SOC 2 Compliance Checklist
A working checklist for teams preparing for a SOC 2 Type II audit, built around the Trust Services Criteria most auditors actually test against. Pair this with our full SOC 2 compliance program for the underlying detail.
Scoping & Governance
- Trust Services Criteria selected (Security is mandatory; Availability, Confidentiality, Processing Integrity, Privacy as applicable)
- System description drafted, covering infrastructure, software, people, and data
- Risk assessment completed and documented, refreshed at least annually
- Named owner for the audit process, with executive sponsorship
Access Control
- MFA enforced on all systems handling customer data
- Access provisioning and deprovisioning follow a documented, auditable process
- Least-privilege access reviewed on a recurring schedule, not ad hoc
- Privileged account activity is logged and reviewed
Change Management & Monitoring
- Code and infrastructure changes go through a documented review and approval process
- Production access is separated from development access
- Continuous vulnerability scanning and penetration testing are in place, with remediation SLAs
- Security incidents are logged, triaged, and tracked to resolution
Vendor & Third-Party Risk
- Subprocessors and vendors with data access are inventoried and risk-assessed
- Vendor SOC 2 reports (or equivalent) are collected and reviewed
- Data processing agreements are in place with all relevant third parties
Evidence Collection
- Evidence is collected continuously throughout the audit period, not reconstructed at the end
- Screenshots, logs, and config exports are timestamped and centrally stored
- Policies (security, access control, incident response, business continuity) are written, approved, and communicated to staff
Where Alastor InfoSec Fits
Alastor Shield automates evidence collection against every item above, mapped directly to Trust Services Criteria, so evidence exists continuously instead of being assembled in a scramble before the audit window opens. Alastor Pulse provides the continuous VAPT coverage auditors increasingly expect in place of a single annual pentest.
Talk to our team about a SOC 2 readiness assessment scored against this checklist.