Complies
SOC 2 CHECKLISTS

SOC 2 Compliance Checklist: 12 Steps From Scoping to Audit

JUNE 2026 · 10 MIN READ · BY THE COMPLIES TEAM

A SOC 2 compliance checklist runs from scoping which Trust Services Criteria you will cover, through policies, controls, and evidence collection, to selecting a CPA firm and sitting the audit. Here are the twelve steps in the order that avoids rework, with the artifacts each one should leave behind.

What SOC 2 is, in 40 seconds

SOC 2 is an attestation framework from the AICPA. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a report: Type 1 for control design at a point in time, Type 2 for operating effectiveness over a 3-12 month window. Security is the mandatory category, expressed as nine common criteria series (CC1-CC9); availability, confidentiality, processing integrity, and privacy are optional. There is no certificate and no pass/fail stamp; there is an auditor's opinion, and your customers read it.

The 12-step SOC 2 compliance checklist

  1. Decide report type and timing. Most teams do a Type 1 to unblock deals, then open the Type 2 window immediately. The tradeoffs are covered in SOC 2 Type 1 vs Type 2.
  2. Scope your Trust Services Criteria. Security is required. Add availability if customers ask about uptime commitments, and confidentiality if you hold sensitive customer data (most B2B SaaS does). Skip processing integrity and privacy unless buyers specifically ask; every added category adds controls, evidence, and auditor fees.
  3. Define the system boundary. Which product, infrastructure, and teams the report covers. A tight, honest boundary keeps the evidence burden proportional.
  4. Run a gap assessment against CC1-CC9. Walk the common criteria (our SOC 2 controls list breaks down each series) and record, per criterion: control exists, partially exists, or missing. This gap list is your project plan.
  5. Run a risk assessment. CC3 requires one, and auditors ask to see it: a documented method, identified risks, likelihood x impact scores, and treatment decisions with owners.
  6. Write the policy set. Typically 10-20 documents: information security, access control, change management, incident response, vendor management, business continuity, data classification, acceptable use. AI drafting compresses this from weeks to days, provided a human reviews and formally approves each policy, with the approval recorded.
  7. Implement technical controls. SSO and MFA everywhere, least-privilege access, logging and alerting, encryption at rest and in transit, hardened endpoints, tested backups, segregated environments. Most engineering effort lives here.
  8. Stand up recurring operational controls. Quarterly access reviews, change management on every production deploy, onboarding and offboarding checklists, annual security training, vendor reviews, incident postmortems. Each needs an owner and a due date on a compliance calendar, because in a Type 2 a control that skipped a quarter becomes a written exception.
  9. Collect evidence as you go. Screenshots, exports, tickets, signed reviews, filed where the auditor request list expects them. Retrofitting evidence at audit time is the single biggest source of schedule slip; an evidence collection workflow with owners and due dates removes it.
  10. Book the pen test if you need one. SOC 2 does not strictly require a penetration test, but CC4 expects monitoring and evaluation activities, and many customers ask for a pen test report alongside the SOC 2. Budget $4,000-$15,000 and schedule it before the audit so findings can be remediated in time.
  11. Select the auditor. It must be a licensed CPA firm. Ask about experience with companies your size and stack, timeline to report delivery, fees (typically $5,000-$20,000 for Type 1, $12,000-$40,000+ for Type 2), and whether they accept evidence exports from your compliance tooling. Get quotes from two or three firms; pricing spread is real.
  12. Run a readiness review, then sit the audit. Do an internal dry run against the auditor's request list, fix what is missing, then hand over evidence, sit the interviews, and review the draft report for factual accuracy before issuance.

The artifacts you should have at the end

  • Scope and system description (this becomes section 3 of the report)
  • Approved policy set with review dates
  • Risk assessment and treatment plan
  • Control matrix mapping each control to criteria, owners, and frequency
  • Evidence archive organized by control
  • The auditor's report itself, ready to share under NDA

Honest expectations

From a decent security baseline, readiness commonly takes 6-12 weeks of part-time effort; a Type 2 then adds its 3-12 month window on top. And a boundary worth repeating: no checklist and no software guarantees the outcome. The CPA firm forms its own opinion; preparation determines whether that opinion is comfortable, and whether the report ships with zero exceptions or a page of them.

Working the checklist without drowning in spreadsheets

Every step above reduces to tracked obligations, scheduled controls, and evidence with due dates. Complies gives you that as self-serve SOC 2 compliance software: the CC1-CC9 control set pre-mapped, a compliance calendar with owners, AI-drafted policies that humans approve, and a live readiness score that tells you when you are actually ready to book the auditor. Prices are published, from $79 per month, and there is no sales call. Get started at step 1 and let the checklist run itself.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.