SOC 2 Auditors

Free resource

The SOC 2 compliance checklist

38 controls across 10 areas, mapped to the Trust Services Criteria and the exact evidence auditors ask for. Read it in full below, or download the CSV and use it as your evidence tracker — no email required.

Download the CSV checklistFree · No signup · Opens in Excel or Google Sheets

Governance & risk

The Common Criteria foundation auditors test first — that someone owns security and risk is assessed on a schedule.

ControlCriteria
Information security policy approved by managementSigned/approved policy with a review date in the last 12 monthsCC1, CC5
Defined security roles and org chartOrg chart and role descriptions naming who owns securityCC1
Annual risk assessment performedRisk register with likelihood/impact ratings and treatment decisionsCC3
Board or leadership security oversightMeeting minutes or a governance cadence showing security is reviewedCC1, CC2
Code of conduct acknowledged by staffSigned acknowledgements from all employeesCC1

Access control

Who can reach what, proven with real system data — the most heavily sampled area of a SOC 2.

ControlCriteria
Unique user IDs; no shared accountsUser listing from key systems showing named accountsCC6.1
Multi-factor authentication enforcedMFA configuration screenshots for email, IdP, and productionCC6.1
Least-privilege / role-based accessRole-to-permission mapping and sample access grantsCC6.1, CC6.3
Quarterly user access reviewsCompleted access-review records with sign-offCC6.2, CC6.3
Timely deprovisioning on offboardingTermination tickets showing access removed within SLACC6.2
Privileged access restricted and loggedAdmin group membership and privileged-action logsCC6.1

Change management

That code reaching production is reviewed, tested, and traceable.

ControlCriteria
Documented change/SDLC processWritten change-management procedureCC8.1
Peer review required before mergePull requests showing required approvalsCC8.1
Separation of dev, test, and productionEnvironment diagram and access differencesCC8.1
Automated testing / CI gatesCI pipeline config and passing-check requirementsCC8.1

Operations & monitoring

Continuous evidence that the system is watched and problems are caught.

ControlCriteria
Centralized logging enabledLog-management config and retention settingCC7.1, CC7.2
Security monitoring / alertingAlert rules and a sample of triggered alertsCC7.2
Vulnerability scanning on a scheduleScan reports with dates and remediation SLAsCC7.1
Patch / remediation trackingTickets showing vulnerabilities fixed within SLACC7.1
Annual penetration testPen-test report and remediation evidenceCC4.1, CC7.1

Vendor & third-party risk

That you assess the subservice organizations your customers now inherit.

ControlCriteria
Vendor inventory maintainedList of vendors with data-access classificationCC9.2
Security review of critical vendorsCollected SOC 2 reports or security assessmentsCC9.2
Contracts include security/DPA termsExecuted agreements with security clausesCC9.2

Incident response

A plan that exists on paper and has been exercised.

ControlCriteria
Documented incident response planWritten IR plan with roles and severity levelsCC7.3, CC7.4
IR plan tested (tabletop) annuallyTabletop exercise notes or a real incident post-mortemCC7.4, CC7.5
Breach notification procedureProcedure defining who is notified and whenCC7.4

Business continuity & availability

For the Availability criterion — that you can recover.

ControlCriteria
Backups configured and encryptedBackup schedule and encryption settingA1.2
Backup restoration testedEvidence of a successful test restoreA1.2, A1.3
Business continuity / DR plan with RTO/RPOBC/DR plan stating recovery objectivesA1.2, A1.3

People & HR security

That access to systems starts with vetted, trained people.

ControlCriteria
Background checks on hireBackground-check records (where legally permitted)CC1.4
Security awareness trainingTraining completion records for all staffCC1.4, CC2.2
Confidentiality / NDA agreementsSigned agreements on fileCC1.4

Data protection & encryption

That data is protected in transit and at rest.

ControlCriteria
Encryption in transit (TLS) enforcedTLS configuration / SSL Labs-style reportCC6.7
Encryption at rest for stored dataStorage/database encryption settingsCC6.1
Key management practicesDocumented key rotation and access controlsCC6.1
Data classification and handling policyWritten policy defining data tiersCC3.2, C1.1

Physical & environmental

Usually inherited from your cloud provider — carve-out or verify.

ControlCriteria
Cloud provider SOC 2 obtainedAWS/GCP/Azure SOC 2 report on fileCC9.2
Office physical access controls (if applicable)Badge logs or access policy for officesCC6.4

Frequently asked questions

What is on a SOC 2 compliance checklist?

A SOC 2 checklist maps the controls an auditor tests to the evidence you must produce. This one covers 38 controls across 10 areas — governance, access control, change management, monitoring, vendor risk, incident response, continuity, people, encryption, and physical — each tied to a Trust Services Criterion.

Is there an official SOC 2 checklist?

No. The AICPA defines the Trust Services Criteria, not a fixed control list — every company maps its own controls to those criteria. A checklist like this is a practical starting point, not an official requirement; your auditor confirms what applies to your scope.

How do I use this checklist?

Download the CSV, assign an owner and status to each control, and work down the list before your readiness assessment. It doubles as an evidence tracker: the 'evidence auditors expect' column tells you exactly what to collect for each item.

Does completing the checklist mean I will pass the audit?

It gets you audit-ready, but the SOC 2 report is still issued by an independent CPA firm that tests your controls over an observation window. Use the checklist to close gaps first, then engage an auditor.

Closed the gaps? Get matched with three auditors.

Tell us your stage, framework, and timeline once. We match you with three firms that fit — one short call, not five sales pitches.

Free for buyers · No spam · Independent of every firm listed