Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
/var/www/traztech.ca/html/blog/post.php on line 12748
22; color:
Warning: Undefined array key "Compliance" in /var/www/traztech.ca/html/blog/post.php on line 12748
;">Compliance

SOC 2 Requirements: A Practical Checklist

SOC 2 certification is the credential most B2B SaaS deals now require before a contract gets signed. Technically, SOC 2 is an attestation, not a certification, but buyers search "SOC 2 certification" and that is the shorthand we will use here. What matters is not the label. What matters is whether you can pass an independent audit without scrambling for six months first.

This checklist covers what SOC 2 actually requires, in the order most companies tackle it. Use it to scope your own readiness effort, or to sanity-check a vendor's proposal.

1. Pick Your Trust Services Criteria

SOC 2 is built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory for every SOC 2 report, it covers access controls, system monitoring, and protection against unauthorized access. The other four are optional and depend on what you sell and what your customers ask about.

  • Security (mandatory): access management, network protections, vulnerability management, incident response.
  • Availability: relevant if customers care about uptime commitments or SLAs.
  • Processing Integrity: relevant if you process transactions or data where accuracy and completeness matter (payments, billing engines).
  • Confidentiality: relevant if you handle sensitive business data under NDA or contract.
  • Privacy: relevant if you handle personal information directly, separate from your general security posture.

Most first-time SaaS companies scope Security plus Availability and stop there. Adding criteria you do not need adds audit cost and evidence burden without moving the deals that are actually blocked.

2. Choose Type I or Type II

A Type I report checks whether your controls are designed correctly as of a single point in time. A Type II report checks whether those controls actually operated effectively over a period, typically three to twelve months. Enterprise buyers increasingly ask for Type II by default, since it demonstrates the controls held up in practice, not just on paper. If you are early and need something to show prospects quickly, Type I can bridge the gap, but expect most serious deals to eventually require Type II.

3. Define Your System Boundary and Scope

Before any controls work starts, you need a written description of the system being audited: what infrastructure, applications, and data flows are in scope, who your subservice organizations are (AWS, payment processors, subprocessors), and where the boundary sits. Getting this wrong is one of the most common causes of delay, either the scope is too broad and drags in systems that do not need auditing, or too narrow and leaves gaps a buyer's security team will flag during due diligence.

4. Build the Core Control Set

This is the bulk of the work. At minimum, expect to implement and document controls across:

  • Access control: role-based access, least privilege, periodic access reviews, offboarding procedures.
  • Change management: code review, deployment approvals, rollback procedures.
  • Risk assessment: a documented process for identifying and evaluating security risks, done at least annually.
  • Vendor and subprocessor management: due diligence on third parties that touch your data.
  • Vulnerability and patch management: scanning cadence, remediation timelines, tracking.
  • Incident response: a written plan, defined roles, and evidence you have tested it.
  • Business continuity and disaster recovery: backup procedures and a recovery plan, tested periodically.
  • Security awareness training: onboarding and annual training for staff.
  • Logging and monitoring: centralized logs, alerting, and a defined review cadence.

Auditors are not just checking that a policy document exists. They want evidence the control operates as written, which is why Type II reports pull samples across the audit period rather than a single snapshot.

5. Write Policies That Match Reality

A common failure mode is buying a policy template pack, publishing it, and then running operations that do not match what the policies describe. Auditors will catch this. Policies need to reflect what your team actually does, not an idealized version of it. If your policy says access reviews happen quarterly, you need four quarters of evidence showing they happened.

6. Collect and Organize Evidence

For a Type II audit, you need evidence spanning the entire observation window, screenshots, exported logs, ticket records, signed-off reviews, training completion records. Manual evidence collection is the single biggest time sink in most readiness projects. Automated evidence collection tools can cut this down significantly, but someone still needs to map each control to the right evidence and keep it current as systems change.

7. Run a Readiness Assessment Before the Real Audit

A readiness assessment, sometimes called a gap assessment, tells you where your control environment falls short before an independent CPA firm looks at it. This step catches the issues that would otherwise surface mid-audit, when fixing them costs more time and can push your report date. It is also where most of the actual project risk lives, so it deserves a fixed scope and a clear deliverable rather than an open-ended engagement.

8. Engage an Independent CPA Auditor

SOC 2 reports must be issued by a licensed CPA firm that is independent of the organization being audited. This is a hard requirement under AICPA standards, a readiness consultant cannot also issue your report. The practical path most companies take is to work with a firm that handles readiness and control implementation, then hand off to an independent CPA auditor for the formal engagement. That separation is not a formality, it is what makes the report credible to the enterprise buyers asking for it.

This is the model traztech's compliance readiness work follows: fixed-scope preparation to close control gaps and organize evidence, then coordination with an independent CPA firm for the actual attestation. We are not the auditor, and we do not pretend to be. Our job is making sure the audit is short, predictable, and does not surface surprises.

9. Plan for Continuous Compliance

SOC 2 is not a one-time project. Type II reports cover a period and need to be renewed, typically annually, to stay useful in sales conversations. Building your control environment with ongoing maintenance in mind, rather than a one-off sprint to a report date, saves significant rework the following year. Companies that also need to demonstrate AI governance maturity alongside SOC 2 should look at how that overlaps with frameworks like ISO 42001 readiness, since some evidence and controls carry across both.

The Bottom Line

SOC 2 requirements come down to five Trust Services Criteria (Security is mandatory), a choice between Type I and Type II, a defined system boundary, a working set of controls with real evidence behind them, and an independent CPA firm to issue the report. The checklist above is the scope. The hard part is execution, and where most projects lose months is in evidence collection and control gaps that only surface once an auditor starts asking questions.

If you are staring down a SOC 2 requirement from a customer or investor and want a straight answer on scope, timeline, and cost before you commit to anything, get in touch with traztech. We will tell you what your actual gap looks like, not sell you a bigger engagement than you need.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on the unglamorous side of building a startup. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation