Start with scope
If you cannot name the product, cloud accounts, and people in the report, the rest of the list will sprawl.
Practical preparation for small SaaS teams
A practical, interactive checklist for small SaaS teams preparing for SOC 2.
Track your progress across scope, policies, access, people, vendors, security, evidence and audit preparation.
Free · Interactive · No account required
50 preparation tasks. This is not the official AICPA checklist, not a list of every SOC 2 requirement, and not an audit opinion. Exact work depends on scope, Trust Services Criteria, your controls and systems, and the independent auditor's examination.
Checklist progress
Track preparation work on this device. This is not a compliance percentage and not an audit result.
0 / 50 completed
0%
Checking boxes is useful. Understanding your gaps is better.
The free AuditBird readiness assessment looks at your current practices and highlights areas that may need attention.
Check your SOC 2 readinessNeed a starting point? Browse free SOC 2 policy templates or check a draft for common gaps.
Having a process is different from being able to demonstrate that the process operated.
A SOC 2 checklist is a way to see remaining preparation work before you spend money on fieldwork. You are organizing owners, documents, habits, and evidence — not collecting a stamp that says you passed.
Work category by category. Check an item only when the practice exists and you could show it. Progress is stored in this browser so you can return without creating an account.
If you cannot name the product, cloud accounts, and people in the report, the rest of the list will sprawl.
Policies that describe a 200-person GRC program you do not run will hurt you in an examination.
A process without a retrievable record is hard to sample. Folders beat screenshots in Slack.
Report type, period, and criteria are decisions for you and a CPA firm — not for this page.
Founder-led teams do not need a 400-row GRC export. You do need named owners, MFA, joiners and leavers, a few honest policies, vendor awareness, and evidence you can find when asked. Skip theater that does not match a five-to-fifty person company.
Type 1 asks whether controls are suitably designed at a point in time. Type 2 also asks whether they operated over a period. The topics on this list still apply; Type 2 simply requires you to keep doing the recurring work and keep dated samples. Ask the buyer which report they will accept before you lock a period.
Think in samples: who reviewed access, who completed training, which vendor packs you read, which changes were approved, which restores you tested, which incidents you closed. Having a process is different from being able to demonstrate that the process operated.
Assign the remaining high-impact gaps, run a readiness pass, and talk to an independent auditor. Completing every box is a preparation milestone. It does not mean you are SOC 2 ready in the sense an auditor uses that phrase, and it is not compliance.
Related: SOC 2 for small SaaS teams, SOC 2 for startups, policy templates, policy checker, SOC 2 readiness assessment, and AI compliance.
It is a working list of preparation tasks — scope, policies, access, people, vendors, operations, evidence, and audit logistics. It helps a small team see remaining work. It is not an official control catalog and not an audit opinion.
AuditBird helps small teams turn compliance work into drafts, evidence tasks, and clear next actions — without standing up a full compliance department.
SOC 2 · ISO 27001 · GDPR · and more