Do you have this control or document at all?
Is the policy/procedure written down and approved?
Is there evidence (logs, tickets, signed forms) showing the control runs consistently?
A control that exists but isn’t documented will be flagged. A documented control that doesn’t operate will be flagged worse. The third column — operating with evidence — is where most first-time SOC 2 projects fail.
Time estimate: Work through this checklist with your team in 4–8 hours. Plan another 4–8 weeks to remediate the gaps you find.
How you run, watch, and protect your systems.
How code and configuration changes reach production.
How you identify, assess, and treat risk.
How you detect, respond to, and recover from security incidents.
People are the largest control surface. Auditors will sample heavily.
Auditors heavily scrutinize how you manage third-party risk.
Auditors heavily scrutinize how you manage third-party risk.
If most items are missing or undocumented: you’re in early-stage readiness. Plan 12–20 weeks of work before scheduling your audit.
If most items exist but aren’t documented: you’re in policy and evidence mode. Plan 6–10 weeks of work focused on documentation.
If items are documented but you can’t produce evidence: you’re in evidence operations mode. Plan 8–12 weeks of running the controls before the audit window opens.
Cyber Security Services takes most clients from gap assessment to audit-ready in 8–16 weeks. We bring this checklist, the policy templates, and the audit liaison experience.
Cyber Security Services has guided dozens of organizations through this exact checklist. We bring the methodology, the policy templates, and the auditor relationships.
What you get: – Gap assessment against this checklist – Prioritized remediation roadmap with effort estimates – Pre-built policy templates calibrated to your environment – Direct audit liaison and evidence support
Book a free 30-minute scoping call. We’ll review your environment, your timeline, and your customer requirements — and give you an honest scope and price.