SOC 2

SOC 2 Readiness Checklist

Cycore's 70-item SOC 2 diagnostic. Mark what's done, score yourself out of 70, and bring the gaps to your first auditor conversation.

Download the PDF
PDF, 13 pages, no form

We built this 70-item checklist for teams getting ready for a SOC 2 audit. Work through it with your team and mark what's done. You'll walk into your first auditor conversation with a specific list. It's organized around the AICPA Trust Services Criteria, and it covers the scope, gaps, and owners you settle before you load a GRC platform.

What's inside

Ten sections, 70 items:

  • Foundational Decisions (5)
  • Policies and Documentation (14)
  • Access Controls (9)
  • Infrastructure and Network Security (9)
  • Change Management (6)
  • Monitoring and Incident Response (6)
  • HR and Security Awareness (5)
  • Vendor and Third-Party Management (5)
  • Business Continuity and Disaster Recovery (5)
  • Evidence Collection and Audit Prep (6)

Every item carries one of three labels, so you can tell what comes from the criteria and what's our advice: TSC-aligned diagnostic, Cycore recommended practice, or Scope-dependent.

How to use it

Tick each item that's done, add up each section, and total your score out of 70. The score is a planning number. It doesn't predict how the audit will go. Then give every open item an owner and a date, and take the list to your auditor so scope and evidence get settled early. If you're not sure where to begin, policies and access controls are where we'd start.

Download the PDF
Format
PDF, 13 pages
Last reviewed
September 10, 2026
Form
None

proof of work

Cocoon's result

Cycore reports that Cocoon reached SOC 2 Type 2 compliance within three weeks and saved an estimated 30 hours of internal work.

Read the case study
SOC 2

SOC 2 Readiness Checklist

Cycore's 70-item SOC 2 diagnostic. Mark what's done, score yourself out of 70, and bring the gaps to your first auditor conversation.

Download the PDF

We built this 70-item checklist for teams getting ready for a SOC 2 audit. Work through it with your team and mark what's done. You'll walk into your first auditor conversation with a specific list. It's organized around the AICPA Trust Services Criteria, and it covers the scope, gaps, and owners you settle before you load a GRC platform.

What's inside

Ten sections, 70 items:

  • Foundational Decisions (5)
  • Policies and Documentation (14)
  • Access Controls (9)
  • Infrastructure and Network Security (9)
  • Change Management (6)
  • Monitoring and Incident Response (6)
  • HR and Security Awareness (5)
  • Vendor and Third-Party Management (5)
  • Business Continuity and Disaster Recovery (5)
  • Evidence Collection and Audit Prep (6)

Every item carries one of three labels, so you can tell what comes from the criteria and what's our advice: TSC-aligned diagnostic, Cycore recommended practice, or Scope-dependent.

How to use it

Tick each item that's done, add up each section, and total your score out of 70. The score is a planning number. It doesn't predict how the audit will go. Then give every open item an owner and a date, and take the list to your auditor so scope and evidence get settled early. If you're not sure where to begin, policies and access controls are where we'd start.

SOC 2 framework page

Cocoon's result

Cycore reports that Cocoon reached SOC 2 Type 2 compliance within three weeks and saved an estimated 30 hours of internal work.

Read the case study

More Cycore resources

Next step

Talk to Cycore about your SOC 2 timeline

This checklist is a Cycore diagnostic organized around the AICPA Trust Services Criteria. It is not an AICPA checklist and it is not legal or audit advice. Your auditor determines examination scope, evidence, and conclusions. Completing every item does not guarantee readiness or a particular audit outcome.