Skip to main content
SOC 2 Readiness

SOC 2
Readiness Checklist

A Type 2 report covers a period, not a day, so evidence that was not being retained when that period opened cannot be produced when it closes. A missing control can be put in place. History cannot.

5
Trust Services Criteria
1
Mandatory (Security)
12 mo
Report validity

SOC 2 Readiness Checklist

Enter your work email for the printable worksheet — scope and criteria selection, the Type 1 / Type 2 decision, an evidence-retention audit to run before the window opens, and a control review.

By downloading, you agree to receive relevant communications. We respect your privacy.

The thing that actually bites

A Type 2 report describes a period, not a day

Type 1 evaluates whether controls were suitably designed at a point in time. Type 2 evaluates whether they operated effectively throughout a window. That difference is where readiness programmes come unstuck: a control implemented halfway through the window produces an exception for the first half, and a log retention shorter than the window means evidence that no longer exists by the time it is asked for.

Access-control logs

Change-management records

Incident-response records

Joiner, mover and leaver records

Access reviews

Backup and restoration testing

Vulnerability identification and remediation

Vendor and subservice reviews

Security-awareness training records

Policy approvals and reviews

For each of these the worksheet asks the same two questions: where is it retained, and does that retention cover every day of the window.

Scope

The five Trust Services Criteria

Security is the mandatory baseline for every SOC 2 report. The other four are elective — and each one added is more evidence to retain. Include a criterion because a buyer asks for it or because it is central to what you sell, not for completeness.

Security

Mandatory

Protection of the system against unauthorised access, use or modification. Required in every SOC 2 report.

Availability

Elective

That the system is available for operation and use as committed or agreed. Usually driven by an uptime commitment already in your contracts.

Processing Integrity

Elective

That processing is complete, valid, accurate, timely and authorised. Most relevant where the product’s value is the correctness of a computation.

Confidentiality

Elective

That information designated as confidential is protected as committed or agreed.

Privacy

Elective

That personal information is collected, used, retained, disclosed and disposed of appropriately. Distinct from Confidentiality — this one is about personal information specifically.

What it is

  • A framework from the American Institute of Certified Public Accountants.
  • A report issued by an independent CPA firm licensed by the AICPA. A consultant prepares you; only a CPA firm attests.
  • Valid for twelve months, then renewed with a new observation period and a new audit.
  • Six to twelve months from a standing start with minimal existing controls, including remediation and the observation period.

What it is not

  • Not a legal or regulatory mandate in India. It is a requirement your buyers impose.
  • Not a pass or fail certificate — the report describes what the auditor observed, including exceptions.
  • Not a penetration-testing mandate. SOC 2 requires that vulnerabilities are identified and addressed; how you do that is yours to evidence.
  • Not a one-off. The second observation window is worth booking before the first report lands.

Want the gap assessment behind the checklist?

Security Brigade prepares the controls, the evidence and the audit package, and works alongside the CPA firm that issues the report.

Talk to a compliance lead