SOC 2 Compliance Checklist | Certifyi
Compliance checklist

SOC 2 Compliance Checklist

SOC 2 evaluates how you collect, process, store, and access customer data. Here's the 9-step path most companies follow to get an audit-ready report.

  1. Choose your objectives

    Get clear on why you're pursuing SOC 2: a specific customer deal, a new market, or strengthening your security posture. This shapes every decision that follows.

  2. Pick Type 1 or Type 2

    Type 1 reports on controls at a single point in time and is faster to produce. Type 2 confirms controls worked over a 3-12 month observation window and is what most enterprise buyers eventually expect.

  3. Define your scope

    Security is mandatory. Add Availability, Confidentiality, Processing Integrity, or Privacy based on what your customers actually care about, not a blanket 'include everything' approach.

  4. Run an internal risk assessment

    Identify threats and vulnerabilities, score each by likelihood and impact, and map controls to the risks that matter most. Skip the gut-feel scoring and use a consistent framework.

  5. Close the gaps

    Compare your current controls against SOC 2 requirements and remediate what's missing before the auditor finds it for you.

  6. Implement and test controls

    Put the missing controls in place, then test that they actually work as designed. This is where most Type 2 audits succeed or stall.

  7. Run a readiness assessment

    A dry run: gap analysis, controls matrix, and a mock version of the auditor's document request list, so nothing is a surprise during the real audit.

  8. Complete the audit

    An independent CPA firm reviews your evidence and issues the report. Type 1 typically takes weeks; Type 2 includes the observation period plus a few weeks of fieldwork.

  9. Move to continuous monitoring

    SOC 2 is annual, not one-and-done. Automated, continuous evidence collection keeps you audit-ready instead of scrambling every twelve months.

← Back to all checklists

What auditors actually ask for

  • Can you show every employee completed background checks and security training?
  • Can you prove code changes were peer-reviewed before merge?
  • Can you demonstrate access was revoked when someone left, with dates?
  • Can you show endpoint encryption is enforced across all devices?
  • Can you produce evidence covering the entire observation window, not just today?

Where teams most often trip up

  • Evidence dated outside the observation window, the single most common Type 2 finding
  • Leaving a relevant Trust Service Criterion out of scope, then having a customer demand it
  • Scoring risks on gut feel rather than a documented methodology
  • Discovering a failing control during fieldwork instead of in a readiness review
  • Treating the report as the finish line rather than an annual cycle

Realistic timeline

Type 1: roughly 1-3 months if baseline controls exist. Type 2: add the 3-12 month observation window plus 2-6 weeks of fieldwork.

Scroll to Top