SOC 2 checklist for startups, from first step to report
A practical SOC 2 checklist for startups: scope, policies, access, change management, vendors, incidents, evidence and the audit, in order.
A SOC 2 checklist is useful because the work is mostly the same for every small company. The details change with your stack, but the categories do not. This SOC 2 checklist is written for startups preparing a first report: small teams, cloud-hosted, with Security in scope. Work through it in order. Each section builds on the one before it.
A quick reminder of what you are preparing for. SOC 2 is an AICPA framework. An independent, licensed CPA firm examines your controls against the Trust Services Criteria and issues a report. A Type 1 covers design as of one date. A Type 2 covers design and operation over a period, usually three to twelve months.
1. Readiness and scope
- [ ] Take a readiness assessment and save the gap list. Ours is a free readiness assessment.
- [ ] Decide the report type your buyer needs: Type 1 or Type 2.
- [ ] Confirm Security is in scope, and add optional criteria only if a customer requires them.
- [ ] List the systems that store or process customer data.
- [ ] List the people and roles with access to those systems.
- [ ] Name one owner for the SOC 2 program.
- [ ] Draft a system description: what your service does, how it is built, where data lives.
2. Policies
Write policies that describe what you actually do. A policy that promises more than you practice becomes a finding.
- [ ] Information security policy
- [ ] Access control policy
- [ ] Change management policy
- [ ] Incident response plan
- [ ] Business continuity and disaster recovery plan
- [ ] Vendor management policy
- [ ] Risk assessment policy
- [ ] Data classification and retention policy
- [ ] Acceptable use policy
- [ ] Each policy approved by leadership, with a date
- [ ] Each employee has acknowledged the policies
3. Access control
- [ ] MFA enforced on the identity provider, cloud console, code host and email.
- [ ] Single sign-on where your tools support it.
- [ ] Least-privilege access: people have only what their role needs.
- [ ] Production access limited to the people who need it.
- [ ] Shared accounts removed or documented with a reason.
- [ ] Access reviews scheduled, usually quarterly, with a record of each one.
4. People
- [ ] A written onboarding checklist, including policy acknowledgment and security training.
- [ ] A written offboarding checklist, with access removed promptly and recorded.
- [ ] Security awareness training for everyone, repeated each year.
- [ ] Background checks where your jurisdiction allows them and your policy requires them.
- [ ] Contractors covered by the same rules as employees.
5. Change management and engineering
- [ ] Every code change reviewed by someone other than the author.
- [ ] Branch protection on the main branch.
- [ ] Production changes traceable to a ticket or pull request.
- [ ] Separate environments for development and production.
- [ ] Dependency and vulnerability scanning in place, with a process for fixing findings.
6. Infrastructure and data
- [ ] Encryption at rest for databases and storage.
- [ ] Encryption in transit (TLS) for all external traffic.
- [ ] Logging enabled for key systems, with logs retained according to your policy.
- [ ] Alerts for security-relevant events.
- [ ] Backups running, and at least one restore tested and recorded.
- [ ] Company laptops with disk encryption and screen lock.
7. Vendors
- [ ] A vendor list: every service that stores or processes customer data.
- [ ] Each critical vendor's own SOC 2 report collected, or another form of review recorded.
- [ ] Complementary user entity controls in those reports noted, so you know what the vendor expects you to do.
- [ ] A yearly vendor review scheduled.
8. Risk and incidents
- [ ] A risk assessment completed and dated, with owners for each risk.
- [ ] The incident response plan tested at least once, for example as a tabletop exercise.
- [ ] A way for customers and staff to report a security issue.
9. Evidence
Evidence is what the auditor actually tests. Collect it as you go, not the week before fieldwork.
- [ ] A screenshot or export for every control, dated.
- [ ] Evidence labeled and mapped to the criteria it supports.
- [ ] For a Type 2, recurring evidence (access reviews, training, vulnerability fixes) scheduled across the whole observation period.
- [ ] One place where all of it lives.
For the full list of what auditors usually ask for, see the SOC 2 evidence checklist.
10. The audit
- [ ] Choose an independent, licensed CPA firm.
- [ ] Agree scope, report type and dates in writing.
- [ ] Prepare the management assertion and the final system description.
- [ ] Share evidence in the format the firm asks for.
- [ ] Answer follow-up questions quickly during fieldwork.
- [ ] Review the draft report before it is issued.
How cybersoftware covers this checklist
Most of this checklist is repeatable work, which is what software is for. cybersoftware turns your answers into a gap list, writes policies from your actual setup, collects evidence from the tools you already run, maps it to the criteria and builds the package for the auditor.
It is one plan: $199 a month, cancel any time, or $2,189 a year, which is one month free. Audits come with access to our preferred pricing program: the best negotiated audit rates on the market, because we negotiate on your behalf. The software does most of the work, so the independent CPA firm verifies evidence that arrives prepared. The full list is on our pricing page. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Frequently asked questions
Is this SOC 2 checklist enough to pass?
It covers the areas most small cloud-based teams need for Security. Your auditor sets the final list based on your scope and system.
Which items take longest?
Anything recurring, like access reviews and training, because a Type 2 needs records across the whole period. Start those early.
Do we need every policy on the list?
Most first reports include policies in each of these areas. You can combine them into fewer documents as long as each topic is covered.
Can a two person startup use this SOC 2 checklist?
Yes. Some items get simpler at that size, such as access reviews, but none of them go away.
Start with a free readiness assessment. It takes about fifteen minutes and needs no card.