The SOC 2 Compliance Checklist That Reflects How Audits Actually Work

Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”.

There is no official SOC 2 compliance checklist. The AICPA publishes Trust Services Criteria, your organisation designs controls that meet them, and a licensed CPA firm examines those controls; any “official checklist” claim is false. What exists is the readiness sequence below, in the order examinations actually run, with what “done” looks like at each step.

The whole process in one table

PhaseWhat happensWho does the workRough duration
2. InventoryList every system, data store and vendor touching customer dataEngineering leadDays, if your architecture is documented
3. Design controlsDesign and document controls against the criteria in scopeOps and engineering leads, often with outside helpThe first long stretch
4. Fix gapsClose the holes the design work exposedEngineering, IT, HRRuns alongside phase 3
5. Collect evidenceGenerate and store proof that controls operateWhoever owns each controlContinuous from here on
6. Choose the auditorScope the engagement with licensed CPA firms and pick oneFounder or ops leadWeeks of conversations
7. Observation window (Type 2 only)Controls operate for a defined period while evidence accumulatesThe whole team, business as usualA period of months agreed with your CPA firm
8. ExaminationThe CPA firm tests your controls and issues the reportThe auditor, with your team answering requestsWeeks of fieldwork

Why listen to us

Atoro is an Irish AI governance and cyber compliance consultancy for software companies, and the first consultancy in Europe certified against ISO 42001. We prepare companies for SOC 2 Type 1 and Type 2 examinations at a fixed price agreed after scoping; this checklist is the order we work in.

Phase 1: Decide your scope and Trust Services Criteria

Your scope decision comes first, because every later phase inherits it. SOC 2 has five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security is mandatory in every examination; the other four are optional, included only where your service commitments make them relevant (AICPA Trust Services Criteria, 2017, revised points of focus 2022). The companion SOC 2 requirements guide covers the full criteria structure.

The scoping question most pages answer badly is which optional criteria belong in yours. Read your customer contracts and security questionnaires: promised uptime figures point to Availability, processing personal data for customers raises Confidentiality and possibly Privacy, and a product whose output correctness matters raises Processing Integrity. Each criterion added multiplies the controls you must design, evidence and defend.

Checklist for this phase:

  • [ ] List your in-scope products and services in one sentence each.
  • [ ] Pull recent customer contracts and security questionnaires; note what they demand.
  • [ ] Decide which optional criteria apply, with one line of justification each.
  • [ ] Write a scope statement you could read to an auditor without wincing.

Done looks like: a one-page scope document naming the system, the criteria in scope, and the contract behind each optional one.

Phase 2: Inventory your systems and data

You cannot control what you have not listed, and this phase produces the inventory the auditor will walk through with you.

A working inventory covers systems that store, process or transmit customer data, the people with access, the vendors in the chain, and where data enters, moves and leaves. Auditors ask about the system nobody wrote down: the analytics database someone spun up, the support tool with production access, the founder’s laptop.

Checklist for this phase:

  • [ ] List every production system and data store, including the embarrassing ones.
  • [ ] List every vendor that touches customer data, and what they touch.
  • [ ] Map how customer data flows in, through and out.
  • [ ] List who has administrative access to each system, and why.

Done looks like: an inventory and data-flow diagram your engineering lead signs off as complete.

Phase 3: Design and document your controls

This is where criteria become your controls. The AICPA gives you criteria and points of focus, not a controls list; as audit firm Schellman puts it, “there is no checklist or even guidance on how to choose” (schellman.com, checked 06-08-2026). You design controls that fit your systems, and the auditor judges whether they meet the criteria.

The Security criterion’s common criteria span nine families, CC1 through CC9: control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation (AICPA 2017 TSC; structure per soc2auditors.org, checked 06-08-2026). First-timers find the real work in CC6 (access control), CC7 (monitoring and incident response) and CC8 (change management).

Design each control with an owner, a frequency and an evidence artefact. “We review access” is not a control. “The engineering lead reviews production access quarterly and records the review” is.

Checklist for this phase:

  • [ ] Map each in-scope criterion to at least one control you actually operate.
  • [ ] Give every control a named owner, a frequency and an evidence artefact.
  • [ ] Write the policies behind the controls: information security, access control, incident response, change management, vendor management, acceptable use.
  • [ ] Have an outsider read each control back to you.

Done looks like: a control set mapped to the criteria, policies that match how you actually work, and no control with a blank evidence column.

Phase 4: Fix the gaps

Gap-fixing is where design meets reality. First examinations surface the same holes: shared accounts, access never revoked when someone left, unreviewed changes to production, an incident response plan that is a wiki paragraph nobody has read.

Two deserve named attention. Joiner-mover-leaver processes get tested hard and by sample, so one missed offboarding is a finding. Enterprise customers and auditors commonly ask for a recent independent penetration test alongside SOC 2; its findings feed your risk assessment and remediation list. Atoro runs penetration testing for software companies facing exactly this expectation.

Checklist for this phase:

  • [ ] Eliminate shared accounts; every person gets their own credentials.
  • [ ] Implement and test joiner-mover-leaver procedures, with records.
  • [ ] Enforce multi-factor authentication on systems holding customer data.
  • [ ] Put a documented review step in front of production changes.
  • [ ] Commission an independent penetration test and triage its findings.
  • [ ] Write the incident response plan as a procedure and run one tabletop exercise.

Done looks like: a gap register where every item is closed or has an owner and a date, with evidence behind the closed ones.

Phase 5: Collect evidence as you go

Evidence is a habit installed before the auditor arrives, not a phase you complete. Auditors do not take your word for anything; they ask for the artefact: the access review log, the onboarding checklist, the change ticket, the incident record.

The mistake is the evidence scramble: back-filling three months of logs the week before fieldwork. Auditors notice, and it reads worse than an honest gap. Set each control up so evidence is a by-product of doing the work.

Checklist for this phase:

  • [ ] Confirm every control’s artefact is generated automatically or by habit.
  • [ ] Pick one place where evidence lives and hold the line on it.
  • [ ] Self-test: pick five controls at random and produce their last two artefacts within an hour.
  • [ ] Decide who owns auditor evidence requests and how they are tracked.

Done looks like: the five-control self-test passes, and nobody had to make anything.

Phase 6: Choose a licensed CPA firm

Only a licensed CPA firm can issue a SOC 2 report. SOC 2 is an attestation under AICPA standards, not a certificate, whatever the market’s vocabulary says (AICPA, System and Organization Controls suite of services; the Journal of Accountancy’s formulation, “SOC 2 isn’t a certification”, via ciphrix.com, checked 06-08-2026). Platforms and consultancies prepare you; the CPA firm examines you.

Choose on three things: experience with software companies of your size and architecture, how the firm runs fieldwork (samples, walkthroughs, evidence requests), and how it handles findings. Ask who actually does the work; the partner who sells the engagement is rarely the person testing your controls.

Checklist for this phase:

  • [ ] Shortlist licensed CPA firms with software company examination experience.
  • [ ] Ask each how they select samples and run walkthroughs.
  • [ ] Ask who staffs the engagement and how findings are raised.
  • [ ] Agree the examination timing and the evidence request process in writing.

Done looks like: an engagement letter with a firm chosen on method, not just price.

Phase 7: Run the observation window (Type 2 only)

A Type 2 report covers how your controls operated over a period, so the period has to happen. Your job during it is boring and important: operate the controls exactly as documented, keep producing evidence, and treat every exception as a problem to fix now, not a finding to explain later.

Two disciplines carry this phase. Calendar the recurring controls (access reviews, vendor reviews, risk assessments) so none is missed; a missed quarter inside the window is a deviation the report may have to disclose. Log every incident and exception as it happens, with the response; auditors read incident logs for honesty as much as outcomes. Type 1 has no observation window; the Type 1 vs Type 2 choice is covered in our dedicated post.

Checklist for this phase:

  • [ ] Calendar every recurring control across the whole window, with owners.
  • [ ] Review evidence monthly for completeness, not just at the end.
  • [ ] Log every incident and exception as it happens, with what you did.
  • [ ] Fix deviations the week you find them, and keep the record of the fix.

Done looks like: the window closes with no missed recurring controls, a complete incident log, and evidence that needs no archaeology.

Phase 8: Sit the examination

The examination is fieldwork: the CPA firm tests your control design and, for Type 2, operating effectiveness across the window. Expect batched evidence requests, walkthrough meetings where a control owner shows the control operating, and follow-up questions.

Handle it like an engineering incident: one coordinator, fast honest answers, no improvisation. If a control failed during the window, say so and show the remediation; a handled exception reads better than a discovered one. Most first reports carry findings somewhere; that is normal.

Checklist for this phase:

  • [ ] Nominate one coordinator for all auditor communication.
  • [ ] Brief every control owner on what a walkthrough involves before it happens.
  • [ ] Answer evidence requests from the single source of truth you built in phase 5.
  • [ ] When a finding lands, respond with the fix and the date, not the excuse.

Done looks like: a signed report you can send to the procurement team that asked for it.

Where SOC 2 projects actually go wrong

The same five failures account for most stalled first examinations.

Scope picked from a template, not from contracts. Teams copy a competitor’s criteria list and end up defending controls they never needed, or missing one a customer demanded. Scope is a reading exercise, not a copying exercise.

Policies that describe a company that does not exist. Auditors test against your policies; if the policy says weekly reviews and you do monthly ones, the policy itself creates the finding. Write policies you can keep, then keep them.

Cookie-cutter evidence in walkthroughs. When the “evidence” is a screenshot folder assembled last week, the walkthrough collapses; practitioners answering founder questions on Reddit flag exactly this pattern (r/cybersecurity AMA, ~2023, via thoropass.com, thread URL unverified).

The joiner-mover-leaver sample that fails. One leaver with access still active is the classic finding, because auditors routinely sample leavers.

Treating the examination as the finish line. Procurement teams ask again next year. The report is the start of an operating rhythm, not the end of a project.

What you can do yourself vs where help earns its fee

You can do yourself: the scope draft, system inventory, data-flow map, first-pass policies, joiner-mover-leaver hygiene, evidence habits. That needs an ops lead with protected time and this checklist, not a consultant.

Help earns its fee in four places: control design against the criteria, where the judgement call is what “enough” looks like for your architecture and auditor; gap-fixing that involves security engineering, such as penetration testing and remediation; auditor selection and management, where knowing how firms sample changes outcomes; and the ongoing rhythm after the report, where TrustOps-style continuous compliance keeps the next examination from becoming an event. Atoro’s SOC 2 implementation service covers the design-to-examination stretch at a fixed price agreed after scoping.

Cost is deliberately not covered here. Our SOC 2 cost guide owns that question.

FAQs

Is there an official SOC 2 compliance checklist?

No. The AICPA publishes Trust Services Criteria, and your organisation designs controls that meet them; a licensed CPA firm then examines those controls. Audit firm Schellman states plainly that “there is no checklist or even guidance on how to choose” controls. Any “official checklist” claim is false.

What initial steps can we take before our first meeting with an auditor or consultant?

Draft your scope from your customer contracts, build the system and vendor inventory, and write down who has access to what. Those three artefacts make every later conversation faster and cheaper. You can do all three without buying anything.

Is SOC 2 a certification?

No. SOC 2 is an attestation report issued by a licensed CPA firm under AICPA standards, not a certificate. The market says “get certified”; the correct term is attestation.

How many employees should be assigned to SOC 2 work?

There is no fixed number, and anyone who gives you one without knowing your systems is guessing. Every first examination needs one accountable owner, usually an ops or engineering lead, plus access to whoever runs infrastructure and HR. The effort concentrates in control design and gap-fixing.

What is the biggest misstep when scoping a SOC 2?

Choosing criteria from a template instead of from your own contracts. Each optional criterion added multiplies the controls you must design, evidence and defend; each one wrongly omitted surfaces when a customer’s security team reads the report. Scope is the cheapest phase to get right and the most expensive to get wrong.

Do we need a compliance platform like Drata or Vanta to do this?

No platform is required for a SOC 2 examination; the AICPA’s requirements say nothing about tooling. A platform does make evidence collection and control monitoring less manual, which matters most in the Type 2 observation window. Choose tooling after your scope and controls exist, not before.

What is the typical time investment to go through an audit?

It depends on your starting hygiene, your scope and whether you are doing Type 1 or Type 2, and honest published ranges vary widely. Type 2 also adds the observation window before the examination. The phases above, not a universal number, are the reliable way to estimate your own timeline.

Should a European company do SOC 2 or ISO 27001?

It depends on who is asking. SOC 2 tends to be demanded by US enterprise customers and their procurement teams, while ISO 27001 generally carries more weight with European buyers. Read your pipeline’s security questionnaires and let them decide. The honest next step, if this checklist has shown you the shape of the work, is scoping it properly. Atoro’s SOC 2 implementation service starts with a scoping conversation and a fixed price agreed before any work begins.

Sources

  1. AICPA, System and Organization Controls (SOC) suite of services, aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services, checked 06-08-2026 (attestation model, licensed CPA firms, SOC 2 under AICPA standards).
  2. AICPA Trust Services Criteria, 2017 TSC with revised points of focus 2022; structure summarised at soc2auditors.org/insights/soc-2-trust-services-criteria/ and soc2auditors.org/insights/soc-2-controls-list/, checked 06-08-2026 (the CC1-CC9 nine-family structure is as summarised by that directory).
  3. Schellman, “SOC 2: Trust Services Criteria with TSC”, schellman.com/blog/soc-examinations/soc-2-trust-services-criteria-with-tsc, checked 06-08-2026 (audit firm: “there is no checklist or even guidance on how to choose”).
  4. Journal of Accountancy, “SOC 2 isn’t a certification”, as quoted by Ciphrix, ciphrix.com/blog/soc-2/trust-services-criteria–soc-2, checked 06-08-2026.
  5. Thoropass, Laika/Reddit AMA recaps, thoropass.com/blog/laikas-reddit-ama-most-upvoted-questions-and-answers and thoropass.com/blog/compliance/soc-2-audit-reddit-ama-most-upvoted-questions-and-answers, checked 06-08-2026 (Reddit language source only; thread URLs unverified; used for founder phrasing of FAQ questions and the cookie-cutter evidence observation, not as a fact source).