SOC 2 guide

The SOC 2 audit checklist — phase by phase

A SOC 2 engagement has six phases. Each builds on the last, and the most common reasons audits run late or produce qualified opinions trace back to gaps in the first three. This checklist covers what to do, in order, so nothing gets missed.

Type I: 3–6 months totalType II: 9–18 months totalAnnual renewal: 6–9 months
01

Define scope

2–4 weeks

Scoping determines which systems, services, and Trust Services Criteria are included in the engagement. Getting this wrong costs time later — too broad and evidence collection becomes unmanageable; too narrow and customers may reject the report.

  • Identify which products and infrastructure components are in scope
  • Confirm which Trust Services Criteria apply (Common Criteria is always required)
  • Document your system description — what you do, for whom, and how
  • Define the boundaries: what's explicitly out of scope and why
  • Confirm the observation period start date (Type II only)

Note: The observation period for Type II cannot start before scoping is complete. Starting the clock too early is a common mistake.

02

Gap assessment and remediation

4–12 weeks

A readiness assessment identifies controls that are missing or not yet documented. Gaps discovered during auditor fieldwork are far more disruptive than gaps discovered now — remediation mid-audit often requires re-scoping or a qualified opinion.

  • Map existing controls to the Trust Services Criteria
  • Identify missing controls and assign owners
  • Draft or update policies that are absent or outdated
  • Remediate technical gaps (MFA enforcement, logging, encryption at rest)
  • Document vendor relationships relevant to in-scope services
  • Confirm backup and recovery procedures are tested and documented
03

Select and engage an auditor

2–4 weeks

SOC 2 reports must be issued by a licensed CPA firm. Only firms registered with the AICPA can issue an attestation report under the AT-C 205 standard. Not all CPA firms specialize in IT audits — the quality of fieldwork and report language varies significantly.

  • Confirm the firm is a licensed CPA firm with AT-C 205 capability
  • Request sample reports and references from comparable engagements
  • Agree on observation period dates, fieldwork timing, and report issuance date
  • Sign the engagement letter and confirm fee structure
  • Establish the primary point of contact and communication cadence

Note: Budget 3–4 months for the full Type II cycle after the observation period ends. Auditors have queues; fieldwork doesn't start the day after your period closes.

04

Evidence collection

Ongoing across the observation period

This is the longest and most operationally intensive phase. Evidence must span the full observation period — not just the final weeks. Type II requires recurring collection at defined intervals to demonstrate controls operated consistently, not just at a point in time.

  • Create an evidence request for every control in scope
  • Assign each request to the control owner who can attest to it
  • Collect recurring evidence on schedule: access reviews (quarterly), training completions, log samples
  • Capture timestamped configuration screenshots at the start and end of the period
  • Document every policy in its ratified, effective-dated version
  • Track open requests — follow up on anything overdue before the period closes
  • Confirm all vendor-related controls have supporting documentation (contracts, SOC 2 reports, security questionnaire responses)

Note: Evidence without a clear chain of custody — who attested to it, when, and for which control — is frequently challenged during fieldwork.

05

Auditor fieldwork

4–8 weeks

Fieldwork is the period when the auditor tests your controls and requests additional evidence. Responsiveness here determines whether the engagement stays on schedule. Evidence that was well-organized during collection takes hours to retrieve; evidence that wasn't can take days.

  • Respond to auditor requests within agreed SLAs (typically 2–3 business days)
  • Be prepared to explain control design and operating effectiveness, not just submit files
  • Track open requests and flag anything that may require additional context
  • Review the draft management representation letter carefully — you're attesting to its contents
  • Address any deficiencies or exceptions raised before the report is finalized
06

Report issuance and distribution

2–4 weeks

The final SOC 2 report includes the auditor's opinion, your system description, and the tested controls with results. How you share it is as important as having it.

  • Review the final report for accuracy before it's issued
  • Decide on distribution: NDA-gated, customer portal, or on-request only
  • Add a management response for any exceptions or qualified opinions
  • Share with customers who requested it during procurement
  • Begin planning the next observation period if this is an annual program

Note: A qualified opinion (exceptions noted) is not the end of the world, but having a management response prepared shows customers you're actively remediating.

Phase 4 is where most audits lose time. TracesOn is built for it.

TracesOn gives every control a request, every request an owner, and every owner a single upload link — no account required. Evidence is mapped to framework criteria as it's collected — TracesOn suggests the match, you confirm it — then timestamped at submission and kept in an append-only audit room. When the auditor asks for something, it takes seconds to find.