Free Readiness Assessment
SOC 2 Readiness Checklist
Score your SOC 2 readiness across governance, TSC mapping, controls, monitoring and evidence. Answer 16 questions, get an instant score and download a branded PDF roadmap to your Type 1 or Type 2 report.
16 questions across 6 TSC domains, plus a quick environment context block.
Calibrated to CC1–CC9 plus Availability, Confidentiality, Processing Integrity and Privacy.
Score breakdown, top gaps and a prioritised action plan. Emailed copy + instant download.
Tell us about your environment
A few details to tailor your SOC 2 roadmap. Required fields are marked *.
Governance & Scope
System boundary, leadership oversight and approved policies.
The system description is the foundation of a SOC 2 report — auditors will check it closely.
View evidence examples ->
- A system description defining in-scope products, services, infrastructure and data flows.
- Clear inclusions and exclusions (e.g. production systems in scope; internal test labs excluded).
- Boundary diagrams showing users, systems, third parties and data movement.
Active leadership oversight is a foundational SOC 2 common criteria requirement.
View evidence examples ->
- A security or risk committee charter approved by the board or executive team.
- Meeting minutes showing review of incidents, risks and audit readiness.
- Assigned executive accountability for SOC 2 compliance.
Policies must be current, approved and demonstrably communicated — not just written.
View evidence examples ->
- Approved security, access control, incident response and change management policies.
- Version control with review and approval dates documented.
- Evidence of staff communication or acknowledgement (training, intranet, onboarding).
TSC Mapping & Risk
Control mapping to Trust Services Criteria and risk assessment.
Auditors expect traceability from each control to the applicable Trust Services Criteria.
View evidence examples ->
- A control matrix mapping controls to CC1–CC9 and any selected Availability, Confidentiality, Processing Integrity or Privacy criteria.
- Written rationale explaining why criteria are in or out of scope.
- Consistent naming between policies, procedures and control descriptions.
Risk assessment should drive control selection and monitoring focus for SOC 2.
View evidence examples ->
- Documented risk assessment covering security, availability and processing risks.
- Risks linked to specific SOC 2 controls with owners and treatment plans.
- Monitoring or KPIs aligned to high-risk areas reviewed at defined cadences.
Controls & Operations
Change management, access, SDLC and third-party risk.
SOC 2 auditors sample change records — they need to show authorisation, testing and recoverability.
View evidence examples ->
- Change tickets with approvals, test evidence and rollback plans.
- Separation of duties between development and production deployment.
- Emergency change procedure with post-implementation review records.
Access controls are heavily sampled in SOC 2 Type 2 — expect auditors to pull JML records.
View evidence examples ->
- Joiner/mover/leaver process with documented approvals for each event.
- Quarterly or semi-annual access reviews for critical systems.
- Privileged access controls including MFA, separate admin accounts and logging.
Systems must process data accurately, completely and as authorised.
View evidence examples ->
- SDLC stages with mandatory peer review and testing requirements.
- Automated tests validating data accuracy, completeness and integrity.
- Defect tracking and resolution records retained.
SOC 2 requires you to manage risk introduced by vendors who access or process your systems.
View evidence examples ->
- Vendor risk assessments based on criticality and data access before onboarding.
- Contracts including security, confidentiality and incident notification clauses.
- Ongoing monitoring via SOC reports, certifications or performance reviews.
Logging, Incidents & Evidence
Centralised monitoring, incident response and evidence management.
Monitoring must demonstrate timely detection and response to security events.
View evidence examples ->
- Centralised logging for identity, infrastructure and application events.
- Alerts integrated with ticketing or incident management tools.
- Evidence of alert review and response at defined intervals.
Preparedness and learning from incidents is a key SOC 2 common criteria expectation.
View evidence examples ->
- Incident response plan with defined roles, severity levels and escalation paths.
- Tabletop or simulated incident exercises conducted at least annually.
- Post-incident reviews with corrective actions tracked to verified closure.
Type 2 auditors sample evidence across the audit period — it must be organised and retrievable.
View evidence examples ->
- An evidence library in SharePoint with folder structure aligned to controls.
- Defined sampling cadence (monthly, quarterly) for continuous evidence collection.
- Retention and versioning enabled for all audit artefacts.
Attribute Criteria
Availability, Confidentiality, Processing Integrity and Privacy.
If Availability is in scope, auditors will look for both architecture and tested recovery evidence.
View evidence examples ->
- Capacity and performance monitoring reports covering production systems.
- Redundancy architecture diagrams showing failover capability.
- Disaster recovery or backup restore test evidence demonstrating RTO/RPO is met.
Sensitive data must be protected throughout its lifecycle — encryption configuration is sampled.
View evidence examples ->
- Documented encryption standards for data at rest and in transit.
- Key management procedures including access controls and rotation schedules.
- Evidence of encryption configuration in production systems.
Privacy criteria require evidence of notice, consent handling and individual rights management.
View evidence examples ->
- Published privacy notice describing data use, rights and contact details.
- Process for handling data subject access, deletion and correction requests.
- Documented retention schedules and secure disposal procedures.
Audit Readiness
Type 1/2 planning, period, population and sampling windows.
Clear planning aligned with your auditor reduces delays and scope disputes.
View evidence examples ->
- Defined audit type (Type 1 or Type 2) and agreed reporting period.
- Agreed population and sampling approach documented with the auditor.
- Audit readiness checklist and milestone timeline prepared.
Available once all questions are answered
Your report is ready
Your PDF has downloaded automatically. A copy of your responses has been sent to our team — we'll follow up if you'd like to discuss the results.