Checklist

SOC 2 audit preparation checklist

By the ShipReady Metrics research team. Published September 22, 2026. Sources are cited inline at the end of each page.

Work through the phases in order. Print this page and check items off, or copy it into your tracker. Every item maps to something an auditor will ask for later.

Phase 1 - Scope

Phase 2 - Controls

Phase 3 - Evidence

Phase 4 - Auditor

Phase 5 - Fieldwork and report

Frequently asked questions

How long does SOC 2 preparation take?

For a startup with reasonable engineering hygiene, weeks to a few months to be Type I ready. Type II adds the observation period on top. The longest pole is usually evidence collection history, which is why starting the clock early matters.

Should we do Type I first?

Usually yes. Type I gives customers something quickly and road-tests your evidence before the Type II observation period starts. Skipping it makes sense only when a customer contract demands Type II on a deadline.

What do auditors sample?

It depends on control frequency and the firm. Quarterly controls often get all instances examined; daily or continuous controls get samples across the period. Ask during planning so your evidence collection matches their method.

What are the most common first-audit findings?

Incomplete offboarding evidence, access reviews without documented sign-off, branch protection gaps, and vulnerability remediation without SLA tracking. All four are cheap to fix before fieldwork and embarrassing during it.

Sources