Managed security and compliance for regulated small businesses — Kansas City metro and nationally · (913) 601-8810
AICPA · Trust Service Criteria · SOC 2

SOC 2 Readiness Checklist — 38 Items

Every control your organization needs before a CPA firm begins the observation period. Trust Service Criteria references. Type I and Type II preparation. Click items to track progress. No email required.

⚠️
Before starting the SOC 2 observation period: Every item on this checklist should be in place before your CPA firm begins the clock. Gaps found during the observation period appear in the audit report — and finding them early is the entire point of this checklist.

Security — Common Criteria CC1–CC2 (Environment & Risk)

0 of 6 complete
Risk assessment conducted and documented
CC3.2
Risk management framework implemented
CC3.3
Board or leadership oversight of security program
CC1.4
Organizational chart and authority matrix current
CC1.2
Security policies reviewed and current
CC5.2
Code of conduct signed by all personnel
CC1.1

Security — CC6 (Logical Access)

0 of 7 complete
Role-based access controls implemented
CC6.1
MFA enforced on all systems in scope
CC6.1
Unique user IDs — no shared credentials
CC6.1
Semi-annual access review documented
CC6.3
Termination access revocation — same-day documented
CC6.2
Privileged access restricted and monitored
CC6.1
Vendor and third-party access reviewed
CC6.6

Security — CC7 (System Operations & Monitoring)

0 of 7 complete
Security monitoring — alerts and review documented
CC7.1
Audit logs enabled on all in-scope systems
CC7.1
Log retention — minimum 6 months
CC7.1
Vulnerability scanning — quarterly minimum
CC7.1
Security incident response plan written
CC7.3
Incident log maintained
CC7.4
Penetration test conducted or scheduled
CC7.1

Security — CC8 (Change Management)

0 of 4 complete
Change management policy written and followed
CC8.1
Code review process for production changes
CC8.1
Change log maintained — all changes documented
CC8.1
Rollback procedures documented
CC8.1

Security — CC9 (Risk Mitigation & Vendor Management)

0 of 4 complete
Vendor risk management program documented
CC9.2
Vendor contracts include security requirements
CC9.2
Critical vendors reviewed annually
CC9.2
Business continuity plan documented and tested
CC9.1

Evidence Collection (Applies to All Criteria)

0 of 10 complete
Evidence collection process configured from day one
All CC
Evidence organized by Trust Service Criteria
All CC
Control owner assigned for each control
All CC
Monthly evidence review process in place
All CC
Workforce security training — completion records
CC2.2
HR onboarding includes security acknowledgment
CC1.1
Equipment inventory maintained and current
CC6.7
Backup and recovery tested and documented
CC9.1
System description document prepared for auditor
All CC
Prior audit findings — management response documented
All CC
BoTech builds your SOC 2 program

Every item on this checklist is addressed by the BoTech Comply or Fortress program. We configure evidence collection from day one so nothing is missed during the observation period.

Comply — $1,100/mo → Fortress — $2,200/mo →
Download this checklist

PDF version of all 38 items with Trust Service Criteria references. Share with your team or use to prepare for your first auditor conversation.

↓ Download PDF

No email address required

Ready to build your SOC 2 program?

BoTech builds SOC 2 programs for Kansas City professional services firms. Contact us to discuss your scope, your timeline, and the right bundle.

Or call (913) 601-8810