Compliance

SOC 2 Compliance Checklist: What You Need for Your First Audit

Heading into your first SOC 2? Here's a plain-English checklist of what auditors look for — and how to keep the evidence ready across the observation window.

The Pelta Team8 min readUpdated Part of SOC 2

SOC 2 is the security credential most requested by North American enterprise buyers. It's an attestation, produced by a licensed auditor, against the AICPA Trust Services Criteria. If you're heading into your first SOC 2, this checklist covers what auditors actually look for and how to avoid a last-minute scramble.

1. Choose your scope and criteria

SOC 2 always includes the Security criterion; you optionally add Availability, Processing Integrity, Confidentiality and Privacy based on what matters to your customers.

  • Decide which Trust Services Criteria are in scope.
  • Define the systems, products and locations the report covers.
  • Decide Type I (design at a point in time) or Type II (operating effectiveness over a period).

2. Put the core controls in place

  • Policies and procedures covering security, access, change and incident management.
  • Access control with least privilege, strong authentication and timely de-provisioning.
  • Change management for how code and infrastructure move to production.
  • Monitoring, logging and alerting across your environment.
  • Vendor management for the sub-processors in your supply chain.
  • A tested incident-response process.
For a Type II report, it's not enough that a control exists — it must be shown to operate consistently across the whole observation window, commonly 3 to 12 months.

3. Collect evidence continuously

The teams that struggle with SOC 2 are the ones assembling screenshots the week before the audit. The teams that breeze through it keep evidence linked to controls as they operate. Set that up early and the observation window takes care of itself.

4. Don't do the work twice

SOC 2 overlaps heavily with ISO 27001. If you map controls once and keep a connected evidence trail, the same artefacts satisfy both — turning a second credential into a fraction of the effort. That shared-mapping, one-evidence-source model is exactly how Pelta runs SOC 2 alongside ISO 27001 and other frameworks.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

SOC 2

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding ISO 27001

~65% carried over
Carried over from SOC 2 New work for your team

Auto-completed from your existing program

Access controlRisk assessmentChange managementIncident responseLogging & monitoringVendor management

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

Frequently asked questions

How long does SOC 2 take?+

A Type I can be reached relatively quickly once controls are in place. A Type II covers an observation period — commonly 3 to 12 months — during which controls must operate effectively.

Do I need SOC 2 or ISO 27001?+

It depends on your market. SOC 2 is most requested by US buyers; ISO 27001 is a globally recognised certification. Many companies pursue both, reusing overlapping controls and evidence.

What's the difference between SOC 2 Type I and Type II?+

Type I assesses whether controls are suitably designed at a point in time; Type II assesses whether they operated effectively over a period.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.