Free checklist

SOC 2 readiness checklist

The engineering work an auditor will look for, in the order it is usually easiest to do it.

This covers the engineering half of SOC 2 — the controls that have to exist in your systems before an auditor can observe them working. It does not cover the policy, vendor management and HR controls your compliance lead or auditor will drive; those matter just as much and sit outside a codebase.

Work top to bottom. The sections are ordered so that the things which block other things come first: you cannot produce a meaningful audit trail until identity is centralised, and you cannot prove least privilege while credentials are shared.

Readiness is not certification. Nobody can certify you except an accredited third-party auditor — what this checklist prepares is the architecture and the evidence trail that audit will examine. Treat any vendor who offers to certify you directly as a red flag.

Identity and access

Auditors start here, because everything else depends on knowing who did what.

Secrets and credentials

Logging and audit trail

Change management

Vulnerability management

Data protection

Evidence collection

The difference between a smooth audit and a painful one is usually here.

0 of 36 complete

Want help working through it?

This is the same ground we cover in a Security & Compliance engagement — except we do the remediation as well as the assessment.

Have a project in mind?

Tell us what you're building. If it ships software, we can help.