Quick answer
To get SOC 2 compliant: (1) define your scope and Trust Services Criteria, (2) run a gap assessment, (3) implement controls, (4) write and enforce policies, (5) choose Type I or Type II, (6) collect evidence, (7) engage an independent CPA auditor, and (8) maintain controls for annual renewal. Most teams reach readiness in about 6–8 weeks, plus a 3–12 month window for a Type II.
The 8-step SOC 2 compliance checklist
- 1Define scope: choose which Trust Services Criteria (Security is required) and which systems, products, and teams the audit covers.
- 2Run a gap assessment: compare current controls against the criteria to find what's missing.
- 3Implement controls: close the gaps, access control, encryption, logging, monitoring, and more.
- 4Document policies: write, approve, and roll out the security policies that back each control.
- 5Choose Type I or Type II: decide the report type and, for Type II, set your observation window.
- 6Collect evidence: gather proof that each control operates, ideally automatically and continuously.
- 7Engage a licensed CPA firm: an independent auditor tests your controls and issues the report.
- 8Maintain and renew: keep controls running, monitor continuously, and renew annually.
What controls do you need for SOC 2?
SOC 2 is not a fixed checklist of controls, you choose controls that satisfy the Trust Services Criteria. These are the categories almost every program implements:
| Control area | Example controls |
|---|---|
| Access control | MFA everywhere, least-privilege roles, quarterly access reviews, prompt offboarding |
| Encryption | TLS in transit, AES-256 at rest, managed key rotation |
| Logging & monitoring | Centralized logs, alerting, and audit trails for critical systems |
| Change management | Peer-reviewed code, CI checks, and tracked change tickets |
| Vendor risk | Security review and inventory of subprocessors and critical vendors |
| Risk assessment | Annual risk assessment with documented treatment plans |
| Incident response | A written IR plan, on-call rotation, and post-incident reviews |
| HR security | Background checks, onboarding, and security awareness training |
Map controls once, reuse everywhere
Most SOC 2 controls overlap heavily with ISO 27001, HIPAA, and GDPR. If you plan to pursue multiple frameworks, map controls to all of them up front so you collect each piece of evidence once.
What evidence does a SOC 2 audit require?
The auditor needs proof that each control actually runs. For a Type II, they sample this evidence across the whole observation window, so it needs to exist consistently, not just the week before the audit. Typical evidence includes:
- Access review records and MFA configuration exports
- Onboarding and offboarding tickets tied to real dates
- System and infrastructure configuration (encryption, backups, logging)
- Change management and code-review records
- Completed security awareness training logs
- Vendor security reviews and your risk assessment
How do you know you're audit-ready?
You're ready when every in-scope control has an owner, a policy behind it, and current evidence that it operates, with no open gaps from your readiness assessment. This is where understanding the SOC 2 basics and picking the right report type pays off.

