Skip to content
AuditFront
SOC 2xlsx

SOC 2 Readiness Checklist

Assess all five Trust Services Criteria, find gaps before the audit, and prioritize remediation. Start online without an account or download the XLSX.

No account required · Autosaves in this browser for 30 days · Sign up only to keep it

What's Inside

Complete checklist covering all five SOC 2 Trust Services Criteria with detailed control objectives
Evidence request list reflecting common CPA firm audit requirements for each criterion
Readiness status tracker with Yes/No/Partial/Not Applicable status for each control
Pre-audit preparation timeline with recommended milestones for 90-day, 60-day, and 30-day checkpoints
Stakeholder assignment matrix to delegate evidence collection responsibilities across team members
Evidence inventory worksheet to catalog documents, screenshots, and configurations already gathered
Gap summary dashboard with automatic calculation of readiness percentage per criterion
Auditor selection criteria checklist to help evaluate and choose the right CPA firm

About This Template

The checklist is organized around the AICPA's Trust Services Criteria: Security (CC1-CC9, always required), Availability (A1), Processing Integrity (PI1), Confidentiality (C1), and Privacy (P1). For each criterion, the template breaks down the specific control objectives, lists the evidence an auditor will typically request, and provides a clear yes/no/partial status field to track your readiness. This is not a generic overview - it reflects the actual evidence requests and control expectations that CPA firms evaluate during SOC 2 engagements.

Beyond the checklist itself, the template includes a pre-audit preparation timeline with recommended milestones, a stakeholder assignment matrix so you can distribute evidence collection across your team, and an evidence inventory worksheet to track which documents, screenshots, and configurations you have already gathered. For companies preparing for their first SOC 2 audit, this template transforms what can feel like an opaque and intimidating process into a concrete, step-by-step project plan. For companies preparing for annual re-audits, it serves as a structured reminder to refresh evidence and verify that controls have been maintained since the last audit period.

Who It's For

Engineering and security teams preparing for their first SOC 2 auditCTOs and VPs of Engineering who are responsible for SOC 2 compliance at their companyCompliance officers managing annual SOC 2 re-audit preparationStartup founders who need to demonstrate SOC 2 readiness to enterprise customersOperations teams responsible for gathering and organizing audit evidence

How It Works

1

Open the assessment

Start the SOC 2 checklist in AuditFront. No account is required.

2

Answer and see gaps

Work through each question and see your score, findings, and priorities.

3

Keep it when useful

Your work autosaves for 30 days. Create a free account only to keep it or use another device.

Frequently Asked Questions

Does this checklist cover both Type 1 and Type 2 audits?
Yes. The control objectives and evidence requirements are the same for both Type 1 and Type 2 audits - the difference is whether the auditor evaluates controls at a point in time (Type 1) or over a period (Type 2). This checklist helps you prepare for either type. For Type 2 preparation, pay special attention to the evidence inventory section, as you will need to demonstrate that controls operated consistently throughout the observation period.
Which Trust Services Criteria should I include in my audit?
Security (Common Criteria) is always required. Beyond that, include the criteria your customers request. SaaS companies typically include Availability. Companies handling sensitive data add Confidentiality. If data accuracy is critical to your service, include Processing Integrity. Privacy is relevant if you process personal information. This checklist covers all five criteria so you can evaluate readiness across any combination.
How far in advance should I start preparing for a SOC 2 audit?
For a first-time audit, start preparation at least 3-6 months before your target audit date. This gives you time to implement missing controls, write policies, and gather evidence. The pre-audit timeline in this template recommends specific milestones at 90, 60, and 30 days before the audit engagement begins.

Ready to see where you stand?

Run the full SOC 2 assessment with guided questions, progress scoring, prioritized findings, and an exportable readiness report. Included on the Free plan.

Start free SOC 2 assessment

No account required · Autosaves for 30 days · No credit card