SOC 2
SOC 2 Readiness Checklist
Cycore's 70-item SOC 2 diagnostic. Mark what's done, score yourself out of 70, and bring the gaps to your first auditor conversation.
We built this 70-item checklist for teams getting ready for a SOC 2 audit. Work through it with your team and mark what's done. You'll walk into your first auditor conversation with a specific list. It's organized around the AICPA Trust Services Criteria, and it covers the scope, gaps, and owners you settle before you load a GRC platform.
What's inside
Ten sections, 70 items:
- Foundational Decisions (5)
- Policies and Documentation (14)
- Access Controls (9)
- Infrastructure and Network Security (9)
- Change Management (6)
- Monitoring and Incident Response (6)
- HR and Security Awareness (5)
- Vendor and Third-Party Management (5)
- Business Continuity and Disaster Recovery (5)
- Evidence Collection and Audit Prep (6)
Every item carries one of three labels, so you can tell what comes from the criteria and what's our advice: TSC-aligned diagnostic, Cycore recommended practice, or Scope-dependent.
How to use it
Tick each item that's done, add up each section, and total your score out of 70. The score is a planning number. It doesn't predict how the audit will go. Then give every open item an owner and a date, and take the list to your auditor so scope and evidence get settled early. If you're not sure where to begin, policies and access controls are where we'd start.
proof of work
Cocoon's result
Cycore reports that Cocoon reached SOC 2 Type 2 compliance within three weeks and saved an estimated 30 hours of internal work.
Read the case study