SOC 2 Readiness Checklist
Find your SOC 2 gaps criterion by criterion, before the auditor does.
Readiness
- 0 Yes
- 0 Partly
- 0 No
- 0 N/A
- 0 Not answered
By area
Gaps to close
Questions you answer No or Partly appear here, No first, with the next step for each.
Evidence to prepare
What auditors usually ask to see for the questions that apply. For a Type 2 report, each item needs records from across the whole period.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the SOC 2 Readiness Checklist
A SOC 2 report is how a service company shows customers that its controls for security, and optionally availability, confidentiality, processing integrity and privacy, are designed and working. The examination is done by a licensed CPA firm against the AICPA’s Trust Services Criteria, and it is expensive to discover gaps in the middle of it.
This checklist asks plain-language questions for every criterion in scope: the common criteria CC1 to CC9 that every report includes, and the extra categories you choose. Each question names the criteria it supports (such as CC6.2), what auditors usually ask to see, and the next step when the answer is No or Partly. You get a readiness view by area, a list of gaps to close, an evidence list and a report to download as PDF or Word. Nothing you answer leaves your browser.
How to use it
- Fill in About the report: the report type (Type 1 or Type 2), where the service runs (a cloud provider, your own servers, or both) and the categories you will include besides Security.
- Answer each question Yes, Partly, No or N/A. Open What auditors usually ask for to see the evidence behind a question, and add a note where it helps.
- Read the result: readiness by area, the gaps to close (No first, then Partly) and the evidence list for the questions that apply.
- Download the report as PDF or Word, the answers as CSV, or copy a summary. Use Save answers to keep a file you can open here again, or tick Keep my answers in this browser.
Examples
Type 1 · cloud provider · Security only · MFA only on the VPN (No), access reviews never run (No), policies drafted (Partly)
Gaps list starts with CC6.1/CC6.6 (enforce MFA everywhere) and CC6.3/CC6.2 (run access reviews), then CC5.3 (approve the policy set), each with the evidence an auditor will request.
Type 2 · own servers and a cloud provider · Security and Availability · restores never tested
Adds the Type 2 period question, both physical-access questions (your server room and the provider’s report) and A1.3: test restores and the recovery plan every year and keep the records.
Common uses
- A SaaS company whose customers ask for a SOC 2 report before they sign.
- A security lead planning the work before choosing a CPA firm.
- Checking which evidence to collect before a Type 2 period starts.
- A consultant running a quick readiness review with a client.
Type 1 and Type 2
- Type 1 reports on the description of your system and whether your controls are suitably designed, at a point in time (a specified date).
- Type 2 also reports on whether the controls operated effectively throughout a period that you agree with the auditor. The auditor tests samples from across the period, so every control needs records for all of it.
Many companies start with a Type 1 and follow with a Type 2. Either way, the auditor reports on what your system description says you do, so write down only controls you actually run.
The Trust Services Criteria in this checklist
- Security (common criteria, always included): CC1 control environment, CC2 communication and information, CC3 risk assessment, CC4 monitoring, CC5 control activities, CC6 logical and physical access, CC7 system operations, CC8 change management, CC9 risk mitigation.
- Availability (A1): capacity, backups and recovery infrastructure, recovery testing.
- Confidentiality (C1): protecting and disposing of confidential information.
- Processing Integrity (PI1): complete, accurate and timely processing of inputs and outputs.
- Privacy (P1–P8): notice, consent, collection, use and retention, access, disclosure and breach notification, quality and complaints.
Criteria numbers follow the AICPA’s 2017 Trust Services Criteria. The questions and the guidance are MySmartCoPilot’s own wording; the AICPA’s text is not reproduced.
Cloud providers and other subservice organisations
If your service runs on a cloud provider, the physical security of its data centres is the provider’s control. Your report usually leaves the provider’s controls out (the carve-out method) and lists the controls you expect it to run; you rely on the provider’s own SOC 2 report. The checklist asks whether you have that report and have checked what it expects from you.
Sources
Limitations
- A self-assessment, not an audit or legal advice: the readiness figure only reflects the answers given, and only a licensed CPA firm can issue a SOC 2 report or decide whether a control meets a criterion.
- The questions cover the main expectations of each criterion. Your auditor will look at your own system description and controls, which may need more than the checklist asks.
- Readiness counts each Yes as one and each Partly as half; it is a planning aid, not a pass mark.
Privacy
Everything happens in your browser. Your answers and notes are not uploaded. If you tick Keep my answers in this browser, they are saved in this browser’s local storage until you untick it; Save answers downloads a file to your device.
Frequently asked questions
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report covers the design of your controls at a point in time. A Type 2 report also covers whether they operated effectively throughout a period agreed with the auditor, tested by sampling across that period. Customers often ask for Type 2 because it shows the controls working over time.
Who can issue a SOC 2 report?
An independent, licensed CPA firm. The examination follows the AICPA’s attestation standards (the SSAEs), its SOC 2 guide and the Trust Services Criteria. Tools, templates and consultants can help you prepare, but they cannot issue the report.
Which categories should we include besides Security?
Include the ones that match what you promise customers: Availability if you commit to uptime or recovery times, Confidentiality if you hold information under confidentiality terms, Processing Integrity if customers rely on your processing being complete and accurate (payments, payroll), and Privacy if you make commitments about how you collect, use, keep, disclose and dispose of personal information. Security is always included.
Is SOC 2 the same as ISO 27001?
No. ISO/IEC 27001 is a management-system standard: an accredited certification body certifies your ISMS. SOC 2 is an attestation report by a CPA firm on your controls against the Trust Services Criteria. Many controls overlap, so the same policies, risk assessment and access reviews usually serve both.
Are my answers sent anywhere?
No. The checklist runs in your browser; nothing you answer is uploaded. Downloads are made on your device.