Checklist
SOC 2 audit preparation checklist
Work through the phases in order. Print this page and check items off, or copy it into your tracker. Every item maps to something an auditor will ask for later.
Phase 1 - Scope
- Choose report type: Type I first (point in time) or straight to Type II (observation period)
- Select Trust Services Criteria: Security is mandatory; add Availability, Processing Integrity, Confidentiality or Privacy only where customers or contracts demand them
- Define the system boundary: products, environments, and data stores in scope
- Write the system description draft: services, infrastructure, people, data flow
- Identify subservice organizations (cloud provider, payroll, CI) and carve-out vs inclusive decisions
- Set the target report date and work backward to the fieldwork start
Phase 2 - Controls
- Map existing practices to the Common Criteria and write gap list
- Assign one named owner per control (a person, not a team)
- Close access-control gaps: SSO, MFA everywhere, offboarding SLA, least privilege
- Turn on change-management enforcement: branch protection, required review, CI gates
- Stand up vulnerability management: scanner, severity SLAs, tracked remediation
- Publish and collect acknowledgment on core policies: security, access, incident response, vendor management, business continuity
- Write the incident response plan and run one tabletop exercise
Phase 3 - Evidence
- Inventory the artifact each control produces and its source system
- Attach a collection cadence to every control; see our evidence freshness guide
- Automate collection from system APIs where possible before relying on screenshots
- Complete the first quarterly access review with sign-off
- Start the evidence clock early: Type II observation windows are calendar time
- Spot-check artifacts the way an auditor would; see SOC 2 evidence examples by control
Phase 4 - Auditor
- Shortlist licensed CPA firms with SaaS SOC 2 experience
- Confirm the firm accepts your evidence format (portal, export, or both)
- Get their sampling approach and request list in advance
- Agree the observation period and fieldwork dates in the engagement letter
- Name your internal audit liaison with authority to chase evidence
Phase 5 - Fieldwork and report
- Respond to requests with the mapped evidence, not raw exports dumped over the wall
- Track auditor follow-ups in a list with owners and dates
- Answer "show me this control in June" questions within days, not weeks
- Review the draft report's exceptions and write management's response where needed
- File the final report under NDA handling; set up the bridge letter process if the report date and customer needs will drift apart
- Convert every exception into next period's control improvements
Frequently asked questions
How long does SOC 2 preparation take?
For a startup with reasonable engineering hygiene, weeks to a few months to be Type I ready. Type II adds the observation period on top. The longest pole is usually evidence collection history, which is why starting the clock early matters.
Should we do Type I first?
Usually yes. Type I gives customers something quickly and road-tests your evidence before the Type II observation period starts. Skipping it makes sense only when a customer contract demands Type II on a deadline.
What do auditors sample?
It depends on control frequency and the firm. Quarterly controls often get all instances examined; daily or continuous controls get samples across the period. Ask during planning so your evidence collection matches their method.
What are the most common first-audit findings?
Incomplete offboarding evidence, access reviews without documented sign-off, branch protection gaps, and vulnerability remediation without SLA tracking. All four are cheap to fix before fieldwork and embarrassing during it.
Sources
- AICPA, SOC 2 overview: aicpa-cima.com