EVIDENCE Β· OWNERSHIP Β· CONTROL GAPS

SOC 2 Readiness Checklist

Find practical readiness gaps against the SOC 2 Trust Services Criteria before an audit turns routine work into a scramble.

Readiness is evidence that controls operate, not a pile of policies. Start with scope, owners, and the systems that process customer data.

PHASE 01

Define scope and ownership

List in-scope services, data, vendors, personnel, and Trust Services Criteria. Name one accountable owner for each control.

  • Document system boundaries and data flows.
  • Identify gaps between policy and real practice.
  • Set evidence collection cadence.

PHASE 02

Check operating controls

Test access review, joiner-mover-leaver flow, change management, logging, incident response, vulnerability management, and vendor review.

  • Collect dated evidence from normal workflows.
  • Test a sample rather than trusting a policy statement.
  • Track exceptions with owner and expiry.

PHASE 03

Run a gap closure cycle

Prioritize missing controls and weak evidence by customer impact and audit timing. Do not backfill records without clear context.

  • Keep a gap register with remediation dates.
  • Review evidence quality before the auditor asks.
  • Practice answering how each control operates.

Frequently asked questions

Does SOC 2 prescribe one control set?

No. Controls should fit your system and risks while supporting the selected Trust Services Criteria.