A SOC 2 readiness checklist
By Sam Rivera, Founder, SentinelPanda · April 4, 2026 · 4 min read · SOC 2
A SOC 2 audit is mostly won before the auditor arrives. This checklist runs the program in the order auditors expect to find it.
1. Scope and timeline
- Define the product or service in scope; identify what is explicitly out.
- Confirm the mandatory Security (Common Criteria) category and decide whether Availability, Processing Integrity, Confidentiality, or Privacy are needed for the deals you want to close.
- Decide Type I (design at a point in time) versus Type II (operating effectiveness over 3 to 12 months) for the first report.
- Set the observation window for Type II; map calendar dates for the start, fieldwork, and report delivery.
- Identify the named ISMS / security owner and the executive sponsor.
2. Governance and policies (CC1, CC2, CC5)
- Information security policy: documented, approved, distributed to staff, version-controlled.
- Acceptable use policy: signed by every employee at onboarding.
- Code of conduct or ethics policy in place; disciplinary action recorded when invoked.
- Organisational chart and role descriptions clear enough for an auditor to identify who owns what.
- A way for outsiders to report security concerns (responsible-disclosure page).
- Internal communication channel where security incidents and updates are circulated.
3. Risk and assessment (CC3)
- Risk assessment methodology documented; not just a one-time spreadsheet.
- Risk register populated with assets, threats, likelihood, impact, treatment decisions.
- Fraud and significant-change considerations addressed.
- Risk register reviewed at least annually and after material changes.
4. Monitoring activities (CC4)
- Continuous monitoring program documented (not annual): vulnerability scanning, log monitoring, control self-assessment.
- Internal control deficiencies tracked through a corrective-action workflow with root cause.
- Evidence that monitoring findings have been remediated, with timestamps.
5. Access and identity (CC6) — where most evidence sits
- Single source of truth for identities (Okta, Workspace, Entra) integrated with all production systems.
- Multi-factor authentication enforced for every user with production access.
- Provisioning and deprovisioning runbooks with HR-trigger automation where possible.
- Quarterly access reviews documented; deviations remediated.
- Privileged access (admin, root, break-glass) inventoried, reviewed, and used through audit-logged channels.
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for credentials and customer data.
- Key management procedure documented; key rotation evidenced.
- Physical security covered through the cloud provider SOC 2 plus a documented carve-out and complementary user-entity controls.
6. System operations (CC7)
- Vulnerability management programme: scan cadence, severity SLAs, remediation tracking.
- Centralised logging with retention matching policy; logs tamper-resistant.
- Alerting on critical security events; on-call rotation defined.
- Incident response runbook tested at least annually (tabletop or real incident).
- Backup procedure documented; restore tested at least once during the observation period.
- Disaster recovery plan with documented RTO and RPO, tested per the policy cadence.
7. Change management (CC8)
- Software development lifecycle documented: branch strategy, code review, automated testing, deployment.
- Required reviewers on production code paths; review history retrievable from version control.
- Separation of environments (dev / staging / production) with documented promotion controls.
- Infrastructure changes go through the same review and audit trail as application code.
- Emergency-change procedure documented with post-hoc review.
8. Vendor / risk mitigation (CC9)
- Vendor inventory with each vendor tiered by data access and criticality.
- Due-diligence evidence per vendor (SOC 2, AOC, ISO certificate, or questionnaire) attached and dated.
- Annual vendor review per tier; off-boarding procedure documented.
- Cyber insurance and business continuity arrangements documented.
9. Evidence and continuous collection
- Per-control evidence list defined; each control has at least one piece of evidence collected on the cadence the auditor will test.
- Continuous integrations (cloud config, identity, EDR, scanners, code) emit evidence on a schedule, not on demand the week before fieldwork.
- Manual evidence (board minutes, signed policies, training acknowledgments) kept in the same repository as automated evidence.
- Append-only audit log of administrative actions and control state changes.
10. Internal audit and management review (clause 9 equivalents)
- Internal audit plan covering the in-scope controls, with independence from the control owner.
- Internal audit findings tracked through corrective action with closure evidence.
- Management review held at least once during the observation period with the documented input pack (audit results, performance trends, risks, incidents) and recorded decisions.
11. Auditor selection and pre-fieldwork
- CPA firm shortlisted and selected before fieldwork is six weeks away; cheaper and faster to engage early.
- Auditor walkthrough scheduled; trial balance of evidence available.
- Section 3 (System Description) drafted and reconciled to the controls in Section 4.
- Subservice organisation list confirmed; carve-out vs inclusive method decided per subservice.
- Complementary user-entity controls drafted for inclusion in the report.
12. The final stretch
- Fresh password-policy and access-review attestations dated within the observation window.
- A clean week of evidence right before kickoff so the auditor sees current data.
- Stakeholders briefed on the auditor walkthrough schedule.
- Bridge-letter template drafted for customers receiving last-cycle SOC 2 while the new report is in production.