Free resources
/
SOC 2 Checklist

The Ultimate SOC 2 Checklist

A six-step checklist for SOC 2, from setting your scope and Trust Services Criteria to collecting the evidence an auditor signs off, whether you're going for Type 1 or Type 2.

SOC 2 is how a business proves it handles customer data the way it promises. A Type 1 report is a snapshot in time; a Type 2 report shows the same controls holding up across months of evidence. This checklist walks the six steps behind both, so you know what "in scope" means, what to put in place, and what an auditor will actually ask for.

What's inside:

  • Scope: clarify why you're doing SOC 2 and which Trust Services Criteria apply (Security, plus Availability, Confidentiality, Processing Integrity or Privacy)
  • Foundation: the policies, owners and team training a SOC 2 programme rests on
  • Internal audit: run a gap analysis to find the weak spots before your auditor does
  • Controls: access control, MFA, vendor management, logging and incident response, in practice
  • Documentation: the records, version control and full-period evidence a Type 2 report needs
  • Stay compliant: the reviews, risk assessments and continuous monitoring that keep the report clean year on year

By the end, you'll know which controls you can already evidence, where the gaps are, and what "audit-ready" looks like for SOC 2 specifically, and how to hold it across the whole reporting period.

Questions? We've
Got You Covered

Planning an audit? These will help.
For anything else, just ask.

What is SOC 2?

SOC 2 is an audit framework, developed by the AICPA, that reports on how a service organisation manages customer data against five Trust Services Criteria: security, availability, confidentiality, processing integrity and privacy. It's the de facto trust standard for B2B SaaS.

What's the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses whether your controls are designed correctly at a single point in time. A Type 2 report tests whether those controls actually operated effectively across a period, usually three to twelve months. Type 2 carries more weight because it proves consistency, not just intent.

Who is this SOC 2 checklist for?

Security, IT and compliance leads at SaaS and technology companies preparing for a first SOC 2 audit, or tightening up before a renewal. It's written for the person running the project, not for an auditor.

How long does SOC 2 take?

Type 1 can be reached once your controls are designed and documented. Type 2 then needs an observation window, commonly three to twelve months of evidence, on top. The checklist helps you scope that window early so it doesn't catch you out.

Is the checklist really free?

Yes. Add a business email and the download unlocks straight away. No demo required, just the checklist.