SOC 2 Compliance Checklist: What to Prepare Before Your Audit
The scope decisions, policies, and evidence to have in place before a SOC 2 audit, and the readiness gaps that most often surprise first-timers.
10 min read
A SOC 2 audit tests controls you already have running, so almost all of the work happens in the months before the auditor shows up. Use this checklist to get ready. It covers six areas, plus the gaps that most often trip up a first-time auditee.
1. Decide Your Scope
- Choose your Trust Services Criteria. Most first reports scope to Security alone and add others as customers ask.
- Choose Type 1 or Type 2. Type 2 is what enterprise buyers expect; Type 1 is a faster interim step.
- Define the system boundary: which product, environments, and data are in scope, and what is explicitly out.
2. Write and Approve Your Policies
- Have the core policies in place and approved: information security, access control, change management, incident response, business continuity, vendor management, and risk assessment.
- Make sure each policy reflects what you actually do. An auditor compares the policy to the evidence, and a policy you do not follow is worse than one you never wrote.
3. Get Access and Identity Under Control
- Enforce unique accounts, strong authentication, and least-privilege access to production.
- Run and document periodic access reviews. This is one of the most commonly tested controls.
- Have a documented process for granting and revoking access when someone joins or leaves.
4. Collect Evidence with a Freshness Schedule
- For every control, know what proves it: an export, a ticket, a signed approval, a completed review.
- Give evidence a cadence. A Type 2 covers a window, so the auditor expects to see the control running throughout, not once.
- Store evidence where an owner keeps it current, not in a folder someone updates the week before the audit.
5. Inventory Your Vendors
- List the third parties that touch customer data, and record what data each one handles.
- Collect each critical vendor's own SOC 2 report or equivalent assurance.
6. Run a Readiness Review
- Before the formal audit, walk your controls against the framework's requirements and find the gaps yourself.
- Close the gaps or document a reasoned exception. Surprises are cheaper to fix now than mid-audit.
The Gaps That Surprise First-Timers
Three show up again and again: access reviews that were never actually performed on a schedule, evidence that exists for one date but not across the whole Type 2 window, and policies that describe a process nobody follows. All three are readiness problems, not audit problems, which is exactly why the checklist above front-loads them.
How Concord Fits
Concord Trust's control library and coverage view turn this checklist into a live status board: you adopt controls, assign owners, attach evidence, and see which requirements are covered before an auditor looks. When you are ready, scoped auditor access lets the firm review your evidence directly without you emailing files around.