The SOC 2 Audit Checklist: Controls to Prepare Before Fieldwork
A practical pre-audit checklist across all five Trust Services Criteria — the evidence auditors ask for first.
- How to use this checklist
- Security (required)
- Availability
- Confidentiality
- Processing Integrity
- Privacy
- Evidence hygiene
How to use this checklist
Security is the only mandatory criterion; the other four are scoped by agreement with your auditor. Work the Security section first — it holds ~60% of typical findings — then the criteria in your scope. For each item, you need the control documented, operating, and evidenced.
Security (required)
- Written information-security policy, acknowledged by all employees annually
- Defined roles: who owns security, who approves access, who runs incident response
- Unique user IDs, MFA on all remote/production access, password standards enforced
- Quarterly access reviews for production and customer-data systems, documented
- Prompt deprovisioning on termination/role change (target: same day)
- Centralized logging with alerting; logs retained per policy (typically 1 year)
- Change management: tested changes, approvals, rollback plans for production
- Vulnerability scanning cadence + remediation SLAs; annual penetration test
- Encryption in transit (TLS) and at rest for customer data; key management defined
- Endpoint protection and patching standards on company devices
- Background checks at hire; security awareness training at hire + annually
- Incident-response plan with named owners; tabletop exercise within the period
Availability
- Documented uptime/SLA commitments and how they're measured
- Monitoring with alerting on availability; on-call rotation defined
- Tested backups with documented restore tests (not just "backups run")
- Disaster-recovery / business-continuity plan, tested within the period
- Capacity planning process for compute and storage
Confidentiality
- Data classification scheme (what counts as confidential, and where it lives)
- NDAs with employees and contractors; confidentiality clauses with vendors
- Encryption and access restrictions specifically on confidential stores
- Secure disposal procedures for confidential data and media
Processing Integrity
- Documented input validation and error-handling for customer-facing processing
- Reconciliation or completeness checks on critical data flows
- Documented processing logic / system descriptions matching actual behavior
- Error logs reviewed; processing exceptions tracked to resolution
Privacy
- Published privacy notice matching actual data practices
- Consent/choice mechanisms where required; data-subject request process (access, deletion)
- Data retention schedule enforced; minimization practices documented
- Subprocessor list maintained and disclosed
Evidence hygiene
The control existing isn't enough — auditors test evidence. For each control, keep: the policy or procedure, a timestamped artifact showing it operated (ticket, log export, review sign-off), and the owner's name. Organize by criterion before fieldwork starts; disorganized evidence is the #1 timeline killer. Take the 2-minute readiness quiz to see where you stand.
Keep reading
How Much Does a SOC 2 Audit Cost in 2026?
Published SOC 2 cost ranges from six real sources: audit fees, readiness, tooling, and the internal time nobody quotes you.
SOC 2 Type 1 vs Type 2: Which Report Do You Actually Need?
The real difference between Type 1 and Type 2, what enterprise buyers accept, and when the cheaper report is the right call.
How to Choose a SOC 2 Auditor: 9 Questions to Ask
The vetting checklist we recommend: license verification, team, fees, scope boundaries, and the red flags that signal a bad fit.
Questions
How many controls are in a typical SOC 2 audit?
It varies by scope, but Security-only audits commonly test 40–80 controls; adding criteria can push past 100. Your auditor finalizes the list during readiness.
Do I need all five Trust Services Criteria?
No — only Security is required. Scope the rest to what your customers ask for; each added criterion adds cost and testing.
Turn reading into quotes
Get scoped, comparable quotes from licensed SOC 2 auditors — free, 2 minutes.