Free resource

The SOC 2 Compliance Checklist

Everything a first time team needs to move from scoping to a clean SOC 2 report, in one checklist you can work through with your team. Every box you cannot tick is part of your gap list.

Download the checklist

What is in a SOC 2 compliance checklist?

A SOC 2 compliance checklist covers the full path to your first report: deciding between Type I and Type II, selecting which Trust Services Criteria are in scope, writing the required security policies, meeting the nine Common Criteria controls (CC1 to CC9), collecting evidence across the observation period, and completing the audit with a licensed CPA firm. This free checklist from Qalea breaks each phase into concrete items so you can turn it into a gap list and a plan.

What is inside

SOC 2 is an attestation report issued by a licensed CPA firm, not a certificate. You become SOC 2 compliant and you hold a report. This checklist maps what that actually takes, in the order you will do it.

It is built for teams pursuing their first SOC 2 report, so it favours plain language over jargon and explains the decisions that shape scope, cost, and timeline before any control work begins.

1

Scope and decisions

Type I or Type II, which Trust Services Criteria apply, the system boundary, the observation period, and who owns the program.

2

Governance and policies

The full set of written policies an auditor expects, from information security to change management and incident response.

3

The controls, by Common Criteria

A working gap assessment across all nine Common Criteria groups (CC1 to CC9), the part the auditor actually tests.

4

Optional criteria

Availability, Confidentiality, Processing Integrity, and Privacy, including alignment with GDPR for European teams.

5

Evidence and the observation period

How to keep a continuous record so Type II holds up, rather than assembling evidence the week before fieldwork.

6

Audit and report

Readiness assessment, fieldwork, the report, and planning the next annual period.

Who it is for: founders, CTOs, and technical leads whose customers have started asking for SOC 2, and who want to understand the process before committing to it.

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation report produced by a licensed CPA firm. There is no certificate. You can say you are SOC 2 compliant and share your report under NDA, but claiming to be SOC 2 certified signals inexperience to the security team reviewing you.

What is the difference between SOC 2 Type I and Type II?

Type I attests that your controls are designed correctly at a single point in time. Type II attests that they operated effectively across a period, usually three to twelve months. Most buyers ask for Type II.

What are the Trust Services Criteria?

There are five: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Security, known as the Common Criteria, is always required. You add the others only where you make those commitments to customers.

What controls does a SOC 2 audit cover?

The Security criteria are organised into nine Common Criteria groups, CC1 to CC9, covering the control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation. The checklist lists the items an auditor typically examines in each.

How long does SOC 2 take?

It depends on how much of the groundwork already exists. The main driver of the timeline is the Type II observation period, during which your controls have to operate and produce evidence. The checklist helps you see how much of that groundwork is already in place.

Not sure where you stand? A free risk assessment from Qalea reviews your gaps, attack surface and posture, and hands you a prioritised plan.