◆ traztech
SOC 2 Readiness Checklist
A practical, plain-language checklist to gauge how close you are to a SOC 2 audit. Tick what is already true; the blanks are your gap list.
SOC 2 is an attestation, not a certification (buyers still call it certification). Security is the only mandatory Trust Services Criterion; add Availability, Confidentiality, Processing Integrity, or Privacy only when you actually commit to them.
Access control
- MFA enforced on all critical systems (cloud, email, code, prod)
- Documented onboarding and offboarding with 24-hour access removal
- Quarterly access reviews with records kept
- Least-privilege roles, no shared admin accounts
Policies & governance
- Information security policy, reviewed annually
- Acceptable use, data classification, and change management policies
- Incident response plan that has been tested at least once
- A named owner for the security program
Technical controls
- Encryption at rest and in transit, with key management documented
- Centralized logging and monitoring with retention
- Vulnerability scanning and a patch cadence
- Documented backup and tested restore
Vendor & change management
- Vendor risk register with subprocessor SOC 2 reports on file
- Change management with review and approval for production
- Separate review for changes to sensitive/financial logic
Evidence (the part teams underestimate)
- Evidence collected continuously, not reconstructed before the audit
- Tickets, logs, review records, and approvals retained across the observation window
- A compliance tool (Vanta, Drata, or similar) or an equivalent evidence process