Before engaging an auditor, make sure your controls, policies, and evidence are in order. A practical checklist for organizations preparing for SOC 2 Type I or Type II.
SOC 2 audits fail — or get delayed — when organizations engage an auditor before their controls, documentation, and evidence collection processes are ready. The most common outcome is a qualified opinion, a delayed report, or an audit window that has to restart — all of which cost more time and money than the readiness work would have.
This checklist is designed to help you identify gaps before the audit window opens, so you can address them on your timeline rather than the auditor's. It covers the areas most commonly cited in SOC 2 readiness gaps across growing companies. For a broader view of Paragon Advisory's approach, see our SOC 2 Readiness services.
Type I vs. Type II: A SOC 2 Type I report assesses whether controls are suitably designed at a point in time. A Type II report assesses whether controls operated effectively over a period — typically 6 to 12 months. Most customers and enterprise prospects require Type II. Plan your audit window accordingly.
01Scope & Audit Preparation
Define the systems, services, and data in scope for the audit
Identify the applicable Trust Services Criteria (Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional)
Document the scope boundary in writing and obtain executive sign-off
Identify all third-party subservice organizations in scope
Select a licensed CPA firm with SOC 2 experience
Determine whether you are pursuing Type I (point-in-time) or Type II (period of time)
02Policies & Documentation
Information security policy reviewed and approved within the last 12 months
Acceptable use policy in place and acknowledged by all employees
Access control policy documented and enforced
Incident response plan documented, tested, and assigned to an owner
Change management policy and procedures documented
Business continuity and disaster recovery plan documented
03Access Controls
Unique user accounts for all employees — no shared credentials
Multi-factor authentication (MFA) enforced for all systems in scope
Privileged access limited to those with a documented business need
Access reviews conducted at least quarterly for privileged accounts
Offboarding process terminates access within 24 hours of separation
Role-based access control (RBAC) implemented for in-scope systems
04Risk Management
Formal risk assessment completed within the last 12 months
Risk register maintained with owners, ratings, and remediation status
Vulnerability scanning conducted at least quarterly
Penetration test completed within the last 12 months (required for Type II)
Findings from assessments tracked to remediation
05Monitoring & Logging
Centralized logging in place for in-scope systems
Log retention meets the audit period requirements (minimum 12 months for Type II)
Alerts configured for unauthorized access attempts and anomalous activity
Security monitoring reviewed on a defined cadence
Uptime and availability monitoring in place if Availability TSC is in scope
06Vendor & Third-Party Management
Inventory of all third-party vendors with access to in-scope systems
Vendor risk assessments completed for critical subservice organizations
Contracts include security and data protection requirements
SOC 2 reports (or equivalent) obtained from key subservice organizations
07Evidence Readiness
Evidence collection process defined and assigned to an owner
Screenshots, exports, and logs organized by control
Evidence covers the full audit period (for Type II)
Exceptions and compensating controls documented with rationale
Internal audit or readiness assessment completed before engaging the auditor
Common Gaps That Delay SOC 2 Audits
MFA not enforced on all in-scope systems — especially email and cloud infrastructure
Access reviews not documented or conducted on a regular cadence
Policies exist but have not been reviewed, approved, or communicated to employees
Logging gaps — some systems not captured in the centralized log aggregator
Vendor inventory incomplete — shadow IT and unmanaged SaaS tools not accounted for
No formal risk assessment on record — or one that predates the audit period
Penetration test not completed or findings not remediated before the audit window
What to Do After the Checklist
Once you have worked through this checklist, you should have a clear picture of where your gaps are. The next step is to prioritize remediation based on audit risk — controls that are completely absent carry more risk than controls that exist but need documentation.
If you are pursuing SOC 2 because customers are asking about it, consider whether your executive security reporting is ready to support the conversation before the report is issued. Customers often ask for a summary of your security program before a formal audit is complete.
If you are unsure how to prioritize or want an outside perspective on your readiness posture, a SOC 2 readiness engagement with Paragon Advisory can help you close gaps efficiently and enter the audit window with confidence.
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
A SOC 2 Type I report assesses whether controls are suitably designed at a point in time. A Type II report assesses whether controls operated effectively over a period — typically 6 to 12 months. Most enterprise customers require Type II. Plan your audit window accordingly.
How long does it take to prepare for a SOC 2 audit?
Organizations with mature security programs may be ready for a Type I audit in 3–6 months. Type II requires a minimum observation period of 6 months. Organizations starting from a low baseline should plan for 9–18 months total.
What are the most common reasons SOC 2 audits fail or get delayed?
Common issues include MFA not enforced on all in-scope systems, access reviews not documented, policies not reviewed or communicated to employees, logging gaps, incomplete vendor inventory, and no formal risk assessment on record.
Do I need a penetration test for SOC 2?
A penetration test is not explicitly required by SOC 2, but most auditors expect evidence of vulnerability management and risk assessment. For Type II audits, a penetration test completed within the audit period is strongly recommended.
Which Trust Services Criteria do I need?
Security (CC criteria) is mandatory for all SOC 2 reports. Availability, Confidentiality, Processing Integrity, and Privacy are optional and should be included based on what your customers care about and what your service commitments include.