Sample template. A starting point to adapt to your organization — not legal advice, and not a finished or binding document. Review with your own counsel before you rely on it.

SOC 2 readiness checklist

Updated

SOC 2 readiness is the work you do before an auditor arrives: deciding scope, implementing the controls the Trust Services Criteria expect, and gathering the evidence that shows they operate. This checklist is organized the way SOC 2 is — around the common criteria (Security), which every SOC 2 includes, plus the optional categories you may add. Work it top to bottom to find your gaps early, while they are cheap to fix.

SOC 2 is not a fixed control list; it is a set of criteria you meet with controls appropriate to your environment. So treat each item below as a question to answer with a real control and real evidence, not a box to assert. A Type I report covers design at a point in time; a Type II covers operating effectiveness over a period, which requires evidence spanning that period.

Step 1 — Scope the report

Decide two things first, because they shape everything else. Which Trust Services Categories are in scope — Security (the common criteria) is mandatory, and you add Availability, Confidentiality, Processing Integrity, or Privacy only if relevant to what you promise customers. And whether you are pursuing Type I (design at a point in time) or Type II (operating effectiveness over a period, typically several months).

  • Confirm the system boundary: which products, environments, and data are in scope.
  • Select Trust Services Categories — Security always; add others only where they apply.
  • Choose Type I vs Type II and, for Type II, set the observation period.
  • Identify the in-scope systems, sub-service organizations, and their CUECs.

Step 2 — Common Criteria (Security) controls

The common criteria are the heart of every SOC 2. They map roughly to the areas below; for each, you need a control that operates and evidence that it did. This is where most readiness gaps appear, so work it thoroughly.

  • Governance: security policies, roles, and a risk-assessment process that runs on a cadence.
  • Access controls: provisioning/deprovisioning, least privilege, MFA, and periodic access reviews.
  • Change management: reviewed, tested, approved changes with an audit trail (ITGCs).
  • Vulnerability management: scanning, prioritization, and remediation against a defined SLA.
  • Logging and monitoring: security event logging, alerting, and retention.
  • Incident response: a documented plan, defined roles, and evidence it has been exercised.
  • Vendor / sub-processor management: risk assessment and monitoring of critical third parties.
  • Data protection: encryption in transit and at rest, and key management.

Step 3 — Evidence and the pre-audit gap review

For a Type II report especially, evidence must span the observation period, not just exist today. Access reviews must show they were performed each period; change tickets must show approvals throughout; scans must show a history. Start collecting early — you cannot retroactively create a period's worth of evidence.

Before engaging an auditor, run your own gap review against this checklist and fix what you find. Readiness done well means the audit confirms what you already know rather than discovering surprises, which is both cheaper and faster than remediating mid-audit.

Frequently asked questions

What is on a SOC 2 readiness checklist?

Scoping (which Trust Services Categories and Type I vs Type II), then the common-criteria Security controls — governance, access, change management, vulnerability management, logging and monitoring, incident response, vendor management, and data protection — and finally evidence collection spanning the observation period plus a pre-audit gap review.

What is the difference between SOC 2 Type I and Type II?

Type I reports on whether controls are suitably designed at a single point in time. Type II reports on whether they operated effectively over a period, typically several months, which requires evidence spanning that whole period. Type II is more demanding and is what most enterprise customers ask for.

How long does SOC 2 readiness take?

It depends on how many controls are already in place and, for Type II, the length of the observation period, since evidence must span it. The controllable variable is starting evidence collection early — you cannot retroactively produce a period's worth of access reviews or change approvals — so a gap review well before the audit is the highest-leverage step.

See your SOC 2 gaps from real system evidence

ShipReady maps your connected systems to the Trust Services Criteria and shows which controls have supporting evidence and which are gaps — before you engage an auditor.