HomeBlogCompliance

SOC 2 Compliance Checklist: Requirements by Trust Services Criteria

Pixel-art illustration of a robot holding a tablet on a busy city sidewalk, with yellow taxis and pedestrians at a crosswalk behind it

A SOC 2 compliance checklist starts with the security criteria every report covers, the common criteria CC1 to CC9, then adds availability, confidentiality, processing integrity or privacy only if customers need them. For a small company the core is MFA, endpoint protection, logging, access reviews, change control, vendor reviews, incident response, tested backups and proof of each.

This is the checklist we work from in our SOC 2 readiness services, organized the way the AICPA organizes the criteria. If you have not chosen a report yet, read SOC 2 Type 1 vs Type 2 first, and for budgeting, see our SOC 2 audit cost guide.

What are the SOC 2 requirements?

SOC 2 has no fixed control list. Its requirements are the AICPA's 2017 Trust Services Criteria, with points of focus revised in 2022, and the AICPA calls them outcome-based: they describe what your controls must achieve, not which tools to buy. The criteria fall into two groups:

  • Common criteria, CC1 to CC9. CC1 to CC5 carry the 17 principles of the COSO internal control framework, grouped as control environment, communication and information, risk assessment, monitoring activities and control activities. CC6 to CC9 add logical and physical access, system operations, change management and risk mitigation. On their own, the common criteria are the complete set for security.
  • Additional criteria. Availability (A1), confidentiality (C1), processing integrity (PI1) and privacy (P1 to P8) each add criteria on top of the common criteria.

Each criterion comes with points of focus, but the AICPA says using the criteria does not require an assessment of whether each point of focus is addressed, and some may not suit your company at all. Treat them as prompts, not as the checklist.

Which Trust Services Criteria apply to your company?

CategoryCriteriaInclude it when
SecurityCC1 to CC9Always: every SOC 2 report covers the common criteria
AvailabilityA1.1 to A1.3Customers depend on your uptime, or you commit to service levels
ConfidentialityC1.1 and C1.2You hold customer information that contracts say to protect and later delete
Processing integrityPI1.1 to PI1.5Customers rely on your processing being complete, accurate and timely, as with billing or payments
PrivacyP1 to P8You collect personal information from individuals and make commitments about how you handle it

A smaller scope is cheaper and still credible. Add a category because a customer asked for it, not because it looks thorough.

What does the SOC 2 checklist include for the security criteria?

These are the controls we expect a small company to run for each part of the common criteria, and the evidence auditors commonly request. The criterion numbers are the AICPA's.

CriteriaControl for a small companyEvidence to keep
CC1: control environmentA code of conduct, a named security owner, background checks at hire, and security training at onboarding and every yearSigned acknowledgments, org chart, role descriptions, training completion records
CC2: communication and informationApproved security policies, a written system description, and a way for staff and customers to report security problemsPolicies with approval dates, staff acknowledgments, the system description
CC3: risk assessmentA yearly risk assessment that considers fraud and major changes to the businessA dated risk register with owners and decisions
CC4: monitoring activitiesPeriodic control reviews, vulnerability scans and a penetration test, with findings tracked to closureReview notes, scan and test reports, remediation tickets
CC5: control activitiesA written procedure and a named owner for every controlA control matrix mapping each control to its criteria and owner
CC6.1: logical accessMulti-factor authentication on every account, single sign-on and Conditional AccessMFA enforcement report, sign-in policy export
CC6.2 and CC6.3: user accessJoiner, mover and leaver steps tied to HR, least privilege, and quarterly access reviewsOnboarding and offboarding tickets matched to HR dates, signed access reviews
CC6.4 and CC6.5: physical access and disposalRestricted access to the office and equipment, and devices wiped before reuse or disposalAccess lists, disposal certificates
CC6.6 to CC6.8: network, data in transit and malwareA firewall, email filtering, encryption in transit and at rest, and endpoint detection and response on every deviceFirewall rule review, disk encryption report, EDR coverage report
CC7.1: vulnerabilities and configurationPatching on a schedule and baseline configurations for devices and serversPatch compliance reports, scan results with fix dates
CC7.2 and CC7.3: monitoringCentral logs, alerts that someone reviews, and suspicious events triagedAlert tickets, log retention settings, monitoring reports
CC7.4 and CC7.5: incident response and recoveryA written incident response plan, tested with a tabletop exercise, and a recovery procedureThe plan, the tabletop record, the incident log and post-incident reviews
CC8.1: change managementChanges requested, tested and approved before releaseSample change tickets with approvals and test notes
CC9.1 and CC9.2: risk mitigation and vendorsBusiness continuity planning, insurance considered for financial loss, and a vendor inventory reviewed every yearThe continuity plan, a vendor list with risk ratings, vendor reports reviewed

Some controls serve several criteria. Security awareness training supports CC1.4, which covers developing competent people, and CC2.2, which covers communicating security information internally. Tested backups support recovery under CC7.5 and the availability criteria below. Our vendor risk management guide goes deeper on CC9.2, and our incident response plan steps cover CC7.4.

What do the other Trust Services Criteria add?

CategoryWhat it addsEvidence to keep
Availability (A1.1 to A1.3)Capacity monitoring, backups and recovery infrastructure, and testing of recovery plan proceduresCapacity reports, backup job logs, restore test results with dates and measured times
Confidentiality (C1.1 and C1.2)Identifying confidential information and disposing of it when it is no longer neededA data inventory, a retention schedule, deletion records
Processing integrity (PI1.1 to PI1.5)Defined processing specifications, plus controls over inputs, processing, outputs and stored data so results are complete, accurate and timelySpecifications, validation checks, reconciliations, error logs
Privacy (P1 to P8)Notice, choice and consent, collection, use, retention and disposal, access, disclosure and notification, quality, and monitoring and enforcementThe privacy notice, consent records, a log of individuals' requests

What evidence will the auditor ask for?

For a Type 1, the auditor looks at whether each control is suitably designed as of the report date, so policies, configurations and procedures carry most of the weight. For a Type 2, the auditor also tests whether controls operated across the period, so you need records from throughout it: access reviews from each quarter, change tickets from different months, restore tests on the dates your schedule promised. Three habits make that easy:

  • Keep an evidence calendar that names who produces each record and when.
  • Export reports straight from the systems that run the controls, with dates visible, instead of rebuilding them later.
  • Store final versions only. A draft policy or an undated screenshot proves little.

How do you work through the SOC 2 checklist?

We run the work in nine steps:

  1. Scope the system. Choose the services, systems, people and vendors the report will cover, and the Trust Services Criteria your customers need beyond security.
  2. Run a gap assessment. Compare your current controls with each criterion in scope and turn every gap into a dated task with an owner.
  3. Write the policies. Write the security, access, change, incident, vendor and continuity policies your team will follow, and have staff acknowledge them.
  4. Implement the controls. Configure MFA, device management, endpoint protection, logging, backups and the other controls the gap list calls for.
  5. Collect evidence on a schedule. Keep an evidence calendar so access reviews, scans, restore tests and change records are produced and stored on time.
  6. Choose an independent CPA firm. Engage a licensed CPA firm that did not build your controls, and agree on the scope, criteria and timing.
  7. Get a Type 1 report if you need one soon. If a customer needs a report quickly, the CPA firm examines the design of your controls as of a date.
  8. Run the observation period. Operate every control through the agreed period and keep the records, because the auditor samples across it.
  9. Complete the Type 2 examination. The CPA firm tests the controls, you answer its requests from the evidence library, and the firm issues the report.

The AICPA notes that a CPA firm that designs or implements an attest client's systems can face threats to its independence, which is why step six names a firm that did not build your controls. We handle steps one to five and support the rest, starting with a free remote external penetration test within an agreed scope. For managed clients we already run many of the controls in Microsoft 365, Entra ID and Intune, so the evidence comes from systems we operate every day.

Frequently asked questions

Is there an official SOC 2 checklist?

No. The AICPA publishes the Trust Services Criteria, which are outcome-based, and leaves the controls to each company. Its points of focus describe characteristics of each criterion but are not required items. A checklist like the one above translates the criteria into controls and evidence for a typical small company; your scope may need more or less.

Do we need every Trust Services Criteria category?

No. Every SOC 2 covers the common criteria, which are the security category. Availability, confidentiality, processing integrity and privacy are optional and should be added only when customers need them, because each adds controls, evidence and audit fees.

What tools does SOC 2 require?

None by name. The criteria describe what controls must achieve, such as restricting logical access or detecting malicious software, so you can meet them with the tools you already run. A typical small company uses its identity provider, device management, endpoint protection, a logging platform and a ticketing system, plus a compliance platform if they want help tracking evidence.

Can a small company with no IT staff get SOC 2 ready?

Yes, with an outside provider running the controls and a named owner inside the company for the decisions only the business can make, such as who gets access and which vendors are approved. The provider builds and operates the controls; an independent CPA firm audits them.

Sources and further reading

SOC 2 Readiness Services

Discuss soc 2 readiness services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore SOC 2 Readiness Services 845-203-3914