SOC 2 Readiness Assessment Checklist

Use this SOC 2 Readiness Assessment Checklist to identify control gaps before audits, covering governance, access, change management, encryption & vendor risk.

SOC 2 Readiness Assessment Checklist



Audit Scope And Planning

1. The report type has been selected (Type 1: point-in-time design assessment, or Type 2: operating effectiveness over 3–12 months)


Photo Comment

2. The in-scope Trust Services Criteria have been confirmed with leadership (Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are optional)


Photo Comment

3. The system description boundary is documented, identifying all services, infrastructure, and data flows in scope


Photo Comment

4. All in-scope cloud environments, data centers, and third-party systems are listed


Photo Comment

5. An audit firm has been identified or engaged


Photo Comment

6. A target audit window or report date has been established


Photo Comment

7. Internal ownership of the SOC 2 program is assigned to a named individual or team


Photo Comment
Governance And Risk Management

1. A formal information security policy is documented, approved by leadership, and reviewed within the last 12 months


Photo Comment

2. Security roles and responsibilities are defined and documented (RACI or equivalent)


Photo Comment

3. Board or executive meeting minutes reference security and risk oversight at least annually


Photo Comment

4. A risk assessment methodology is documented and includes likelihood and impact ratings


Photo Comment

5. A current risk register exists with named owners for each identified risk


Photo Comment

6. The risk register has been reviewed and updated within the last 12 months


Photo Comment

7. Risk treatment decisions are documented for all high and medium risks


Photo Comment

8. Acceptable use policies for systems, data, and devices are in place and acknowledged by staff


Photo Comment
Security Policies And Documentation

1. All security policies required by the Common Criteria are in place (access control, incident response, change management, vendor management, business continuity)


Photo Comment

2. Policies specify review frequency and have been reviewed within that period


Photo Comment

3. Policies are stored in a version-controlled, accessible location


Photo Comment

4. Staff have acknowledged security policies in writing, with records retained


Photo Comment

5. Security awareness training is conducted at least annually, with completion records


Photo Comment

6. New hire security onboarding includes security policy review and acknowledgment


Photo Comment
Logical Access Controls (CC6)

1. A formal access provisioning process requires documented approval before access is granted


Photo Comment

2. Role-based access control (RBAC) is implemented for all production systems


Photo Comment

3. Access follows the principle of least privilege for all user roles


Photo Comment

4. Multi-factor authentication (MFA) is enforced for all production system logins


Photo Comment

5. MFA is enforced for email, VPN, and administrative consoles


Photo Comment

6. A formal access de-provisioning process revokes access within one business day of termination


Photo Comment

7. Terminated employee de-provisioning tickets are retained with timestamps


Photo Comment

8. Privileged access (admin, root, superuser) is limited to named individuals with documented justification


Photo Comment

9. Privileged access activity is logged for the full observation period


Photo Comment

10. Periodic access reviews are conducted on a defined schedule (quarterly is standard) with reviewer sign-off retained


Photo Comment

11. Access review records identify each user reviewed, the reviewer, the date, and the approval or removal decision


Photo Comment

12. Shared and service account credentials are managed and rotated on a documented schedule


Photo Comment

13. Production database and cloud console access is restricted and reviewed on the same schedule as other privileged access


Photo Comment
System Operations, Monitoring, And Incident Response (CC7)

1. Logs are collected from all production systems, including application, infrastructure, and network layers


Photo Comment

2. Logs are retained for a minimum period aligned to the observation window (12 months recommended)


Photo Comment

3. Log access is restricted to authorized personnel


Photo Comment

4. Automated alerting is configured for security-relevant events (unauthorized access attempts, privilege escalation, configuration changes)


Photo Comment

5. Alert reviews are documented and retained, not just performed


Photo Comment

6. An incident response plan is documented and includes classification criteria, escalation paths, and response steps


Photo Comment

7. The incident response plan has been tested within the last 12 months (tabletop exercise or equivalent), with results documented


Photo Comment

8. Security incidents are recorded in a formal incident log with date, classification, response actions, and resolution


Photo Comment

9. Vulnerability scanning is performed on a defined schedule and results are documented


Photo Comment

10. A formal patch management process exists with defined remediation timeframes by severity


Photo Comment

11. Patch compliance is tracked and exceptions are formally documented


Photo Comment
Change Management (CC8)

1. All production changes are tracked in a ticketing or change management system


Photo Comment

2. Change requests require documented approval before deployment to production


Photo Comment

3. Separation of duties exists between the person developing and the person approving or merging changes to production


Photo Comment

4. Pre-deployment testing is required and evidence of test results is retained per change


Photo Comment

5. A documented emergency change procedure exists, including a post-implementation review requirement


Photo Comment

6. Emergency changes are tracked and reviewed after deployment


Photo Comment

7. Configuration baselines are documented for critical systems


Photo Comment

8. Deviations from configuration baselines are tracked and approved


Photo Comment
Data Protection And Encryption

1. A data classification policy is in place, defining sensitivity tiers and handling requirements for each


Photo Comment

2. Customer and sensitive data is identified, mapped, and categorized within the classification framework


Photo Comment

3. Encryption is applied to all sensitive data at rest (AES-256 or equivalent)


Photo Comment

4. Encryption is applied to all data in transit (TLS 1.2 minimum on all external endpoints)


Photo Comment

5. Encryption key management is documented, including key rotation schedules


Photo Comment

6. Key rotation logs are retained and demonstrate the schedule is followed


Photo Comment

7. Data retention periods are documented for each data category


Photo Comment

8. Secure data disposal procedures are documented and disposal records are retained


Photo Comment

9. Portable media and device encryption is enforced where sensitive data may be stored


Photo Comment
Vendor And Third-Party Risk Management (CC9)

1. A vendor inventory lists all third parties with access to in-scope systems or customer data


Photo Comment

2. Each vendor is classified by risk level based on data access and criticality


Photo Comment

3. Vendor security assessments are conducted before onboarding and on a periodic schedule (annually for high-risk vendors)


Photo Comment

4. Current vendor assessment files are retained for all high-risk vendors (SOC 2 reports, security questionnaires, or equivalent)


Photo Comment

5. Vendor contracts include security and data protection obligations (data processing agreements or equivalent)


Photo Comment

6. Complementary User Entity Controls (CUECs) from vendor SOC 2 reports have been reviewed and implemented


Photo Comment

7. A process exists to re-evaluate vendors following significant security incidents or contractual changes


Photo Comment

8. Vendor offboarding includes revocation of all system access and data disposal confirmation


Photo Comment
Availability And Business Continuity (A1 — Include If Availability Is In Scope)

1. System availability commitments are documented (uptime targets or SLA terms)


Photo Comment

2. Infrastructure capacity is monitored against defined thresholds


Photo Comment

3. A business continuity and disaster recovery (BCP/DR) plan is documented


Photo Comment

4. The BCP/DR plan has been tested within the last 12 months, with test results retained


Photo Comment

5. Recovery time objectives (RTO) and recovery point objectives (RPO) are defined and tested


Photo Comment

6. Data backups are performed on a defined schedule


Photo Comment

7. Backup restoration is tested periodically, with results documented


Photo Comment

8. System redundancy and failover mechanisms are documented and tested


Photo Comment
Processing Integrity (PI1 — Include If Processing Integrity Is In Scope)

1. Input validation controls are implemented and documented for all data entry points


Photo Comment

2. Data processing errors are detected, logged, and resolved through a documented process


Photo Comment

3. Processing completeness is verified and monitored for all in-scope workflows


Photo Comment

4. Unauthorized data modification is detected and alerted


Photo Comment
Confidentiality (C1 — Include If Confidentiality Is In Scope)

1. Confidential data is identified and classified under the data classification policy


Photo Comment

2. Access to confidential data is restricted to authorized individuals and reviewed on a defined schedule


Photo Comment

3. Confidential data is not retained beyond its documented retention period


Photo Comment

4. NDAs or confidentiality agreements are in place with employees and contractors who access confidential data


Photo Comment
Privacy (P1–P8 — Include If Privacy Is In Scope)

1. A privacy notice is published and describes the data collected, its use, and the individual's rights


Photo Comment

2. Consent mechanisms are documented and records of consent are retained where required


Photo Comment

3. Personal data collection is limited to what is necessary for the stated purpose


Photo Comment

4. Individuals can request access to, correction of, or deletion of their personal data, and a process exists to fulfill these requests


Photo Comment

5. Personal data is not shared with third parties without a lawful basis and documented agreement


Photo Comment

6. Cross-border data transfer mechanisms are documented where applicable


Photo Comment

7. Privacy incidents (unauthorized disclosure of personal data) are tracked and reportable to regulators within required timeframes


Photo Comment
Evidence And Remediation Readiness

1. A control inventory maps each in-scope Trust Services Criterion to the control(s) addressing it


Photo Comment

2. Evidence for each control is identified, collected, and stored in an organized, audit-ready location


Photo Comment

3. Evidence covers the full observation period (for Type 2) and is not limited to point-in-time snapshots


Photo Comment

4. Identified control gaps have a documented remediation plan with assigned owner and target date


Photo Comment

5. Remediation progress is tracked and reviewed on a regular cadence


Photo Comment

6. A management representation letter process is understood and a draft is in preparation


Photo Comment

7. The system description (Section III of the SOC 2 report) is drafted and reviewed by relevant stakeholders


Photo Comment

Checklist by GoAudits.com – Please note that this checklist is intended as an example. We do not guarantee compliance with the laws applicable to your territory or industry. You should seek professional advice to determine how this checklist should be adapted to your workplace or jurisdiction.

Is this sample what you are looking for?
Sign up to use & customize this template, or create your own custom checklist.

NEW! Try generating a custom checklist with our free AI tool:

Easy inspection app for your digital checklists