The gap register is a live checklist
Each gap from Phase 2 sits in a table inside the task, with its criterion, owner, effort and target date. Retest evidence is attached as a file, and the sponsor sees what is still open without a status meeting.
This free SOC 2 readiness checklist is for whoever has just been told to “get us SOC 2”, usually an engineering, security or operations lead at a SaaS or IT services company with a customer deadline. It runs the readiness project from scoping to the day the observation window opens: report path and categories, system boundary, a gap assessment against the AICPA’s 2017 Trust Services Criteria, remediation, control owners and evidence, choosing a CPA firm and a mock audit. You finish with a signed scope, a closed gap register, a draft system description and a start date your sponsor and auditor have agreed.
A Type 2 report gives a CPA firm’s opinion on whether your controls operated effectively throughout a stated period. A failure inside that period is reported as an exception, and fixing it later does not remove it. Readiness is the work before the clock starts: decide what is being reported on, close the gaps and prove each control produces evidence on demand.
The common mistake is treating the start date as a formality. Once the window is open, a skipped quarterly access review is simply a skipped review. Pushing the start date back costs a month. Starting before the controls are running costs an exception in a report your customers will read.
Work: scoping, gaps, remediation, owners, evidence set-up, mock audit.
Who: an internal lead and an executive sponsor.
Output: a signed scope, a closed gap register and an agreed start date.
Cost of a mistake: time. You move the date.
Work: risk assessment, evidence requests, sampling, testing and reporting.
Who: the service auditor, independent of you.
Output: a report carrying the auditor’s opinion and any exceptions found.
Cost of a mistake: an exception your customers can read.
This checklist stops on the first day of the window. For the categories, typical costs and the controls that run during the audit, read our SOC 2 compliance checklist guide.
Seven phases take a first SOC 2 from a scoping decision to an open observation window. Answers in Phase 1 switch tasks on or off for subservice organisations, extra categories and a Type 1 first report.
The first task carries the scope questions. The category task appears only when categories beyond Security are in scope, and the subservice tasks here and in Phase 4 only when the service relies on one.
Assign this phase to someone who did not build the controls: internal audit, an adviser or the CPA firm under a readiness engagement.
The two Type 1 tasks appear only when the Phase 1 report path is Type 1 first. After this phase, recurring control checklists take over.
SOC 2 is not a regulation. It is an attestation report built on AICPA standards and criteria, and the table maps each readiness decision to its source and to the phase that evidences it. Your auditor’s methodology and your customers’ contracts shape the detail, so treat the table as a starting point, not legal advice.
| Readiness decision | AICPA source | What it means in practice | Evidenced in |
|---|---|---|---|
| Report type and period | SOC 2 Guide (updated as of 15 October 2022); attestation standards AT-C 105 and 205 | Type 1 covers design at a point in time; Type 2 covers design and operating effectiveness over a period | Phases 1 and 7 |
| Categories and criteria | TSP section 100: 2017 Trust Services Criteria (with revised points of focus, 2022) | Security (the common criteria) is always in scope; the other four categories are optional | Phases 1 and 2 |
| Points of focus | TSP section 100 | Illustrations of how a criterion can be met; an assessment of each one is not required | Phase 2 |
| System description | DC section 200: 2018 description criteria (with revised implementation guidance, 2022) | Management describes services, commitments, components, subservice organisations and complementary controls | Phases 1 and 4 |
| Subservice organisations | SOC 2 Guide: carve-out or inclusive method | Carve-out leaves the provider’s controls out of scope but discloses the controls you expect it to operate | Phases 1 and 4 |
| Choice of auditor | State licensing and the AICPA Code of Professional Conduct | Only a licensed CPA firm can issue the report, and it must stay independent of you | Phase 5 |
At the time of review, the 2017 criteria and the 2018 description criteria are still current. The AICPA’s Auditing Standards Board exposed proposed revisions to the core attestation standards in February 2026, with a proposed effective date of 15 June 2029; they are not final. In April and May 2026 the AICPA also published ethics guidance on audit firms’ arrangements with SOC 2 tool providers, and a peer review alert about SOC 2 engagements with identical risk assessments, sample sizes and testing across clients. Neither changes what you must evidence, but both are reasons to ask harder questions in Phase 5. If your window starts in 2027, check the AICPA site for newer criteria first.
Each gap from Phase 2 sits in a table inside the task, with its criterion, owner, effort and target date. Retest evidence is attached as a file, and the sponsor sees what is still open without a status meeting.
Phase 1 answers drive conditional logic, so subservice, extra-category and Type 1 tasks appear only when they apply. Scope sign-off and the go or no-go decision are approvals, recorded with who and when.
Each control goes onto a recurring schedule during readiness, with dynamic due dates and a named assignee. The first quarterly cycle has run before the mock audit, so Phase 6 samples real records.
CheckFlow is not a GRC platform, a CPA firm or an auditor, and it cannot issue or certify a SOC 2 report. It runs the readiness project and the human controls that follow, next to your monitoring tools. CheckFlow for SOC 2 shows how those controls keep running once the window is open.
Each subservice organisation you carve out will send you its own SOC report, and customers will review yours the same way. The SOC Report Review Checklist covers that side of the process.
It is a rehearsal of the audit before the window opens. Someone who did not build the controls walks through each one with its owner, samples evidence as an auditor would and compares the draft system description with what is running. The result is a findings list and a decision on whether the window can start. It is not a report you can give customers.
They sit at opposite ends of the project. A gap assessment comes first: it compares what you do today with the criteria in scope and lists what is missing or unevidenced. A readiness assessment comes last: it tests whether the fixed controls work and produce evidence on demand. This checklist runs them in Phase 2 and Phase 6.
Often, yes, within the AICPA’s independence rules for non-attest services. Your management must make every decision, name a suitably skilled person to oversee the work and accept responsibility for the results. The firm can assess and recommend, but it cannot take on management responsibilities, such as deciding which gaps to fix or running your controls. Some firms keep the two engagements separate, so ask in Phase 5.
Practice and your customers set the length, not a fixed rule. Three months is the shortest period commonly seen and a frequent choice for a first report; 12 months is the usual cadence afterwards. A short first window still has to contain at least one run of every quarterly control. Check what your largest customers accept.
When the readiness assessment says go, not when sales needs it. Every control in scope has run at least once, every owner can produce evidence unaided, populations export for any date range and the draft description matches reality. If any of those is missing, move the date.
No. The Trust Services Criteria do not require any particular tool. Monitoring platforms save time on technical evidence, but people still run access reviews, approve policies and decide scope. If you use one, check that your CPA firm sets its own scope, timing and sampling, and ask about any referral arrangement with the platform.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.