SOC 2
Readiness Checklist
A Type 2 report covers a period, not a day, so evidence that was not being retained when that period opened cannot be produced when it closes. A missing control can be put in place. History cannot.
SOC 2 Readiness Checklist
Enter your work email for the printable worksheet — scope and criteria selection, the Type 1 / Type 2 decision, an evidence-retention audit to run before the window opens, and a control review.
Check your inbox
We've emailed you a link to download SOC 2 Readiness Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
Something went wrong. Please try again.
The thing that actually bites
A Type 2 report describes a period, not a day
Type 1 evaluates whether controls were suitably designed at a point in time. Type 2 evaluates whether they operated effectively throughout a window. That difference is where readiness programmes come unstuck: a control implemented halfway through the window produces an exception for the first half, and a log retention shorter than the window means evidence that no longer exists by the time it is asked for.
Access-control logs
Change-management records
Incident-response records
Joiner, mover and leaver records
Access reviews
Backup and restoration testing
Vulnerability identification and remediation
Vendor and subservice reviews
Security-awareness training records
Policy approvals and reviews
For each of these the worksheet asks the same two questions: where is it retained, and does that retention cover every day of the window.
Scope
The five Trust Services Criteria
Security is the mandatory baseline for every SOC 2 report. The other four are elective — and each one added is more evidence to retain. Include a criterion because a buyer asks for it or because it is central to what you sell, not for completeness.
Security
Mandatory
Protection of the system against unauthorised access, use or modification. Required in every SOC 2 report.
Availability
Elective
That the system is available for operation and use as committed or agreed. Usually driven by an uptime commitment already in your contracts.
Processing Integrity
Elective
That processing is complete, valid, accurate, timely and authorised. Most relevant where the product’s value is the correctness of a computation.
Confidentiality
Elective
That information designated as confidential is protected as committed or agreed.
Privacy
Elective
That personal information is collected, used, retained, disclosed and disposed of appropriately. Distinct from Confidentiality — this one is about personal information specifically.
What it is
- A framework from the American Institute of Certified Public Accountants.
- A report issued by an independent CPA firm licensed by the AICPA. A consultant prepares you; only a CPA firm attests.
- Valid for twelve months, then renewed with a new observation period and a new audit.
- Six to twelve months from a standing start with minimal existing controls, including remediation and the observation period.
What it is not
- Not a legal or regulatory mandate in India. It is a requirement your buyers impose.
- Not a pass or fail certificate — the report describes what the auditor observed, including exceptions.
- Not a penetration-testing mandate. SOC 2 requires that vulnerabilities are identified and addressed; how you do that is yours to evidence.
- Not a one-off. The second observation window is worth booking before the first report lands.
Want the gap assessment behind the checklist?
Security Brigade prepares the controls, the evidence and the audit package, and works alongside the CPA firm that issues the report.
Talk to a compliance lead