Skip to content

A SOC 2 readiness checklist

By Sam Rivera, Founder, SentinelPanda · April 4, 2026 · 4 min read · SOC 2

A SOC 2 audit is mostly won before the auditor arrives. This checklist runs the program in the order auditors expect to find it.

1. Scope and timeline

  • Define the product or service in scope; identify what is explicitly out.
  • Confirm the mandatory Security (Common Criteria) category and decide whether Availability, Processing Integrity, Confidentiality, or Privacy are needed for the deals you want to close.
  • Decide Type I (design at a point in time) versus Type II (operating effectiveness over 3 to 12 months) for the first report.
  • Set the observation window for Type II; map calendar dates for the start, fieldwork, and report delivery.
  • Identify the named ISMS / security owner and the executive sponsor.

2. Governance and policies (CC1, CC2, CC5)

  • Information security policy: documented, approved, distributed to staff, version-controlled.
  • Acceptable use policy: signed by every employee at onboarding.
  • Code of conduct or ethics policy in place; disciplinary action recorded when invoked.
  • Organisational chart and role descriptions clear enough for an auditor to identify who owns what.
  • A way for outsiders to report security concerns (responsible-disclosure page).
  • Internal communication channel where security incidents and updates are circulated.

3. Risk and assessment (CC3)

  • Risk assessment methodology documented; not just a one-time spreadsheet.
  • Risk register populated with assets, threats, likelihood, impact, treatment decisions.
  • Fraud and significant-change considerations addressed.
  • Risk register reviewed at least annually and after material changes.

4. Monitoring activities (CC4)

  • Continuous monitoring program documented (not annual): vulnerability scanning, log monitoring, control self-assessment.
  • Internal control deficiencies tracked through a corrective-action workflow with root cause.
  • Evidence that monitoring findings have been remediated, with timestamps.

5. Access and identity (CC6) — where most evidence sits

  • Single source of truth for identities (Okta, Workspace, Entra) integrated with all production systems.
  • Multi-factor authentication enforced for every user with production access.
  • Provisioning and deprovisioning runbooks with HR-trigger automation where possible.
  • Quarterly access reviews documented; deviations remediated.
  • Privileged access (admin, root, break-glass) inventoried, reviewed, and used through audit-logged channels.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for credentials and customer data.
  • Key management procedure documented; key rotation evidenced.
  • Physical security covered through the cloud provider SOC 2 plus a documented carve-out and complementary user-entity controls.

6. System operations (CC7)

  • Vulnerability management programme: scan cadence, severity SLAs, remediation tracking.
  • Centralised logging with retention matching policy; logs tamper-resistant.
  • Alerting on critical security events; on-call rotation defined.
  • Incident response runbook tested at least annually (tabletop or real incident).
  • Backup procedure documented; restore tested at least once during the observation period.
  • Disaster recovery plan with documented RTO and RPO, tested per the policy cadence.

7. Change management (CC8)

  • Software development lifecycle documented: branch strategy, code review, automated testing, deployment.
  • Required reviewers on production code paths; review history retrievable from version control.
  • Separation of environments (dev / staging / production) with documented promotion controls.
  • Infrastructure changes go through the same review and audit trail as application code.
  • Emergency-change procedure documented with post-hoc review.

8. Vendor / risk mitigation (CC9)

  • Vendor inventory with each vendor tiered by data access and criticality.
  • Due-diligence evidence per vendor (SOC 2, AOC, ISO certificate, or questionnaire) attached and dated.
  • Annual vendor review per tier; off-boarding procedure documented.
  • Cyber insurance and business continuity arrangements documented.

9. Evidence and continuous collection

  • Per-control evidence list defined; each control has at least one piece of evidence collected on the cadence the auditor will test.
  • Continuous integrations (cloud config, identity, EDR, scanners, code) emit evidence on a schedule, not on demand the week before fieldwork.
  • Manual evidence (board minutes, signed policies, training acknowledgments) kept in the same repository as automated evidence.
  • Append-only audit log of administrative actions and control state changes.

10. Internal audit and management review (clause 9 equivalents)

  • Internal audit plan covering the in-scope controls, with independence from the control owner.
  • Internal audit findings tracked through corrective action with closure evidence.
  • Management review held at least once during the observation period with the documented input pack (audit results, performance trends, risks, incidents) and recorded decisions.

11. Auditor selection and pre-fieldwork

  • CPA firm shortlisted and selected before fieldwork is six weeks away; cheaper and faster to engage early.
  • Auditor walkthrough scheduled; trial balance of evidence available.
  • Section 3 (System Description) drafted and reconciled to the controls in Section 4.
  • Subservice organisation list confirmed; carve-out vs inclusive method decided per subservice.
  • Complementary user-entity controls drafted for inclusion in the report.

12. The final stretch

  • Fresh password-policy and access-review attestations dated within the observation window.
  • A clean week of evidence right before kickoff so the auditor sees current data.
  • Stakeholders briefed on the auditor walkthrough schedule.
  • Bridge-letter template drafted for customers receiving last-cycle SOC 2 while the new report is in production.
SOC 2 Common Criteria explained A compliance audit readiness checklist

Run your compliance program in one workspace.