Preparation

The SOC 2 Audit Checklist: Controls to Prepare Before Fieldwork

A practical pre-audit checklist across all five Trust Services Criteria — the evidence auditors ask for first.

How to use this checklist

Security is the only mandatory criterion; the other four are scoped by agreement with your auditor. Work the Security section first — it is the largest criterion and the one enterprise reviewers probe hardest — then the criteria in your scope. For each item, you need the control documented, operating, and evidenced.

Security (required)

Availability

Confidentiality

Turn reading into quotes. Get scoped, comparable quotes from licensed SOC 2 auditors — free, 2 minutes, no obligation.

Request quotes

Processing Integrity

Privacy

Evidence auditors actually ask for, by Trust Services Criterion

Controls are only half the audit — auditors test evidence. Below are examples of the artifacts auditors commonly request for each Security criterion (CC1–CC9). Your auditor's exact list varies, but if you can produce these, you're most of the way there.

CriterionWhat it coversEvidence examples auditors commonly request
CC1Control environmentOrg chart; information-security policy with annual employee acknowledgment records; background-check reports; security training completion logs
CC2Communication & informationPolicy distribution records; evidence security responsibilities are communicated (onboarding packets, all-hands decks); anonymous reporting channel records
CC3Risk assessmentAnnual risk assessment report; risk register; risk treatment/remediation plans with owners and dates
CC4MonitoringManagement review meeting minutes; control self-assessment records; deficiency tracking log showing issues to resolution
CC5Control activitiesDocumented procedures for key processes; evidence controls operate as written (sample tickets, approvals)
CC6Logical & physical accessUser access listings; MFA enrollment export; quarterly access-review sign-offs; termination tickets showing same-day deprovisioning; badge/facility access logs
CC7System operationsMonitoring and alerting configurations; vulnerability scan reports with remediation tickets; backup job logs; capacity monitoring records
CC8Change managementChange tickets with approvals and test evidence; deployment logs; rollback records; segregation-of-duties evidence
CC9Risk mitigation (vendors)Vendor inventory; vendor risk assessments; subservice organizations' SOC 2 reports; signed DPAs/BAAs

Evidence hygiene

The control existing isn't enough — auditors test evidence. For each control, keep: the policy or procedure, a timestamped artifact showing it operated (ticket, log export, review sign-off), and the owner's name. Organize by criterion before fieldwork starts; disorganized evidence is the #1 timeline killer. Take the 2-minute readiness quiz to see where you stand.

Keep reading

SOC 2 Type 1 vs Type 2: Which Report Do You Actually Need?

The real difference between Type 1 and Type 2, what enterprise buyers accept, and when the cheaper report is the right call.

How to Choose a SOC 2 Auditor: 9 Questions to Ask

The vetting checklist we recommend: license verification, team, fees, scope boundaries, and the red flags that signal a bad fit.

7 Common SOC 2 Audit Failures (and How to Avoid Each One)

The exceptions and qualifications auditors actually write — and the fixes that prevent them.

Questions

How many controls are in a typical SOC 2 audit?

It varies by scope, but Security-only audits commonly test 40–80 controls; adding criteria can push past 100. Your auditor finalizes the list during readiness.

Do I need all five Trust Services Criteria?

No — only Security is required. Scope the rest to what your customers ask for; each added criterion adds cost and testing.

Turn reading into quotes

Get scoped, comparable quotes from licensed SOC 2 auditors — free, 2 minutes.

Get a free quote