakes are the expensive ones, and evidence problems surface last but start early.
01 Scope the program
- Pick your report type: Type I (point in time) or Type II (observation period) — most enterprise buyers expect Type II
- Select trust services criteria: Security is mandatory; add Availability or Confidentiality only if customers demand them
- Define the system boundary: which products, environments, and teams are in scope
- Set the deadline backwards from the deal that's driving this, including a 3-month observation window for a first Type II
- Assign an internal owner with real authority — a name, not a committee
02 Establish governance and policies
- Write and approve the core policy set: information security, access control, change management, incident response, vendor management, business continuity, data classification, acceptable use
- Tailor every policy to how you actually operate — auditors test against your own words
- Get executive sign-off and record it; ungoverned policies are findings
- Set an annual policy review cadence with named owners
- Roll out security awareness training and track completion
03 Implement technical controls
- Enforce SSO and MFA across production systems and the identity provider
- Implement least-privilege access with documented, quarterly access reviews
- Turn on audit logging for production infrastructure and retain logs
- Encrypt data at rest and in transit; document key management
- Stand up vulnerability scanning with severity-based remediation SLAs
- Establish change management: PRs, reviews, CI checks enforced by the pipeline
- Deploy endpoint management (MDM) covering disk encryption and screen lock
- Schedule an annual penetration test with a qualified independent tester
04 Operationalize evidence
- Connect cloud, identity, HR, and repo integrations to collect evidence automatically
- Map each control to its evidence source and owner
- Run onboarding/offboarding checklists that produce records, not just outcomes
- Track vendor security reviews with documented risk tiers
- Fix control drift as it happens — gaps during the observation window become exceptions in the report
05 Run the audit
- Select a CPA firm your buyers will recognize; get quotes early — good firms book out
- Complete a readiness assessment and close every gap before the window opens
- Freeze scope: no new products or environments mid-window without a plan
- Respond to auditor sample requests within days, not weeks
- Review the draft report for accuracy before it's finalized — especially system description and exceptions
Two notes from the field before you start. First: the most common failure mode isn’t a missing control — it’s an unowned program. Every stalled SOC 2 we’ve rescued had software, policies-in-progress, and no one whose job it was to finish. Second: auditors sample; they don’t inspect everything. What they sample, they expect to be boring — complete records, no surprises. Build for boring.
If a deal deadline makes the timeline impossible, read our guide to what SOC 2 actually costs and consider whether a done-for-you program beats hiring.
SOC 2 Compliance Services
Hands-on SOC 2 compliance services: gap assessment, control implementation, evidence collection, and audit support — platform included, experts driving.
Book a CallHow long does this checklist take to complete?
With an owner and automation: 8–12 weeks to audit-ready for most startups, plus the observation window for Type II. Without an owner, this checklist is where programs stall — usually at the policy and evidence stages.
Do I need every item for a Type I?
Nearly all — Type I tests the same controls at a point in time instead of over a period. Skipping the operational-evidence section is what makes a Type I feel easier, and it's exactly the gap a Type II then exposes.
Can software do this checklist for me?
Automation covers evidence collection and monitoring — roughly a third of the items. Policies, scoping, access decisions, and the audit itself need people. That split is exactly why we ship both.