The SOC 2 Compliance Checklist
Here is the whole path: scope your trust services criteria, run a gap assessment, write policies that match how you actually operate, implement the controls, build evidence habits, run a readiness review, select an auditor, operate through the observation window if you are pursuing a Type 2, and receive the report. From a reasonable starting point that takes four to nine months and $30,000 to $90,000 all-in for year one. This checklist is written from the auditor's side of the table: BD Emerson performs SOC 2 examinations through its attest arm, BD Emerson CPA, which means the failure points below come from fieldwork, not from theory. Work the phases in order, because each one depends on the one before it.
1. Scope the trust services criteria
Security is mandatory and, for most first-time reports, sufficient. Add Availability or Confidentiality only when customers ask for them by name, because each additional criterion raises audit effort and fee by roughly 10 to 25 percent. Then draw the system boundary: which product, which infrastructure, which people, and which vendors sit inside the report. A tight boundary, one legal entity and one product, is the single biggest cost and sanity lever in the whole program. Write the scope down before anyone builds anything, because scope decided by accident gets discovered during fieldwork, which is the expensive way to decide it.
2. Run a gap assessment
Map what you have against what the criteria require. A compliance automation platform will produce a rough version of this the day you connect it; a consultant-led gap assessment runs $5,000 to $15,000 and adds judgment about which gaps actually matter for your environment. Either way the output is the same: a remediation register with an owner and a date on every line. Companies that skip this step do not actually skip it. They perform it during the audit instead, with the meter running and the follow-up requests multiplying.
3. Write policies that match reality
Auditors read policies, then ask for the evidence the policy implies. A policy library imported from a template that describes a 500-person company with a change advisory board, dropped into a 40-person startup that ships four times a day, creates exceptions out of thin air. Expect twelve to twenty policies for a typical scope: information security, access control, change management, incident response, vendor management, business continuity, data classification, acceptable use, and the rest. Write them to describe what your company actually does, have leadership formally adopt them, and track acceptance for every employee, because personnel who never acknowledged the policy set remain one of the most common findings in first-year audits.
4. Implement the controls
The specific control set is yours to define, but first-year audits are won or lost on a familiar core:
- Single sign-on and MFA on every system in scope
- Role-based access with quarterly access reviews someone actually performs
- Onboarding and offboarding tickets, with offboarding completed inside a defined SLA
- Change management with code review and approval evidence in the repository
- A vendor inventory with security review of the critical ones
- An incident response plan, tested at least annually
- Centralized logging and alerting on the systems that matter
- Tested backups and a recovery exercise you can produce minutes from
- Vulnerability scanning on a cadence, plus a penetration test if customers expect one
None of this is exotic. The failure mode is not missing controls; it is controls that exist on paper and run only in the weeks before fieldwork.
5. Build evidence habits before the window opens
Evidence created at the moment work happens is cheap; evidence reconstructed months later is expensive and looks like exactly what it is. Decide where evidence lives, put timestamps and tickets on routine work, and let an automation platform collect the recurring artifacts: access lists, configuration snapshots, policy acceptance, review sign-offs. The habit matters more than the tooling. An auditor sampling a July access review wants the July review, performed in July by someone who read the list, not a September screenshot with July typed into the filename. This is the phase that decides whether the audit is a confirmation or an excavation.
6. Run a readiness review
Before the audit, have someone independent of the build walk the program the way an auditor will: pick controls, pull samples, follow the evidence trail end to end. This is where you find the offboarding ticket that never closed and the access review one manager rubber-stamped in ninety seconds. Fix findings now, while they are private and free. A readiness review costs a fraction of what mid-audit remediation costs, and it converts fieldwork from archaeology back into confirmation.
7. Select the auditor
Only licensed CPA firms can issue a SOC 2 report. Beyond the license, ask three questions: does the team have security backgrounds or only accounting ones, do they work natively in your automation platform, and will they quote a fixed fee against defined scope. Expect $7,000 to $25,000 for a Type 1 and $12,000 to $45,000 for a Type 2 at startup and mid-market scope, with the drivers detailed in our SOC 2 cost guide, and book two to three months ahead because audit calendars compress hard in the fourth quarter. Since we perform SOC 2 examinations ourselves, read this section as a disclosure as much as advice: these are the same questions you should put to us.
8. Operate through the observation window
A Type 2 report covers a window, usually three months for a first report and twelve thereafter. During the window the job is boring on purpose: run the controls, keep the evidence flowing, and resist re-platforming anything in scope. Exceptions during the window are not fatal; undocumented ones are. If an offboarding runs late or a review slips, record what happened and remediate it, because an auditor who finds a documented exception with remediation writes a very different sentence than one who finds a hole nobody noticed. Companies that need an artifact sooner run a Type 1 first, then let the Type 2 window run behind it.
9. Fieldwork and the report
Fieldwork runs two to eight weeks: evidence requests, sampling, interviews, follow-ups. Your responsiveness drives the timeline more than anything the auditor does, so assign one owner to triage requests daily. The report that emerges contains the opinion, your system description, and the test results, including any exceptions alongside your responses. Distribute it under NDA, and expect your most sophisticated customers to read the testing section closely. Then the cycle restarts, every year, which is why the habits in phase five matter more than any single deliverable in this list.
Where first-year programs actually fail
From the auditor's chair, a handful of findings account for most first-year exceptions. Offboarding that missed a contractor account. Access reviews performed as a signature rather than a review. Policies adopted the week before fieldwork, with acceptance dates to match. Evidence reconstructed after the fact, which sampling exposes quickly. And scope quietly widened by sales promises, so the report describes a smaller system than the one customers were told about. Every one of these is cheaper to fix in month two than in the exceptions section of a report your buyers will read for the next twelve months.
Where BD Emerson fits
Our SOC 2 practice runs readiness and remediation for companies being audited elsewhere, and our attest arm performs SOC 2 Type 2 examinations at fixed fees for companies that arrive ready, never both for the same client, because independence rules exist to keep your report worth reading. Use the checklist either way. The companies that get through this in four months instead of nine are not smarter; they decided scope early, made evidence a habit, and treated the auditor as a deadline rather than a surprise.
