SOC2 auditors evaluate your controls against the Trust Service Criteria. This checklist covers the most common requirements for startups pursuing SOC2 Type II with Security (and optionally Availability and Confidentiality) criteria.
Use this to self-assess before engaging an auditor. Items marked as critical are almost always required; others depend on your scope.
Access Control
Each employee has their own account—no shared credentials.
MFA enabled on all production systems, cloud consoles, and SaaS tools.
Access granted based on job function, not individual requests. Principle of least privilege.
Documented review of who has access to what, at least quarterly.
Documented procedure for revoking access when employees leave.
Minimum length, complexity, and rotation requirements documented and enforced.
Change Management
All code in Git with commit history preserved.
Pull requests require approval before merge. Branch protection enabled.
Development, staging, and production environments isolated.
How code gets from commit to production is documented.
Documented process for reverting bad deployments.
Risk Management
Annual identification and assessment of security risks.
Process for evaluating security of third-party services.
Document how identified risks are mitigated, accepted, or transferred.
Incident Response
Documented procedure for detecting, responding to, and recovering from security incidents.
Record of security incidents and how they were handled.
Who to notify (customers, authorities) in case of breach.
Logging & Monitoring
Authentication events, data access, and admin actions logged.
Logs retained for at least 90 days, preferably 1 year.
Alerts for suspicious activity (failed logins, unusual access patterns).
Logs tamper-evident or stored in immutable storage.
Data Protection
Database and storage encryption enabled (AES-256).
TLS 1.2+ for all data transmission.
Backups encrypted and stored separately from production.
Document what data you store and its sensitivity level.
HR & Training
Pre-employment screening for employees with system access.
Annual training on security policies and phishing awareness.
Documented policy employees sign regarding system usage.
Policies & Documentation
Master policy covering security commitments and responsibilities.
Documentation of your system architecture, data flows, and boundaries.
Policies dated, versioned, and reviewed annually.
This Is Not Exhaustive
This checklist covers common requirements, but your specific scope may require additional controls. Availability criteria adds uptime and disaster recovery requirements. Confidentiality adds data handling controls. Always work with your auditor to confirm scope.
Next Steps
- Self-assess: Go through this checklist and identify gaps
- Prioritize: Start with critical items, then work through the rest
- Get a readiness assessment: We can scan your systems and map findings to these controls
- Remediate: Fix the gaps before engaging an auditor
- Engage auditor: When you're ready, select a CPA firm for the audit
Get Your SOC2 Readiness Assessment
We scan your code and infrastructure, map findings to SOC2 controls, and give you a prioritized remediation plan—so you know exactly where you stand before engaging an auditor.
View Pricing →