When an enterprise prospect emails "send us your SOC 2," the clock starts — and the work that actually gets you to a report is mostly readiness, not the audit itself. SOC 2 isn't a law or a certification; it's an independent attestation from a licensed CPA firm that your company does the security things it claims to do. Readiness is the phase where you put those things in place, write them down, and start producing evidence, so that when the auditor shows up there are no gaps to flag. Get readiness right and the audit is mostly sampling. Get it wrong and you either pay a consultant $10,000–$15,000 to tell you what's missing, or you end up with exceptions in your report.
This checklist covers the 12 control areas auditors expect for a Security-scope SOC 2 — the most common first-audit scope — broken into 24 concrete, do-able steps. Use the interactive version to track where you stand; nothing is stored or sent anywhere, it runs entirely in your browser.
Interactive SOC 2 readiness checklist
Tick everything that's already true for your company. Your readiness score and the number of remaining gaps update live, and we'll point you to the right next step. This is an educational planning tool — your auditor's scoping call is the source of truth.
1. Governance & policies
2. Access control
3. Change management & secure development
4. Risk assessment & vendor management
5. Incident response & business continuity
6. Logging, monitoring & encryption
7. HR security & awareness
8. Data classification & retention
9. Endpoints & vulnerability management
10. Scope, evidence & auditor
Twenty-four items across the 12 control areas auditors review for a first Security-scope SOC 2. A high score means you're close to engaging an auditor; gaps point to exactly where templates, a platform, or a focused sprint will help most.
2026 readiness timeline & effort
Readiness isn't a single task — it's three streams of work that overlap, followed by the audit itself. The table shows typical 2026 durations and costs for a startup doing a Security-scope SOC 2, assuming you start from templates rather than a blank page.
| Readiness phase | Typical 2026 duration | Typical cost | What happens |
|---|---|---|---|
| Scope & gap assessment | 3–7 days (DIY) | $0 (DIY) – $15,000 (consultant) | Decide criteria, run this checklist, list the gaps |
| Write & approve policies | 1–3 weeks | $0–$2,000 (templates) | Adopt the full policy set, customize for your stack |
| Implement technical controls | 2–6 weeks | Mostly internal time | MFA, logging, access reviews, change gates, encryption |
| Stand up evidence collection | Ongoing (parallel) | $0–$25,000/yr (platform) | Dated access reviews, training, monitoring logs |
| Penetration test | 1–2 weeks | $4,000–$15,000 | Annual; effectively expected by auditors |
| Readiness total (before audit) | ~4–12 weeks | ~$5,000–$30,000 | You are now audit-ready |
| Type II observation window | 3–6 months | Recurring platform/pen-test | Auditor observes controls operating |
| SOC 2 Type II audit (CPA firm) | 4–8 weeks fieldwork | $12,000–$45,000 | Report issued |
The pattern most founders miss: the audit fee is rarely the slow or expensive part. Readiness work and the months-long Type II observation window dominate the calendar, which is exactly why front-loading the checklist — and not discovering gaps mid-window — saves the most time and money. For the full line-by-line numbers, see the SOC 2 cost breakdown.
SOC 2 Audit Prep Kit for SaaS Founders
Every gap this checklist surfaces maps to a document or control in the kit: the full policy set written to the standard auditors expect, the Trust Services Criteria control mapping, and the evidence checklists that turn a folder of files into a defensible audit. It's the fastest way to skip the $10,000–$15,000 consultant gap assessment and turn red checkboxes green — built for early SaaS teams who need to move now.
- 14 core security policy templates (the full set)
- Trust Services Criteria control mapping
- Evidence-collection checklist per control
- Access-review & vendor-tracking trackers
- Incident-response & change-management runbooks
- Auditor-question prep prompts
SOC2Guide sells this digital product directly. It's a documentation accelerator, not legal or audit advice — your CPA firm issues the actual report. One-time purchase, instant download, free updates.
How to get SOC 2 ready faster (and cheaper)
Two startups can both "get SOC 2 ready" and spend months and tens of thousands of dollars apart. The levers below decide which side you land on.
1. Scope tightly — Security only, for now
Every extra Trust Services Criterion (Availability, Confidentiality, Processing Integrity, Privacy) adds controls, evidence and audit hours. The overwhelming majority of first-time companies need only Security — the "common criteria" — because that's what customers actually ask for. Don't get ready for criteria no contract requires; you can always add them later.
2. Start from templates, not a blank page
The slow part of readiness isn't writing — it's knowing what each policy must contain to satisfy an auditor and how the controls fit together. A complete, auditor-aligned policy template set compresses two to four weeks of drafting into a few days of customization, and it doubles as your own gap assessment, replacing the consultant line item entirely.
3. Automate evidence if it pays for itself
Evidence collection — dated access reviews, training records, monitoring logs — is the work that never stops. A compliance automation platform connects to your cloud, identity and HR tools and gathers most of it for you. For teams with several integrations and a continuous-monitoring need, that usually saves more engineering time than it costs; very small teams can run a first audit manually with disciplined folders.
4. Decide Type I vs Type II deliberately
If a deal is blocked today, a Type I report is faster and cheaper and often enough to keep it moving while you complete the Type II over the observation window. Some teams skip straight to Type II to avoid paying for two audits. The right call depends on how urgently a customer needs proof — model both in the cost & timeline estimator.
Should you use an automation platform?
If your readiness gaps are mostly about evidence — collecting and keeping the proof that your controls operate — a compliance automation platform can carry most of that load and keep you monitored after the audit. The three leaders are broadly comparable on core SOC 2 automation; they differ on onboarding, framework breadth and price, and all run startup tiers and partner programs.
Worth it once you have several integrations or want continuous monitoring; not a prerequisite for getting ready. Pricing is quote-based and scales with headcount.
Some links on this page are affiliate or partner links and we may earn a commission if you sign up, at no extra cost to you. We only list tools we consider genuinely useful, and these links never change our pricing or recommendations.
Read the full Vanta vs Drata vs Secureframe comparison → — pricing, integrations, frameworks and audit support side by side, with an interactive picker.
Keep going
Cost & timeline estimator
Get a tailored SOC 2 cost range and month estimate for your situation.
SOC 2 cost breakdown
Every line item and realistic 2026 all-in totals for startups and mid-market.
SOC 2 controls list
The nine Common Criteria families behind every checklist item, explained.
SOC 2 policy templates
The 14 documents auditors expect, what each covers and how it maps to the criteria.
Vanta vs Drata vs Secureframe
How the three leading automation platforms compare for SaaS teams.
SOC 2 audit-prep kit
Turn red checkboxes green — the full policy set, control mapping and evidence checklists.
SOC 2 FAQ
Type I vs II, ISO 27001, timelines and budget questions answered.
Turn your gaps into a plan
Score your readiness above, then grab the audit-prep kit and start closing the red boxes today.
Get the audit-prep kitFrequently asked questions
What is a SOC 2 readiness checklist?
It's the list of controls, written policies and evidence an auditor expects in place before they'll start your SOC 2. The AICPA doesn't publish a fixed form, but in practice it spans about a dozen control areas — access control, change management, incident response, risk assessment, vendor management, logging/monitoring, encryption, business continuity, secure development, HR security and the governance policies that tie them together. Working through it before you engage an auditor is the readiness (or gap) assessment.
How long does SOC 2 readiness take?
About 4–12 weeks of focused work for a typical startup, depending on how many controls already exist: roughly 1–3 weeks to write and approve policies, 2–6 weeks to implement missing technical controls, with evidence collection running in parallel. A Type II then adds the 3–6 month observation window. Templates and an automation platform compress the readiness phase the most.
Do I need a consultant to get SOC 2 ready?
No. A consultant gap assessment runs $10,000–$15,000 and largely produces the same control list this checklist covers. A founder or ops lead working from a complete, auditor-aligned template set can do their own gap assessment in a few days and spend the saved budget on the audit. Consultants earn their fee on complex, multi-criteria or enterprise scopes — not a first Security-only startup audit.
What's the difference between readiness and the actual audit?
Readiness is preparation — you put the controls, policies and evidence in place and confirm there are no gaps. The audit is when a licensed CPA firm independently tests them and issues the report (Type I checks design at a point in time; Type II observes controls operating over months). You always do readiness first; rushing in with gaps leads to exceptions or a repeated observation window.
What technical controls does SOC 2 require for a startup?
The core set: MFA enforced everywhere (email, cloud, repos, admin); role-based least-privilege access with quarterly reviews and prompt offboarding; encryption in transit and at rest; centralized logging with retention and alerting; vulnerability management plus an annual pen test; gated change management (PR review, CI/CD); endpoint protection/MDM; and tested, monitored backups. Each needs a matching written policy and ongoing evidence.
Can I track SOC 2 readiness without a platform?
Yes, especially for a first audit. A small team can track readiness with a structured checklist, a complete policy set and disciplined, dated evidence folders. The interactive checklist on this page is a fine starting point. Platforms like Vanta, Drata and Secureframe become worth it once you want continuous monitoring and automated evidence across many integrations — but they aren't a prerequisite for getting ready or passing.