A free SOC 2 risk register template with real rows

A blank grid teaches nothing, so this one comes with six rows already written. Copy the columns, replace the rows, keep it current.

Here is a SOC 2 risk register template you can copy for free, with the rows already filled in. Every risk sits on one line with a score, one owner, a decision, and the control that deals with it. Swap our six sample rows for your own and you have a working register.

Why SOC 2 wants this table

The 2017 Trust Services Criteria carry the COSO framework into the common criteria, and a block of them is about risk.1 CC3.1 wants objectives clear enough to attach risks to. CC3.2 wants risks identified and analyzed as the basis for deciding how to manage them. CC3.3 asks you to think about fraud on purpose. CC3.4 wants significant changes reassessed, and CC9.1 covers planning for business disruption.

Read CC3.2 twice. It is about decisions. A register with scores but no treatment column does not meet it.

The columns

Ten columns carry the load. The owner and the control link matter most, because those two turn a list of worries into something someone does and something an auditor can check.

ColumnContentsWhy keep it
IDR-01 and up, never recycledControls and evidence point back to it
RiskOne sentence: what could happen, to what“Access” is a topic, not a risk
CategoryAccess, change, vendor, people, fraud, continuityShows you which area has no rows
OwnerA single personA team owner means nobody acts
L and ILikelihood and impact, one to five eachKept apart so people can argue each one
ScoreL times ISets the order of work
TreatmentMitigate, transfer, avoid or acceptThe decision CC3.2 asks for
Control and evidenceYour control ID and where its proof livesMakes the row testable
Residual scoreScore after treatmentShows the work changed something
DatesFound, last reviewed, next reviewProves the register is alive

Six sample rows for a small SaaS team

These are written for a fifteen person company on Google Cloud. They are concrete on purpose, because “unauthorized access” as a row tells you nothing about what to fix. L is likelihood and I is impact.

IDRiskOwnerLIScoreTreatmentControl
R-01A leaver keeps cloud and code access because offboarding is informalCTO3515MitigateAC-03, offboarding checklist
R-02The cloud organization admin account has no hardware key and a shared passwordPlatform lead2510MitigateAC-01, MFA enforcement report
R-03Engineers can merge their own changes to main without reviewCTO4312MitigateCM-01, branch protection export
R-04Database backups run nightly and no restore has ever been triedPlatform lead2510MitigateBC-02, quarterly restore test
R-05One finance user can both issue credits and change the invoice they apply toCEO248MitigateFR-01, monthly credit report sign off
R-06The support chat vendor stores customer emails and has no SOC 2 reportHead of support339Accept (CEO, revisit at renewal)VM-02, acceptance memo

R-05 is the fraud row CC3.3 asks you to think about. R-04 still belongs here under a Security only scope, since recovering from a security event is part of the common criteria, though how deeply it is tested depends on scope. The scoping tool helps with that choice.

A scale anyone can reuse

One to five for likelihood, one to five for impact, multiply. A three point scale is just as valid. What matters is a written meaning for each number, so the same four means the same thing in January and in June. Skip weighted asset models and loss formulas. At fifteen people they produce numbers nobody can explain six months later, and the time is better spent fixing R-01.

Four ways to treat a risk

Every row ends in one of four decisions. “Still looking into it” is not one of them, and a row left there has no treatment.

Mitigate
Add or tighten a control and point the row at it. Five of the six rows above.
Transfer
Shift the cost to someone else through insurance or a contract. The event can still happen.
Avoid
Stop the activity: drop the vendor, the feature or the data you did not need.
Accept
Carry the risk knowingly. This is the only treatment that needs a signature from someone with authority, a date, and a date to look again. The person who found the risk does not sign. On a small team that is a founder or officer, as SOC 2 for a small team explains.

When to review it

Yearly at minimum, quarterly if you ship often. Under CC3.4, a big change triggers a review whatever the calendar says: a new critical vendor, a first enterprise deal, an incident, a new region.1 For a Type 2, check the dates. A review finished before your window opened is a good habit but not evidence for that window.2 The shortest window is a 3-month observation window, so plan at least one review inside it.

Link every row to proof

Test your register with one walk. Pick a row, open the control it names, then open the evidence that control produced. If any step fails, the row is a claim, not a control. Use your own control IDs, not criterion numbers: CC6.2 is a criterion, AC-03 is something you run. Most of that evidence also appears on the PBC list, and the matching documents are in the SOC 2 policy list.

What a risk review costs if you buy one

Filling in this template yourself costs a few hours. Firms that sell professional readiness work publish figures like these for an assessment:

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

The cybersoftware readiness assessment is free: readiness assessment, score, gap list and one AI sample policy. Take the free readiness assessment in about 15 minutes. If you want the register kept for you, the software generates it and tracks reviews at $199 a month, cancel any time. All options are on pricing.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What is a risk register in SOC 2?
A single table of the risks your company has found. Each one has a likelihood and impact score, an owner, a decision about what to do, and a link to the control that handles it. The common criteria ask you to identify and analyze risks and decide how to respond, and this table is the written record of that.
Which columns should the register have?
An ID that is never reused, a one line risk, a category, one named owner, likelihood, impact, the score, the treatment, the control that handles it, where the evidence lives, the score after treatment, and the review dates. More columns are optional and add upkeep.
How should risks be scored?
Rate likelihood and impact from one to five and multiply them. A three point scale works too. Write down what each number means so a four means the same thing on every row, and work the highest scores first.
Is it acceptable to accept a risk rather than fix it?
Yes, if it is a deliberate decision. Record who accepted it, their authority to do so, the date, and when it will be looked at again. The person who raised the risk should not be the one who accepts it.
How often must the register be reviewed?
At least once a year, and quarterly is easier to defend if you ship often. Big changes also trigger a review, such as a new key vendor, a first enterprise customer, an incident or a new hosting region. For a Type 2, the review must be dated inside the report period.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.