A checklist is a preparation tool
SOC 2 readiness is the work of getting a scoped service, its controls and its evidence ready for an appropriate professional examination. The AICPA resource listing identifies the trust-services criteria used in this area.1 This article is an original management checklist, not the criteria themselves or a promise of a successful report.
Treat readiness as a set of decisions and demonstrated practices. A policy may be approved while its procedure is not yet implemented. A procedure may operate while its evidence is incomplete. Those distinctions should remain visible throughout the project.
1. Confirm scope and the intended output
Before collecting files, agree what service the work covers. Document systems, people, processes, data, locations and material providers. Identify the customer commitments and system requirements relevant to the service.
Confirm the proposed report type and date or period with the CPA firm. A Type 2 engagement concerns operating effectiveness over its stated period; readiness services are not the examination.2 Do not assume a universal evidence period or delivery timetable from a marketing checklist.
The SOC 2 explainer describes report scope and type distinctions. Your scoping record should answer:
- Which service and environments are included?
- Which entity operates the service?
- Which categories and criteria are proposed?
- What external dependencies affect the controls?
- What responsibilities remain with customers?
- Who can approve scope changes?
2. Assign owners before assigning documents
Name the business sponsor, project coordinator and individual control owners. State who performs, checks and approves each important activity. A department name alone is insufficient when a request is overdue.
Confirm owner capacity. Readiness work may require technology, people operations, finance, customer support and leadership. Agree how competing delivery commitments will be handled and who decides when a dependency blocks progress.
Maintain a backup for essential evidence and operational tasks. The control should not depend on one person remembering an undocumented step.
3. Record risks and obligations
Identify scenarios that could prevent the service from meeting its commitments. Link relevant contractual, policy or legal obligations, with qualified interpretation where needed. Avoid treating a generic framework mapping as an applicability decision.
Each important risk should have current controls, evidence, uncertainty and a response. A treatment plan needs an owner and a completion criterion. Record acceptance authority and review dates where a gap remains temporarily unresolved.
This work helps explain why the controls exist. It also helps management avoid collecting a large volume of evidence that has no relationship to the agreed service.
4. Describe controls so they can be checked
For each control, record the trigger, performer, action, scope and retained evidence. State how exceptions are identified and escalated.
Compare “access is reviewed regularly” with “the application owner reviews the complete privileged-access export on the approved schedule, records removals and documents unresolved exceptions.” The second description gives a reviewer a clear question to investigate.
Do not invent frequencies or time limits purely to sound rigorous. Choose commitments your organization can operate, consistent with applicable requirements, then confirm their suitability with the relevant advisers and examiner.
5. Distinguish policies from operational evidence
Use a simple evidence map. The evidence-collection guide explains provenance, populations and protected handoffs:
| Readiness area | Intent or design record | Possible operational record |
|---|---|---|
| Access management | Approved access rules and roles | Provisioning, review and removal records |
| Changes | Change and emergency-change process | Reviewed changes and implementation records |
| Recovery | Recovery responsibilities and objectives | Measured restoration results and exceptions |
| Monitoring | Alert ownership and response process | Alert delivery and acknowledgement records |
| Suppliers | Review process and decision authority | Scoped supplier assessments and decisions |
| Staff practices | Training and responsibility expectations | Relevant completion and follow-up records |
These are examples, not an exhaustive evidence request. The examiner determines what is needed for the actual engagement. NIST SP 800-53A's examination, interview and testing methods can help owners think about how a claim is checked.3
6. Establish complete populations
When a control operates repeatedly, retain a way to identify its relevant occurrences. If a reviewer asks about changes during a period, a folder of five successful tickets does not establish that those are all the changes.
Record the source system, extraction filters, period, owner and reconciliation. Document exclusions and exceptions. Keep the original export when possible and explain modifications in a separate working copy.
Do not preselect favorable evidence and describe it as complete. Missing or failed records belong in the readiness review, with an explanation and an action.
Worked example: a monthly access review
This fictional team says it reviews privileged access monthly. The readiness coordinator finds an approved policy and two screenshots but cannot determine which accounts or months were covered.
The team creates an evidence map with the account inventory, complete monthly exports, reviewer decisions and completion records. One month has no retained review. Management records the gap, checks current access and decides how to address the historical exception with the examiner.
It does not recreate a document dated in the past and present it as an original review. A current reconstruction can explain what is now known, but should be labeled as reconstructed and retain its actual preparation date.
The next cycle produces a complete record under the improved process. That supports current operation; it does not erase the prior gap.
7. Test important procedures safely
Choose authorized checks that fit the scenario. A synthetic departure can test account removal. A labeled test alert can confirm delivery and ownership. An isolated restoration can check recoverability without risking customer data or interrupting production.
Define expected outcomes before testing and retain actual results, including failures. A test is not complete merely because someone clicked the button. Confirm the relevant end state and document limitations.
Coordinate changes through existing approval and access processes. Readiness urgency does not authorize bypassing production controls.
8. Track exceptions and remediation
For each gap, capture its scope, effect, owner, planned action and evidence of completion. Distinguish temporary workaround, implemented correction and verified closure.
Escalate overdue work and decisions beyond the owner's authority. Record who accepts any remaining exposure, the conditions and when that acceptance expires. A green project status should never hide an unresolved material decision.
9. Review readiness with management
Present a concise package: agreed scope, control ownership, evidence coverage, known exceptions and decisions required. Explain what is documented, implemented, operating with evidence or still under verification.
The review should decide whether to proceed, narrow or change the scope, remediate first or obtain further advice. It should not simply declare “SOC 2 compliant” based on completion of a checklist.
10. Prepare for the professional examination
Confirm request handling, authorized evidence access, key contacts and communication arrangements with the CPA firm. Preserve privacy and contractual restrictions when supplying evidence. Do not send credentials or unnecessary sensitive records in response to a broad request.
Keep the underlying processes operating during the examination and afterward. The report is an output at a point in time or for a stated period; ongoing service responsibilities continue.
Final readiness questions
Can you explain the scope without relying on a sales slogan? Does every important control have an owner? Can another authorized person retrieve its evidence and identify the relevant population? Are gaps recorded honestly? Are acceptance and change decisions approved by the appropriate people?
If those answers are clear, the checklist has done its job: it has made preparation explainable and accountable, while preserving the separate role of the professional examination.
Sources and references
-
AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus - 2022) (2023-09-30). Current resource listing identifies the trust-services criteria; downloading the complete resource requires a free account. ↩
-
AICPA. 2017 Trust Services Criteria, including March 2020 updates (2020-03). Public historical edition explains Type 1/Type 2 and readiness versus examination. Use the current 2022 revised-points-of-focus resource for an engagement. ↩
-
NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

