SOC 2 Audit Prep Checklist: 60 Items Before Field Work
A comprehensive 60-item SOC 2 audit preparation checklist. Verify every policy, control, evidence item, and team preparation task before auditor fieldwork begins.
- This 60-item checklist covers policies, controls, evidence, team preparation, and auditor logistics.
- Complete the checklist 6–8 weeks before your planned fieldwork start date.
- Items that are not complete 2 weeks before fieldwork represent active risks to your audit outcome.
- Every gap identified in the checklist is better to find now than during fieldwork.
- After completing the checklist, brief your team — they need to know the audit process and their role in it.
In this guide
Policies (Items 1–12)
1. Information Security Policy — approved, dated, current version, distributed to all employees. 2. Access Control Policy — defines provisioning, review frequency, MFA requirements, privileged access. 3. Encryption Policy — covers encryption at rest and in transit, acceptable standards (AES-256, TLS 1.2+). 4. Incident Response Policy — includes severity levels, response team, notification timelines. 5. Change Management Policy — covers approval requirements, testing, emergency change process.
6. Vulnerability Management Policy — defines scan frequency, CVSS thresholds, remediation SLAs. 7. Risk Assessment Policy — describes risk methodology, frequency, risk register maintenance. 8. Vendor Management Policy — tiering, review frequency, DPA requirements. 9. Data Classification Policy — sensitivity levels and handling requirements. 10. Backup and Recovery Policy — backup frequency, retention, restore test requirements. 11. Business Continuity Policy — BCP scope, RTO/RPO targets, testing frequency. 12. Acceptable Use Policy — employee system use, personal device policy, enforcement.
Technical Controls (Items 13–28)
13. MFA enabled for all users with console access (IAM, GitHub, Okta). 14. MFA required (not just available) — sign-on policy configured. 15. Root account MFA enabled, no root access keys. 16. IAM password policy configured (minimum 14 characters, complexity). 17. CloudTrail enabled in all regions, multi-region trail. 18. CloudTrail log file validation enabled. 19. CloudTrail logs encrypted with KMS. 20. CloudTrail log retention set to 12+ months.
21. GuardDuty enabled in all regions. 22. Security Hub enabled, CIS AWS Foundations Benchmark active. 23. AWS Config enabled in all regions with key rules. 24. S3 buckets: public access blocked at account level. 25. RDS instances: storage encrypted, public access disabled. 26. EC2 instances: security groups reviewed — no 0.0.0.0/0 SSH or RDP. 27. GitHub branch protection: required reviews, required CI status checks. 28. SSO coverage: all production system access requires SSO authentication.
Evidence (Items 29–44)
29. IAM credential report — current export, all users MFA_Active = true. 30. Security Hub compliance score export (dated within 30 days). 31. GuardDuty finding summary (dated within 30 days, no unaddressed HIGH findings). 32. Access review — Q1 completion documented. 33. Access review — Q2 completion documented (if observation period includes Q2). 34. Access review — Q3 completion documented (if applicable). 35. Access review — Q4 completion documented (if applicable).
36. Terminated employee offboarding checklists — at least 2 samples, all systems confirmed. 37. Change management tickets — 5–10 samples showing required PR reviews and approvals. 38. Vendor risk register — current, all Tier 1 vendors listed. 39. Vendor SOC 2 reports — current reports for AWS, Okta, GitHub, and other Tier 1 vendors. 40. Penetration test report — dated within 12 months. 41. Vulnerability tracking spreadsheet — all open items with CVSS scores and remediation dates. 42. Incident response tabletop exercise record — dated within 12 months. 43. Security awareness training completion report — 90%+ employee completion. 44. Backup restore test record — dated within 3 months.
Team Preparation (Items 45–52)
45. Programme owner briefed on all controls they own. 46. Engineering lead briefed on change management and technical controls they own. 47. HR/Operations briefed on access reviews, termination checklists, and training they own. 48. Brief on control walkthrough process: how interviews work, what auditors ask, how to answer. 49. Consistent answers confirmed: programme owner, engineering lead, and HR lead have reviewed key controls and will give consistent answers.
50. All-hands communication: team knows audit fieldwork is upcoming, why, what to expect if interviewed. 51. Auditor portal access: compliance tool configured for auditor read-only access, auditor account created. 52. PBC response process: owner of PBC management identified, 2-day response commitment confirmed.
Auditor Logistics (Items 53–60)
53. Engagement letter signed and filed. 54. Fieldwork start date confirmed with auditor. 55. Fieldwork end date confirmed (realistic given evidence complexity). 56. Auditor kickoff meeting scheduled. 57. System description document — final draft reviewed by programme owner, ready for auditor review. 58. Control matrix in compliance tool — all criteria mapped to controls, evidence linked. 59. Auditor portal — compliance tool auditor access configured and tested. 60. Report delivery timeline agreed — draft report expected date, final report expected date, deal commitments aligned.
Frequently Asked Questions
When should I complete this checklist?
What if I cannot complete all 60 items?
Is this checklist suitable for Type I and Type II?
Should I share this checklist with my auditor?
What is the most commonly incomplete item on this checklist?
Automate your compliance today
AuditPath runs 86+ automated checks across AWS, GitHub, Okta, and 14 more integrations. SOC 2 and DPDP Act. Free plan available.
Start for free