SOC 2 is buyer-driven, so the programme starts with the deal rather than the framework: which customer is asking, and what would they accept instead. Two decisions then set the shape of everything that follows. Scope first: Security is mandatory, and every optional criterion you add is another set of controls to operate and evidence for the whole window. Report type second, because a Type 2 needs an observation period and that fixes the calendar. The AICPA publishes criteria rather than controls, so readiness is scored against a control set mapped to them, whether you build that set yourself or start from a platform library. Only then does software choice matter, judged on whether it carries evidence across the period.
5 pages on SOC 2, in the order the work happens. Jump to the stage you are at, or read straight through.
Decide which criteria belong in your report and whether a Type 1 or a Type 2 answers the customer who is asking.
Map your controls and evidence against the criteria you put in scope and give each open item an owner before the observation window opens.
Judge platforms on whether they carry evidence across the observation period, with pricing and trade-offs stated rather than implied.
These sit under another subject but bear directly on SOC 2.
The free compliance check runs the SOC 2 gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users