SOC 2 compliance checklist
Forty-nine items in the order they have to happen, with the four that gate everything else named in the first paragraph. Your progress is saved in this browser, so you can work through it over weeks rather than in one sitting.
Four things gate everything else, and if you do only four things this quarter, do these: get the report type confirmed in writing, turn on multi-factor authentication everywhere including your cloud root accounts, start keeping evidence with dates on it, and pick your observation window start date. Everything else on this page can be done in parallel. Those four cannot be compressed later.
The list below is ordered the way the work actually happens rather than the way the criteria are numbered. Progress is stored in your own browser and nowhere else, so you can close the tab and come back.
Phase one: settle the scope
Two weeks, mostly waiting on other people. Doing this badly is the most expensive mistake available, because every later decision inherits it.
0 of 0 done ·
Use the deadline calculator once you have the date. It tells you whether a Type 2 can exist by then. What drives a quote covers how the scope decisions above turn into a fee.
Phase two: the control set
Two to five months, and this is where all the real work is. An auditor tests whether these operated, not whether you wrote them down, so a policy signed yesterday describing a process nobody follows is worse than no policy.
0 of 0 done ·
The one that fails most often
Access reviews. Companies do them and cannot prove they did, because the evidence is a Slack thread or a spreadsheet with no date and no reviewer name. An access review that cannot be evidenced did not happen as far as an examination is concerned. Decide now where the record lives and what it looks like, then do the first one badly rather than not at all.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Phase three: the observation window
Three to twelve months of calendar time, and almost no work if phase two was done properly. The window is the stage nobody can shorten, which is why it should open as early as the control set allows. How the window works covers choosing the length.
0 of 0 done ·
Phase four: fieldwork and the report
Four to ten weeks from the end of the window to a signed report, assuming your first evidence submission is complete. It usually is not, and that is what turns four weeks into ten.
0 of 0 done ·
The Canadian items nobody puts on these lists
None of the following is a SOC 2 requirement. A Canadian buyer or regulator will ask about all of them anyway.
0 of 0 done ·
The detail is on SOC 2 and PIPEDA, SOC 2 and Law 25, and data residency. A firm running your readiness that has not raised any of them is running an American playbook.
What is deliberately not on this list
A compliance platform. It is a genuine time saver at forty people and up, and under about twenty staff with one cloud account a spreadsheet and a disciplined owner will get you through a first audit for nothing. Where that line actually sits is the page to read before you spend $12,000 CAD a year on tooling to solve a problem you may not have.
Also missing: anything that promises a timeline shorter than the observation window. No item on any checklist changes the fact that a Type 2 examines a period that has already run.
Get quotes when the list is mostly green
Firms quote better and cheaper against a company that can describe its own control set.
Get matchedWhat is on a SOC 2 compliance checklist?
Four phases: settling the scope with whoever asked for the report, building a control set that runs rather than one that is written down, running the observation window while keeping evidence as it is produced, and fieldwork with the audit firm. The forty-nine items above are ordered the way the work happens rather than by criteria number.
How long does a SOC 2 checklist take to complete?
Six to twelve months from a standing start for a Type 2. Two weeks for scoping, two to five months of control work, three months minimum for the observation window, and four to ten weeks from the end of fieldwork to a signed report. Only the control-work stage responds to spending more money.
Which SOC 2 control fails most often?
Access reviews, and almost always for evidence rather than substance. Companies perform the review and cannot prove it, because the record is an undated spreadsheet or a chat thread with no reviewer named. Decide where the record lives before you run the first one.
Do I need a compliance platform to work through this?
No. Above roughly forty staff a platform saves real time on evidence collection. Under twenty, with one cloud account and someone who owns the work, a spreadsheet is enough for a first audit and saves $8,000 to $15,000 CAD in year one.
What Canadian items belong on a SOC 2 checklist?
A named accountable individual for privacy, a data inventory, a privacy impact assessment for personal information leaving Quebec, a confidentiality incident register, a retention schedule, and a written answer to the data residency question. None are SOC 2 requirements and all of them are asked about by Canadian buyers.