+91 98804 42758

SOC 2 Compliance Checklist: All 5 Trust Services Criteria

Every control your auditor will test, the evidence they will ask for, and who on your team owns it. Free to read, free to download.

Updated August 2026 12 min read Compliance

What SOC 2 Compliance Actually Requires

SOC 2 compliance requires you to implement, document and evidence controls across the Trust Services Criteria your report covers. Security — the nine Common Criteria, CC1 through CC9 — is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional and included only if you scope them in.

Three things have to be true for every control on the checklist below. There is a written policy. The control actually operates. And you can prove it operated — for a Type 2, across the entire observation window, not just on the day someone asked.

Type 1 vs Type 2: what changes on the checklist

 Type 1Type 2
What is testedControl design at a point in timeControl design and operating effectiveness over time
Observation windowNoneTypically 3–12 months
Evidence neededPolicies and configuration as at one dateContinuous evidence across the whole window
What buyers acceptSometimes, as an interimThe one procurement teams actually want

The checklist is identical for both. The difference is entirely in how much evidence you have to produce and for how long — which is why starting evidence collection early is the single most useful thing you can do.

The SOC 2 Compliance Checklist

Grouped as the auditor groups them. The Common Criteria apply to every SOC 2 report; the four criteria after them apply only if scoped in.

Security: Common Criteria CC1–CC9

  1. CC1 Control environment. Board or leadership oversight of security is documented.
  2. CC1 Organizational structure, roles and reporting lines are defined.
  3. CC1 Background checks run before hire, on a documented policy.
  4. CC1 Security awareness training is delivered and completion is tracked.
  5. CC1 Code of conduct is acknowledged by every employee.
  6. CC2 Communication. Security policies are published where staff can reach them.
  7. CC2 A channel exists to report security concerns, including anonymously.
  8. CC2 Commitments to customers are communicated in writing.
  9. CC3 Risk assessment. A formal risk assessment runs at least annually.
  10. CC3 Risks are rated, owned and tracked to closure.
  11. CC3 Fraud risk is considered explicitly in that assessment.
  12. CC3 Vendor and third-party risk is assessed before onboarding.
  13. CC4 Monitoring. Control performance is reviewed on a defined cadence.
  14. CC4 Deficiencies are logged, escalated and remediated.
  15. CC5 Control activities. Controls are selected and documented against each risk.
  16. CC5 Technology controls are configured to policy and reviewed.
  17. CC6 Logical access. Access is granted on least privilege and approved.
  18. CC6 Multi-factor authentication is enforced on all production access.
  19. CC6 Access reviews run quarterly and are evidenced.
  20. CC6 Offboarding revokes access within a defined SLA.
  21. CC6 Data is encrypted in transit and at rest.
  22. CC6 Physical access to facilities and equipment is restricted.
  23. CC7 System operations. Vulnerability scanning runs on a defined schedule.
  24. CC7 Logging and alerting cover production systems.
  25. CC7 An incident response plan exists and has been tested.
  26. CC7 Incidents are logged, classified and reviewed post-hoc.
  27. CC8 Change management. Changes are reviewed and approved before release.
  28. CC8 Development, staging and production are separated.
  29. CC8 Emergency changes follow a documented exception path.
  30. CC9 Risk mitigation. Business continuity and disaster recovery plans exist.
  31. CC9 Vendor agreements include security and confidentiality terms.

Availability

  1. Capacity is monitored against forecast demand.
  2. Backups run on schedule and restores are tested, not assumed.
  3. A recovery plan defines RTO and RPO, and has been exercised.
  4. Environmental and infrastructure monitoring is in place with alerting.
  5. Availability commitments to customers are documented and measured.

Processing Integrity

  1. Inputs are validated before processing.
  2. Processing errors are detected, logged and corrected.
  3. Outputs are reconciled against expected results.
  4. Data quality and completeness are monitored on a defined cadence.

Confidentiality

  1. Confidential data is identified and classified.
  2. Retention periods are defined per classification.
  3. Secure disposal is documented and evidenced.
  4. Confidentiality obligations flow into vendor and employee agreements.

Privacy

  1. A privacy notice describes collection, use, retention and disclosure.
  2. Consent is captured where required and is revocable.
  3. Data subject access and deletion requests have a defined process and SLA.
  4. Personal data shared with third parties is governed by agreement.

Scope only what you need. Every optional criterion you add is more controls, more evidence and a longer audit. Add Availability or Confidentiality because a customer contract requires it, not because the list looks more impressive with five.

Evidence Your Auditor Will Ask For

The controls are the easy part. Evidence is where readiness projects overrun, because it has to exist for the whole window and it has to have an owner.

CriterionControlEvidence artifactUsual owner
CC1Security awareness trainingCompletion report with dates per employeePeople / HR
CC3Annual risk assessmentRisk register with ratings, owners, review dateSecurity lead
CC6Quarterly access reviewSigned review export per system, per quarterIT / Engineering
CC6MFA on productionIdP configuration export plus enrollment reportIT
CC6Offboarding revocationTicket showing revocation within SLA, sampledIT / People
CC7Vulnerability scanningScan reports across the window plus remediation ticketsEngineering
CC7Incident response testTabletop record with date, participants, findingsSecurity lead
CC8Change approvalPull request history showing review before mergeEngineering
CC9Backup restore testRestore test record with date and outcomeInfrastructure

The pattern that fails audits: quarterly access reviews that were only run once, in the quarter before fieldwork. Type 2 tests the window, and a gap in month two is a gap in the report.

How Long Each Stage Takes

StageTypical durationWhat decides it
Readiness & gap assessment2–4 weeksHow much is already documented
Remediation1–3 monthsEngineering capacity, not policy writing
Observation window (Type 2)3–12 monthsYour choice; 3 months is the common first report
Fieldwork2–6 weeksEvidence quality and auditor availability
Report issued2–4 weeksCPA firm's review cycle

A first Type 2 realistically runs six to twelve months end to end. A Type 1 skips the window and can be done in two to three months, which is why companies under customer pressure often do a Type 1 first and a Type 2 after.

What a SOC 2 Audit Costs

Avantcert readiness engagement ranges, already discounted 30–50% below typical market rates. The CPA firm's audit fee is separate.

TierEmployeesAvantcert readinessCPA audit feeMax duration
Startup5–50from $7,000Separate90 days
Mid-Market51–200around $16,000Separate90 days
Large Enterprise201–500up to $25,000Separate90 days

See the full SOC 2 certification cost breakdown, or use the calculator for your own scope.

Checklist vs Done-For-You: When to Bring in Help

Plenty of companies run readiness themselves off a list like this one. It works when you have someone who owns security as a real part of their job, an engineering team with capacity for remediation, and no customer deadline inside ninety days.

It stops working when the checklist reveals more gaps than your team can close, when evidence collection has already started late, or when a deal is contingent on the report. At that point the constraint is capacity, not knowledge.

What no one can DIY is the audit itself. SOC 2 reports are issued by an independent CPA firm, and the organization that prepares you cannot also attest. Any provider implying otherwise is describing something that is not a SOC 2 report.

Get a scoped readiness quote

Tell us your headcount and which criteria are in scope. Scoped estimate within 24 hours.

SOC 2 Checklist FAQs

What is on a SOC 2 compliance checklist?

A SOC 2 checklist covers the nine Common Criteria (CC1–CC9) that every report includes, plus any of the four optional Trust Services Criteria in your scope: Availability, Processing Integrity, Confidentiality and Privacy. For each control you need a documented policy, the control operating in practice, and evidence that it operated across the observation window.

What are the five SOC 2 Trust Services Criteria?

Security, Availability, Processing Integrity, Confidentiality and Privacy. Security, delivered through the nine Common Criteria, is mandatory in every SOC 2 report. The other four are optional and included only if you scope them in, usually because a customer asked.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 tests whether your controls are suitably designed at a single point in time. Type 2 tests whether they actually operated effectively across an observation window, typically three to twelve months. The checklist is the same; Type 2 additionally requires evidence that every control ran consistently for the whole window.

How long does SOC 2 compliance take?

Readiness and remediation typically take one to three months, then a Type 2 observation window of three to twelve months, then two to six weeks of fieldwork and about two to four weeks for the report. A Type 1 skips the observation window and can complete in roughly two to three months end to end.

How much does a SOC 2 audit cost?

Avantcert SOC 2 readiness engagements run from $7,000 for a 5–50 employee company, around $16,000 at 51–200, and up to $25,000 at 201–500 or complex scope, within a 90-day maximum. The CPA firm's audit fee is separate and paid directly to them.

Can I do SOC 2 myself with a checklist?

You can run readiness yourself, and many companies do. What you cannot do is audit yourself: SOC 2 reports are issued by an independent CPA firm, and the firm that prepares you cannot also attest. A checklist gets you organized; it does not remove the auditor.

Is SOC 2 a certification?

Strictly, no. SOC 2 produces an attestation report issued by a CPA firm under AICPA standards, not a certificate from an accreditation body. In practice buyers say "SOC 2 certified", but what you send them is a report, and there is no certificate to hang on a wall.

Do I need SOC 2 or ISO 27001?

SOC 2 is the North American norm and is usually driven by a specific customer asking for a report. ISO 27001 is the international certification and is more often required in Europe, the Middle East and Asia, or in tenders. Companies selling into both markets frequently end up holding both, and the control work overlaps heavily. See ISO 27001 vs SOC 2.

Download the Checklist

Take our free SOC 2 pre-audit checklist, 48 audit-ready items with the exact evidence your auditor will ask for, as a print-friendly PDF and an editable CSV tracker. No cost.

Related Reading

See SOC 2 certification services for how an engagement runs, what a Type 2 audit involves, SOC 2 for small businesses, or SOC 1 if your customers are asking about financial controls instead.

Want the checklist done for you?

We run readiness, collect the evidence, and stay with you through the auditor's fieldwork. See the full SOC 2 compliance guide for requirements, scope and cost in one place.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.