---
title: "SOC 2 Compliance Checklist"
description: "A practical checklist for SOC 2 Type II readiness — security, availability, and confidentiality controls, evidence collection, and audit preparation."
keywords:
  - SOC 2 checklist
  - SOC 2 Type II checklist
  - SOC 2 audit readiness
  - trust services criteria checklist
---

# SOC 2 Compliance Checklist

A working checklist for teams preparing for a SOC 2 Type II audit, built around the Trust Services Criteria most auditors actually test against. Pair this with our full [SOC 2 compliance program](/compliance/soc-2) for the underlying detail.

## Scoping & Governance

- [ ] Trust Services Criteria selected (Security is mandatory; Availability, Confidentiality, Processing Integrity, Privacy as applicable)
- [ ] System description drafted, covering infrastructure, software, people, and data
- [ ] Risk assessment completed and documented, refreshed at least annually
- [ ] Named owner for the audit process, with executive sponsorship

## Access Control

- [ ] MFA enforced on all systems handling customer data
- [ ] Access provisioning and deprovisioning follow a documented, auditable process
- [ ] Least-privilege access reviewed on a recurring schedule, not ad hoc
- [ ] Privileged account activity is logged and reviewed

## Change Management & Monitoring

- [ ] Code and infrastructure changes go through a documented review and approval process
- [ ] Production access is separated from development access
- [ ] Continuous vulnerability scanning and penetration testing are in place, with remediation SLAs
- [ ] Security incidents are logged, triaged, and tracked to resolution

## Vendor & Third-Party Risk

- [ ] Subprocessors and vendors with data access are inventoried and risk-assessed
- [ ] Vendor SOC 2 reports (or equivalent) are collected and reviewed
- [ ] Data processing agreements are in place with all relevant third parties

## Evidence Collection

- [ ] Evidence is collected continuously throughout the audit period, not reconstructed at the end
- [ ] Screenshots, logs, and config exports are timestamped and centrally stored
- [ ] Policies (security, access control, incident response, business continuity) are written, approved, and communicated to staff

## Where Alastor InfoSec Fits

[Alastor Shield](/products/alastor-shield) automates evidence collection against every item above, mapped directly to Trust Services Criteria, so evidence exists continuously instead of being assembled in a scramble before the audit window opens. [Alastor Pulse](/products/alastor-pulse) provides the continuous VAPT coverage auditors increasingly expect in place of a single annual pentest.

[Talk to our team](/about-us) about a SOC 2 readiness assessment scored against this checklist.
