Back to Blog
SOC 2 8 min read

SOC 2 Audit Prep Checklist: 60 Items Before Field Work

A comprehensive 60-item SOC 2 audit preparation checklist. Verify every policy, control, evidence item, and team preparation task before auditor fieldwork begins.

Key Takeaways
  • This 60-item checklist covers policies, controls, evidence, team preparation, and auditor logistics.
  • Complete the checklist 6–8 weeks before your planned fieldwork start date.
  • Items that are not complete 2 weeks before fieldwork represent active risks to your audit outcome.
  • Every gap identified in the checklist is better to find now than during fieldwork.
  • After completing the checklist, brief your team — they need to know the audit process and their role in it.

Policies (Items 1–12)

1. Information Security Policy — approved, dated, current version, distributed to all employees. 2. Access Control Policy — defines provisioning, review frequency, MFA requirements, privileged access. 3. Encryption Policy — covers encryption at rest and in transit, acceptable standards (AES-256, TLS 1.2+). 4. Incident Response Policy — includes severity levels, response team, notification timelines. 5. Change Management Policy — covers approval requirements, testing, emergency change process.

6. Vulnerability Management Policy — defines scan frequency, CVSS thresholds, remediation SLAs. 7. Risk Assessment Policy — describes risk methodology, frequency, risk register maintenance. 8. Vendor Management Policy — tiering, review frequency, DPA requirements. 9. Data Classification Policy — sensitivity levels and handling requirements. 10. Backup and Recovery Policy — backup frequency, retention, restore test requirements. 11. Business Continuity Policy — BCP scope, RTO/RPO targets, testing frequency. 12. Acceptable Use Policy — employee system use, personal device policy, enforcement.

Technical Controls (Items 13–28)

13. MFA enabled for all users with console access (IAM, GitHub, Okta). 14. MFA required (not just available) — sign-on policy configured. 15. Root account MFA enabled, no root access keys. 16. IAM password policy configured (minimum 14 characters, complexity). 17. CloudTrail enabled in all regions, multi-region trail. 18. CloudTrail log file validation enabled. 19. CloudTrail logs encrypted with KMS. 20. CloudTrail log retention set to 12+ months.

21. GuardDuty enabled in all regions. 22. Security Hub enabled, CIS AWS Foundations Benchmark active. 23. AWS Config enabled in all regions with key rules. 24. S3 buckets: public access blocked at account level. 25. RDS instances: storage encrypted, public access disabled. 26. EC2 instances: security groups reviewed — no 0.0.0.0/0 SSH or RDP. 27. GitHub branch protection: required reviews, required CI status checks. 28. SSO coverage: all production system access requires SSO authentication.

Evidence (Items 29–44)

29. IAM credential report — current export, all users MFA_Active = true. 30. Security Hub compliance score export (dated within 30 days). 31. GuardDuty finding summary (dated within 30 days, no unaddressed HIGH findings). 32. Access review — Q1 completion documented. 33. Access review — Q2 completion documented (if observation period includes Q2). 34. Access review — Q3 completion documented (if applicable). 35. Access review — Q4 completion documented (if applicable).

36. Terminated employee offboarding checklists — at least 2 samples, all systems confirmed. 37. Change management tickets — 5–10 samples showing required PR reviews and approvals. 38. Vendor risk register — current, all Tier 1 vendors listed. 39. Vendor SOC 2 reports — current reports for AWS, Okta, GitHub, and other Tier 1 vendors. 40. Penetration test report — dated within 12 months. 41. Vulnerability tracking spreadsheet — all open items with CVSS scores and remediation dates. 42. Incident response tabletop exercise record — dated within 12 months. 43. Security awareness training completion report — 90%+ employee completion. 44. Backup restore test record — dated within 3 months.

Team Preparation (Items 45–52)

45. Programme owner briefed on all controls they own. 46. Engineering lead briefed on change management and technical controls they own. 47. HR/Operations briefed on access reviews, termination checklists, and training they own. 48. Brief on control walkthrough process: how interviews work, what auditors ask, how to answer. 49. Consistent answers confirmed: programme owner, engineering lead, and HR lead have reviewed key controls and will give consistent answers.

50. All-hands communication: team knows audit fieldwork is upcoming, why, what to expect if interviewed. 51. Auditor portal access: compliance tool configured for auditor read-only access, auditor account created. 52. PBC response process: owner of PBC management identified, 2-day response commitment confirmed.

Auditor Logistics (Items 53–60)

53. Engagement letter signed and filed. 54. Fieldwork start date confirmed with auditor. 55. Fieldwork end date confirmed (realistic given evidence complexity). 56. Auditor kickoff meeting scheduled. 57. System description document — final draft reviewed by programme owner, ready for auditor review. 58. Control matrix in compliance tool — all criteria mapped to controls, evidence linked. 59. Auditor portal — compliance tool auditor access configured and tested. 60. Report delivery timeline agreed — draft report expected date, final report expected date, deal commitments aligned.

Frequently Asked Questions

When should I complete this checklist?
6–8 weeks before planned fieldwork start date. This gives you time to address remaining gaps before fieldwork begins. Completing the checklist 1 week before fieldwork with significant items incomplete is a red flag — push the fieldwork date rather than entering with known gaps.
What if I cannot complete all 60 items?
Prioritise by audit risk. Items 1–44 (policies and evidence) are critical. Items 45–60 (team preparation and logistics) can be partially addressed with accelerated preparation. An incomplete checklist is still more valuable than no checklist — it tells you exactly where to focus.
Is this checklist suitable for Type I and Type II?
With adjustments: for Type I, the evidence items (29–44) focus on current-state evidence rather than observation period coverage. For Type II, all access review, change management, and incident response evidence items must cover the full observation period.
Should I share this checklist with my auditor?
You can share your completion status as an indicator of readiness, but the checklist itself is internal documentation. The auditor's PBC list (sent at fieldwork start) is the formal evidence request — your checklist ensures you are ready to respond.
What is the most commonly incomplete item on this checklist?
Based on experience, the most commonly incomplete items are: item 40 (penetration test — scheduling lead time is underestimated), item 41 (vulnerability tracking — gaps discovered during observation period were not tracked), and item 44 (backup restore test — configured but never actually tested).

Automate your compliance today

AuditPath runs 86+ automated checks across AWS, GitHub, Okta, and 14 more integrations. SOC 2 and DPDP Act. Free plan available.

Start for free