SOC 2 Readiness Checklist
Pragmatic SOC 2 Type II prep checklist before your auditor walks in. CC6, CC7, CC8 broken down with evidence requirements, the 90-day pre-audit timeline, and the six common Type II audit failure patterns. Free, email-only. Source: AICPA.
Preview of the document.
- →CC6 (Logical Access), CC7 (System Operations), CC8 (Change Management) broken down to control-by-control evidence requirements
- →The 10-question CC7.1 sub-checklist — the trust criterion most directly evidenced by pentest results
- →Pentest-at-audit-minus-90, retest-at-audit-minus-30 timing rule explained
- →Six common Type II audit failure patterns and how to avoid each
- →90-day pre-audit timeline laid out week-by-week
CC6.6 — External access restriction
Pentest report with documented external scope. Findings tied to public-facing surface. Auditors mark this control as ineffective if there is no third-party pentest evidence.
CC7.1 — Vulnerability detection
The 10-question sub-checklist. Has a pentest been run within the audit window. Does the report include scope, methodology, severity rubric. Are findings triaged. Have critical / high findings been retested. Is there a retest letter.
Timing rule
Pentest at audit-minus-90 days. Retest at audit-minus-30. Anything later produces an open-findings list at audit-start, which the auditor will flag as ineffective control regardless of finding severity.
Common failure pattern — pentest deliverable is a CSV
If the report is a list of CVE numbers from a scanner with no methodology, no narrative, no retest, the auditor will flag CC7.1 ineffective regardless. Procure a pentest with a written report, not a scan.
90-day pre-audit timeline
T-90 pentest kickoff. T-75 internal access review (CC6.3). T-60 fieldwork complete. T-45 sub-processor inventory refresh. T-30 retest complete. T-30 IR tabletop. T-15 internal walkthrough. T-7 evidence pack assembled. T-0 audit start.
Who this is written for.
Series A/B SaaS preparing for first SOC 2 Type II. Security engineers gathering evidence before the auditor walkthrough. CISOs sequencing pentest + retest against an audit window.
Real public references.
We cite the canonical source so you can verify anything in the document yourself. No fabricated stats, no "industry research says" without a link.
- → AICPA Trust Services Criteria · https://www.aicpa-cima.com/
- → MeitY (DPDP overlap) · https://www.meity.gov.in/
- → AWS Pentest Policy · https://www.aws.amazon.com/security/penetration-testing/
We send the document. That is it.
The SOC 2 Readiness Checklist lands in your inbox the same business day. The request is read by the operator who owns the artefact — not by a marketing system.
No drip after that. No "day-3 nudge", no auto-enrolment in a newsletter, no calendar invite for a discovery call you did not ask for. If you want a 30-minute scoping call, the contact form routes the same way and the call is free.
Want a 30-minute scoping call instead?
The SOC 2 Readiness Checklist is useful as a working document. If you would rather walk through your specific situation with an operator, the call is free and you get a written summary either way.