Practical checklist
SOC 2 readiness checklist
SOC 2 has no fixed control list. Your auditor tests the controls you claim to operate against the trust services criteria. In practice the same evidence gets requested at almost every company, and the list below is that evidence. Work through it before you book fieldwork and you will avoid most exceptions.
Before you start
Decide three things first: which criteria are in scope beyond Security, which systems and environments the report will cover, and whether you are aiming at a Type 1 or a Type 2. Every item below gets cheaper when the scope is narrow and honest. Excluding a product line you cannot yet evidence is normal, and buyers care far more about the report existing than about it covering everything.
Governance and policy
- A written information security policy set, approved and dated by a named owner
- Employee acknowledgement of policies at hire and annually after that
- A risk assessment with identified risks, owners, treatment and a review date
- An organisation chart and defined security responsibilities
- Board or leadership oversight recorded somewhere an auditor can see it
Access control
- Multi factor authentication enforced on email, cloud consoles and VPN
- A single source of truth for who works here and what they can reach
- Documented onboarding and offboarding with evidence for recent joiners and leavers
- Quarterly access reviews that have actually been performed and signed off
- Privileged access limited, justified and reviewed separately
Change and development
- Code review required before merge, with the setting enforced in the repository
- A deployment pipeline that records who shipped what and when
- Separate production and non production environments with no real customer data in test
- A tracked backlog for security issues with an agreed remediation timeframe
Operations and monitoring
- Centralised logging with a retention period that covers the audit window
- Alerting that someone is genuinely responsible for answering
- Vulnerability scanning on a defined cadence with evidence of fixes
- Backups configured, and at least one restore test you can show
- An incident response plan plus one tabletop exercise on record
Vendors and people
- A vendor inventory with criticality ratings and review dates
- Reports or assurance evidence collected for critical subservice providers
- Background checks where local law allows, evidenced for recent hires
- Security awareness training completed and recorded for everyone
What readiness costs
For a team of twenty with reasonable hygiene already in place, expect 80 to 200 internal hours to clear this list, spread across engineering, people operations and whoever owns the programme. At a fully loaded rate of around $85 an hour that is roughly $7,000 to $17,000 of time, before any tooling or audit fees. A readiness assessment from a consultancy runs somewhere between $5,000 and $25,000 and is worth it mainly when nobody in the company has been through an audit before.
The items that most often turn into exceptions are access reviews that were never actually performed, offboarding evidence for a leaver who kept access for three weeks, and log retention that is shorter than the observation window. Those three are cheap to fix in advance and expensive to fix during fieldwork.
Next steps
Price the whole programme with the SOC 2 cost calculator, plan the calendar with how long SOC 2 takes, and if you are weighing a platform to carry the evidence work, be honest about the saving using the automation ROI calculator.