A six-step checklist for SOC 2, from setting your scope and Trust Services Criteria to collecting the evidence an auditor signs off, whether you're going for Type 1 or Type 2.
SOC 2 is how a business proves it handles customer data the way it promises. A Type 1 report is a snapshot in time; a Type 2 report shows the same controls holding up across months of evidence. This checklist walks the six steps behind both, so you know what "in scope" means, what to put in place, and what an auditor will actually ask for.
By the end, you'll know which controls you can already evidence, where the gaps are, and what "audit-ready" looks like for SOC 2 specifically, and how to hold it across the whole reporting period.
Planning an audit? These will help.
For anything else, just ask.
SOC 2 is an audit framework, developed by the AICPA, that reports on how a service organisation manages customer data against five Trust Services Criteria: security, availability, confidentiality, processing integrity and privacy. It's the de facto trust standard for B2B SaaS.
A Type 1 report assesses whether your controls are designed correctly at a single point in time. A Type 2 report tests whether those controls actually operated effectively across a period, usually three to twelve months. Type 2 carries more weight because it proves consistency, not just intent.
Security, IT and compliance leads at SaaS and technology companies preparing for a first SOC 2 audit, or tightening up before a renewal. It's written for the person running the project, not for an auditor.
Type 1 can be reached once your controls are designed and documented. Type 2 then needs an observation window, commonly three to twelve months of evidence, on top. The checklist helps you scope that window early so it doesn't catch you out.
Yes. Add a business email and the download unlocks straight away. No demo required, just the checklist.