Scope and fit
Use this checklist to organize preparation before speaking with an independent CPA firm. SOC 2 readiness is implementation work; it is not the examination or a promise of a particular report.
Set the service and criteria
Describe the product, infrastructure, people, data flows, vendors, and customer responsibilities in scope. Discuss which Trust Services Criteria address customer commitments; Security is included, while other criteria depend on the service.
Check operation, not just documentation
For access, change management, risk, incident response, availability, and vendor processes, identify a control owner and inspect representative records. Where the period of operation matters, plan with the CPA rather than assuming a short evidence snapshot is enough.
Close gaps with accountable decisions
Track missing controls, exceptions, remediation owners, and evidence sources. An independent CPA determines examination procedures and conclusions; preparation should never be described as issuance of a SOC 2 report.
Decisions and tradeoffs
Use this table as a working review record. Replace assumptions with evidence from the target environment.
| Decision area | Working guidance |
|---|---|
| Set the service and criteria | Describe the product, infrastructure, people, data flows, vendors, and customer responsibilities in scope. Discuss which Trust Services Criteria address customer commitments; Security is included, while other criteria depend on the service. |
| Check operation, not just documentation | For access, change management, risk, incident response, availability, and vendor processes, identify a control owner and inspect representative records. Where the period of operation matters, plan with the CPA rather than assuming a short evidence snapshot is enough. |
| Close gaps with accountable decisions | Track missing controls, exceptions, remediation owners, and evidence sources. An independent CPA determines examination procedures and conclusions; preparation should never be described as issuance of a SOC 2 report. |
Implementation questions
What should the team decide about set the service and criteria?
Describe the product, infrastructure, people, data flows, vendors, and customer responsibilities in scope. Discuss which Trust Services Criteria address customer commitments; Security is included, while other criteria depend on the service. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about check operation, not just documentation?
For access, change management, risk, incident response, availability, and vendor processes, identify a control owner and inspect representative records. Where the period of operation matters, plan with the CPA rather than assuming a short evidence snapshot is enough. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about close gaps with accountable decisions?
Track missing controls, exceptions, remediation owners, and evidence sources. An independent CPA determines examination procedures and conclusions; preparation should never be described as issuance of a SOC 2 report. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
Plan, build, verify, operate
Set the service and criteria: Describe the product, infrastructure, people, data flows, vendors, and customer responsibilities in scope. Discuss which Trust Services Criteria address customer commitments; Security is included, while other criteria depend on the service. Record the result and the next owner before changing the next boundary.
Check operation, not just documentation: For access, change management, risk, incident response, availability, and vendor processes, identify a control owner and inspect representative records. Where the period of operation matters, plan with the CPA rather than assuming a short evidence snapshot is enough. Record the result and the next owner before changing the next boundary.
Close gaps with accountable decisions: Track missing controls, exceptions, remediation owners, and evidence sources. An independent CPA determines examination procedures and conclusions; preparation should never be described as issuance of a SOC 2 report. Record the result and the next owner before changing the next boundary.
Deployment checks
Turn the page into a reviewable handover by assigning each check to a person and retaining its result.
SOC 2 Readiness Checklist for a SaaS Service: decision 1
Write down the boundary, owner, dependency, and proof required for soc 2 readiness checklist for a saas service before implementation begins.
SOC 2 Readiness Checklist for a SaaS Service: decision 2
Write down the boundary, owner, dependency, and proof required for soc 2 readiness checklist for a saas service before implementation begins.
SOC 2 Readiness Checklist for a SaaS Service: decision 3
Write down the boundary, owner, dependency, and proof required for soc 2 readiness checklist for a saas service before implementation begins.
Handover and ownership
Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.
Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

