What SOC 2 Compliance Actually Requires
SOC 2 compliance requires you to implement, document and evidence controls across the Trust Services Criteria your report covers. Security — the nine Common Criteria, CC1 through CC9 — is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional and included only if you scope them in.
Three things have to be true for every control on the checklist below. There is a written policy. The control actually operates. And you can prove it operated — for a Type 2, across the entire observation window, not just on the day someone asked.
Type 1 vs Type 2: what changes on the checklist
| Type 1 | Type 2 | |
|---|---|---|
| What is tested | Control design at a point in time | Control design and operating effectiveness over time |
| Observation window | None | Typically 3–12 months |
| Evidence needed | Policies and configuration as at one date | Continuous evidence across the whole window |
| What buyers accept | Sometimes, as an interim | The one procurement teams actually want |
The checklist is identical for both. The difference is entirely in how much evidence you have to produce and for how long — which is why starting evidence collection early is the single most useful thing you can do.
The SOC 2 Compliance Checklist
Grouped as the auditor groups them. The Common Criteria apply to every SOC 2 report; the four criteria after them apply only if scoped in.
Security: Common Criteria CC1–CC9
- CC1 Control environment. Board or leadership oversight of security is documented.
- CC1 Organizational structure, roles and reporting lines are defined.
- CC1 Background checks run before hire, on a documented policy.
- CC1 Security awareness training is delivered and completion is tracked.
- CC1 Code of conduct is acknowledged by every employee.
- CC2 Communication. Security policies are published where staff can reach them.
- CC2 A channel exists to report security concerns, including anonymously.
- CC2 Commitments to customers are communicated in writing.
- CC3 Risk assessment. A formal risk assessment runs at least annually.
- CC3 Risks are rated, owned and tracked to closure.
- CC3 Fraud risk is considered explicitly in that assessment.
- CC3 Vendor and third-party risk is assessed before onboarding.
- CC4 Monitoring. Control performance is reviewed on a defined cadence.
- CC4 Deficiencies are logged, escalated and remediated.
- CC5 Control activities. Controls are selected and documented against each risk.
- CC5 Technology controls are configured to policy and reviewed.
- CC6 Logical access. Access is granted on least privilege and approved.
- CC6 Multi-factor authentication is enforced on all production access.
- CC6 Access reviews run quarterly and are evidenced.
- CC6 Offboarding revokes access within a defined SLA.
- CC6 Data is encrypted in transit and at rest.
- CC6 Physical access to facilities and equipment is restricted.
- CC7 System operations. Vulnerability scanning runs on a defined schedule.
- CC7 Logging and alerting cover production systems.
- CC7 An incident response plan exists and has been tested.
- CC7 Incidents are logged, classified and reviewed post-hoc.
- CC8 Change management. Changes are reviewed and approved before release.
- CC8 Development, staging and production are separated.
- CC8 Emergency changes follow a documented exception path.
- CC9 Risk mitigation. Business continuity and disaster recovery plans exist.
- CC9 Vendor agreements include security and confidentiality terms.
Availability
- Capacity is monitored against forecast demand.
- Backups run on schedule and restores are tested, not assumed.
- A recovery plan defines RTO and RPO, and has been exercised.
- Environmental and infrastructure monitoring is in place with alerting.
- Availability commitments to customers are documented and measured.
Processing Integrity
- Inputs are validated before processing.
- Processing errors are detected, logged and corrected.
- Outputs are reconciled against expected results.
- Data quality and completeness are monitored on a defined cadence.
Confidentiality
- Confidential data is identified and classified.
- Retention periods are defined per classification.
- Secure disposal is documented and evidenced.
- Confidentiality obligations flow into vendor and employee agreements.
Privacy
- A privacy notice describes collection, use, retention and disclosure.
- Consent is captured where required and is revocable.
- Data subject access and deletion requests have a defined process and SLA.
- Personal data shared with third parties is governed by agreement.
Scope only what you need. Every optional criterion you add is more controls, more evidence and a longer audit. Add Availability or Confidentiality because a customer contract requires it, not because the list looks more impressive with five.
Evidence Your Auditor Will Ask For
The controls are the easy part. Evidence is where readiness projects overrun, because it has to exist for the whole window and it has to have an owner.
| Criterion | Control | Evidence artifact | Usual owner |
|---|---|---|---|
| CC1 | Security awareness training | Completion report with dates per employee | People / HR |
| CC3 | Annual risk assessment | Risk register with ratings, owners, review date | Security lead |
| CC6 | Quarterly access review | Signed review export per system, per quarter | IT / Engineering |
| CC6 | MFA on production | IdP configuration export plus enrollment report | IT |
| CC6 | Offboarding revocation | Ticket showing revocation within SLA, sampled | IT / People |
| CC7 | Vulnerability scanning | Scan reports across the window plus remediation tickets | Engineering |
| CC7 | Incident response test | Tabletop record with date, participants, findings | Security lead |
| CC8 | Change approval | Pull request history showing review before merge | Engineering |
| CC9 | Backup restore test | Restore test record with date and outcome | Infrastructure |
The pattern that fails audits: quarterly access reviews that were only run once, in the quarter before fieldwork. Type 2 tests the window, and a gap in month two is a gap in the report.
How Long Each Stage Takes
| Stage | Typical duration | What decides it |
|---|---|---|
| Readiness & gap assessment | 2–4 weeks | How much is already documented |
| Remediation | 1–3 months | Engineering capacity, not policy writing |
| Observation window (Type 2) | 3–12 months | Your choice; 3 months is the common first report |
| Fieldwork | 2–6 weeks | Evidence quality and auditor availability |
| Report issued | 2–4 weeks | CPA firm's review cycle |
A first Type 2 realistically runs six to twelve months end to end. A Type 1 skips the window and can be done in two to three months, which is why companies under customer pressure often do a Type 1 first and a Type 2 after.
What a SOC 2 Audit Costs
Avantcert readiness engagement ranges, already discounted 30–50% below typical market rates. The CPA firm's audit fee is separate.
| Tier | Employees | Avantcert readiness | CPA audit fee | Max duration |
|---|---|---|---|---|
| Startup | 5–50 | from $7,000 | Separate | 90 days |
| Mid-Market | 51–200 | around $16,000 | Separate | 90 days |
| Large Enterprise | 201–500 | up to $25,000 | Separate | 90 days |
See the full SOC 2 certification cost breakdown, or use the calculator for your own scope.
Checklist vs Done-For-You: When to Bring in Help
Plenty of companies run readiness themselves off a list like this one. It works when you have someone who owns security as a real part of their job, an engineering team with capacity for remediation, and no customer deadline inside ninety days.
It stops working when the checklist reveals more gaps than your team can close, when evidence collection has already started late, or when a deal is contingent on the report. At that point the constraint is capacity, not knowledge.
What no one can DIY is the audit itself. SOC 2 reports are issued by an independent CPA firm, and the organization that prepares you cannot also attest. Any provider implying otherwise is describing something that is not a SOC 2 report.
Get a scoped readiness quote
Tell us your headcount and which criteria are in scope. Scoped estimate within 24 hours.
Our form could not load. Email your headcount and scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formSOC 2 Checklist FAQs
What is on a SOC 2 compliance checklist?
A SOC 2 checklist covers the nine Common Criteria (CC1–CC9) that every report includes, plus any of the four optional Trust Services Criteria in your scope: Availability, Processing Integrity, Confidentiality and Privacy. For each control you need a documented policy, the control operating in practice, and evidence that it operated across the observation window.
What are the five SOC 2 Trust Services Criteria?
Security, Availability, Processing Integrity, Confidentiality and Privacy. Security, delivered through the nine Common Criteria, is mandatory in every SOC 2 report. The other four are optional and included only if you scope them in, usually because a customer asked.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 tests whether your controls are suitably designed at a single point in time. Type 2 tests whether they actually operated effectively across an observation window, typically three to twelve months. The checklist is the same; Type 2 additionally requires evidence that every control ran consistently for the whole window.
How long does SOC 2 compliance take?
Readiness and remediation typically take one to three months, then a Type 2 observation window of three to twelve months, then two to six weeks of fieldwork and about two to four weeks for the report. A Type 1 skips the observation window and can complete in roughly two to three months end to end.
How much does a SOC 2 audit cost?
Avantcert SOC 2 readiness engagements run from $7,000 for a 5–50 employee company, around $16,000 at 51–200, and up to $25,000 at 201–500 or complex scope, within a 90-day maximum. The CPA firm's audit fee is separate and paid directly to them.
Can I do SOC 2 myself with a checklist?
You can run readiness yourself, and many companies do. What you cannot do is audit yourself: SOC 2 reports are issued by an independent CPA firm, and the firm that prepares you cannot also attest. A checklist gets you organized; it does not remove the auditor.
Is SOC 2 a certification?
Strictly, no. SOC 2 produces an attestation report issued by a CPA firm under AICPA standards, not a certificate from an accreditation body. In practice buyers say "SOC 2 certified", but what you send them is a report, and there is no certificate to hang on a wall.
Do I need SOC 2 or ISO 27001?
SOC 2 is the North American norm and is usually driven by a specific customer asking for a report. ISO 27001 is the international certification and is more often required in Europe, the Middle East and Asia, or in tenders. Companies selling into both markets frequently end up holding both, and the control work overlaps heavily. See ISO 27001 vs SOC 2.
Download the Checklist
Take our free SOC 2 pre-audit checklist, 48 audit-ready items with the exact evidence your auditor will ask for, as a print-friendly PDF and an editable CSV tracker. No cost.
Related Reading
See SOC 2 certification services for how an engagement runs, what a Type 2 audit involves, SOC 2 for small businesses, or SOC 1 if your customers are asking about financial controls instead.
Want the checklist done for you?
We run readiness, collect the evidence, and stay with you through the auditor's fieldwork. See the full SOC 2 compliance guide for requirements, scope and cost in one place.