Free resource
The SOC 2 compliance checklist
38 controls across 10 areas, mapped to the Trust Services Criteria and the exact evidence auditors ask for. Read it in full below, or download the CSV and use it as your evidence tracker — no email required.
Governance & risk
The Common Criteria foundation auditors test first — that someone owns security and risk is assessed on a schedule.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Information security policy approved by managementSigned/approved policy with a review date in the last 12 months | Signed/approved policy with a review date in the last 12 months | CC1, CC5 |
| Defined security roles and org chartOrg chart and role descriptions naming who owns security | Org chart and role descriptions naming who owns security | CC1 |
| Annual risk assessment performedRisk register with likelihood/impact ratings and treatment decisions | Risk register with likelihood/impact ratings and treatment decisions | CC3 |
| Board or leadership security oversightMeeting minutes or a governance cadence showing security is reviewed | Meeting minutes or a governance cadence showing security is reviewed | CC1, CC2 |
| Code of conduct acknowledged by staffSigned acknowledgements from all employees | Signed acknowledgements from all employees | CC1 |
Access control
Who can reach what, proven with real system data — the most heavily sampled area of a SOC 2.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Unique user IDs; no shared accountsUser listing from key systems showing named accounts | User listing from key systems showing named accounts | CC6.1 |
| Multi-factor authentication enforcedMFA configuration screenshots for email, IdP, and production | MFA configuration screenshots for email, IdP, and production | CC6.1 |
| Least-privilege / role-based accessRole-to-permission mapping and sample access grants | Role-to-permission mapping and sample access grants | CC6.1, CC6.3 |
| Quarterly user access reviewsCompleted access-review records with sign-off | Completed access-review records with sign-off | CC6.2, CC6.3 |
| Timely deprovisioning on offboardingTermination tickets showing access removed within SLA | Termination tickets showing access removed within SLA | CC6.2 |
| Privileged access restricted and loggedAdmin group membership and privileged-action logs | Admin group membership and privileged-action logs | CC6.1 |
Change management
That code reaching production is reviewed, tested, and traceable.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Documented change/SDLC processWritten change-management procedure | Written change-management procedure | CC8.1 |
| Peer review required before mergePull requests showing required approvals | Pull requests showing required approvals | CC8.1 |
| Separation of dev, test, and productionEnvironment diagram and access differences | Environment diagram and access differences | CC8.1 |
| Automated testing / CI gatesCI pipeline config and passing-check requirements | CI pipeline config and passing-check requirements | CC8.1 |
Operations & monitoring
Continuous evidence that the system is watched and problems are caught.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Centralized logging enabledLog-management config and retention setting | Log-management config and retention setting | CC7.1, CC7.2 |
| Security monitoring / alertingAlert rules and a sample of triggered alerts | Alert rules and a sample of triggered alerts | CC7.2 |
| Vulnerability scanning on a scheduleScan reports with dates and remediation SLAs | Scan reports with dates and remediation SLAs | CC7.1 |
| Patch / remediation trackingTickets showing vulnerabilities fixed within SLA | Tickets showing vulnerabilities fixed within SLA | CC7.1 |
| Annual penetration testPen-test report and remediation evidence | Pen-test report and remediation evidence | CC4.1, CC7.1 |
Vendor & third-party risk
That you assess the subservice organizations your customers now inherit.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Vendor inventory maintainedList of vendors with data-access classification | List of vendors with data-access classification | CC9.2 |
| Security review of critical vendorsCollected SOC 2 reports or security assessments | Collected SOC 2 reports or security assessments | CC9.2 |
| Contracts include security/DPA termsExecuted agreements with security clauses | Executed agreements with security clauses | CC9.2 |
Incident response
A plan that exists on paper and has been exercised.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Documented incident response planWritten IR plan with roles and severity levels | Written IR plan with roles and severity levels | CC7.3, CC7.4 |
| IR plan tested (tabletop) annuallyTabletop exercise notes or a real incident post-mortem | Tabletop exercise notes or a real incident post-mortem | CC7.4, CC7.5 |
| Breach notification procedureProcedure defining who is notified and when | Procedure defining who is notified and when | CC7.4 |
Business continuity & availability
For the Availability criterion — that you can recover.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Backups configured and encryptedBackup schedule and encryption setting | Backup schedule and encryption setting | A1.2 |
| Backup restoration testedEvidence of a successful test restore | Evidence of a successful test restore | A1.2, A1.3 |
| Business continuity / DR plan with RTO/RPOBC/DR plan stating recovery objectives | BC/DR plan stating recovery objectives | A1.2, A1.3 |
People & HR security
That access to systems starts with vetted, trained people.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Background checks on hireBackground-check records (where legally permitted) | Background-check records (where legally permitted) | CC1.4 |
| Security awareness trainingTraining completion records for all staff | Training completion records for all staff | CC1.4, CC2.2 |
| Confidentiality / NDA agreementsSigned agreements on file | Signed agreements on file | CC1.4 |
Data protection & encryption
That data is protected in transit and at rest.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Encryption in transit (TLS) enforcedTLS configuration / SSL Labs-style report | TLS configuration / SSL Labs-style report | CC6.7 |
| Encryption at rest for stored dataStorage/database encryption settings | Storage/database encryption settings | CC6.1 |
| Key management practicesDocumented key rotation and access controls | Documented key rotation and access controls | CC6.1 |
| Data classification and handling policyWritten policy defining data tiers | Written policy defining data tiers | CC3.2, C1.1 |
Physical & environmental
Usually inherited from your cloud provider — carve-out or verify.
| Control | Evidence auditors expect | Criteria |
|---|---|---|
| Cloud provider SOC 2 obtainedAWS/GCP/Azure SOC 2 report on file | AWS/GCP/Azure SOC 2 report on file | CC9.2 |
| Office physical access controls (if applicable)Badge logs or access policy for offices | Badge logs or access policy for offices | CC6.4 |
Frequently asked questions
What is on a SOC 2 compliance checklist?
A SOC 2 checklist maps the controls an auditor tests to the evidence you must produce. This one covers 38 controls across 10 areas — governance, access control, change management, monitoring, vendor risk, incident response, continuity, people, encryption, and physical — each tied to a Trust Services Criterion.
Is there an official SOC 2 checklist?
No. The AICPA defines the Trust Services Criteria, not a fixed control list — every company maps its own controls to those criteria. A checklist like this is a practical starting point, not an official requirement; your auditor confirms what applies to your scope.
How do I use this checklist?
Download the CSV, assign an owner and status to each control, and work down the list before your readiness assessment. It doubles as an evidence tracker: the 'evidence auditors expect' column tells you exactly what to collect for each item.
Does completing the checklist mean I will pass the audit?
It gets you audit-ready, but the SOC 2 report is still issued by an independent CPA firm that tests your controls over an observation window. Use the checklist to close gaps first, then engage an auditor.
Closed the gaps? Get matched with three auditors.
Tell us your stage, framework, and timeline once. We match you with three firms that fit — one short call, not five sales pitches.
Free for buyers · No spam · Independent of every firm listed