
The problem: SOC 2 has no official checklist. The AICPA built it around principles, not a fill-in-the-blank form, which leaves security and compliance teams guessing at what "audit-ready" actually looks like.
In a 2025 Vanta survey of 2,500 leaders across the US, UK, and Australia, 65% said customers, investors, and suppliers now demand proof of compliance before they'll do business with you, part of a broader shift toward automated vendor risk review. Vanta's 2025 State of Trust research confirms what most vendor managers already feel: the scrutiny isn't slowing down.
This guide breaks that ambiguity into a working checklist. We'll cover the Trust Services Criteria, how to pick between Type I and Type II, and what it actually takes to stay compliant after the auditor leaves.
Key Takeaways
- Security is the only mandatory Trust Services Criteria; the other four get scoped to your actual services
- SOC 2 compliance is a process (scoping, gap analysis, controls, evidence, audit), not a one-time document
- Type I checks control design at one moment; Type II tests operating effectiveness over 3 to 12 months
- SOC 2 isn't legally required, but it's become a commercial necessity for enterprise and SaaS sales
- Most compliance programs fail at Type II renewal, not the first audit, due to weak evidence-collection habits
The 5 Trust Services Criteria: The Foundation of Every SOC 2 Checklist
Every SOC 2 report is built on the AICPA's Trust Services Criteria (TSC). Security is the only category that's mandatory in every single report. The other four get scoped in based on what your customers actually need to see.
| Criterion | What it protects | When you need it |
|---|---|---|
| Security (Common Criteria) | Systems and data from unauthorized access | Always required in every SOC 2 report |
| Availability | System uptime and disaster recovery | You have uptime SLAs or promise system availability |
| Processing Integrity | Accuracy, completeness, and timing of data processing | You process, transform, or calculate data for customers |
| Confidentiality | Business-sensitive info (contracts, IP), not personal data | You handle client trade secrets or proprietary business info |
| Privacy | Collection, use, retention, and disposal of personal information | You collect personal data directly from consumers |
Security controls cover the basics most teams already have some version of:
- Access management, defining who can touch which systems and data
- Network segmentation, isolating critical systems from the broader network
- A documented incident response plan, tested rather than left in a drawer
Availability matters if you're promising 99.9% uptime in a contract: auditors will want to see capacity planning and actual disaster recovery test results, not just a plan sitting in a drawer.
Privacy is the criterion teams overspend on scoping. It's less common than most people assume. In a benchmark review of 73 SOC 2 reports, CBIZ found Privacy included in only 6.8% of examinations, compared to 100% for Security and 75.3% for Availability. Add Privacy because your actual data practices demand it, not because it feels safer to include everything.

The Complete SOC 2 Compliance Requirements Checklist for 2026
Here's the working process. Treat it as a cycle, not a one-time task list.
Define your audit scope. Identify which Trust Services Criteria apply based on your services and what customers expect in the report. Document why you're excluding any criteria — auditors and buyers both ask.
Run a readiness assessment. Compare your existing controls against the TSC points of focus before you bring in a formal auditor. This is where most teams discover gaps in policy documentation, access reviews, or vendor management they didn't know existed.
Implement missing controls and write the policies down. Build out access management, encryption, vendor risk management, change management, and incident response, then formalize each into a written policy with a named control owner. Verbal understanding doesn't count as evidence.
Establish an evidence collection cadence. Decide how often each control gets tested (monthly, quarterly, annually) and start collecting evidence on that schedule. Scrambling for six months of screenshots the week before fieldwork is the single most common self-inflicted wound in SOC 2 prep.
Validate your controls internally and pick your report type. Test controls against the evidence you've gathered, fix what fails, then decide between Type I and Type II based on sales timeline pressure and how mature your evidence process actually is.
Engage a licensed CPA firm and complete the audit. Submit evidence, walk through auditor testing, and treat the resulting report as day one of a continuous cycle, not a finish line. Quarterly reviews and an annual risk reassessment keep you from starting over every year.

SOC 2 Type 1 vs. Type 2: Choosing the Right Report for Your 2026 Goals
Buyers rarely ask "do you have SOC 2?" anymore. They ask which type, and that distinction changes your timeline dramatically.
| Type I | Type II | |
|---|---|---|
| What it tests | Control design at a single point in time | Design plus operating effectiveness over a period |
| Observation window | None — a snapshot | Typically 3 to 12 months |
| Speed to first report | Faster | Slower |
| Enterprise procurement preference | Rarely sufficient alone | Usually the requested standard |
When scope stays the same between engagements, Type II tests the operating effectiveness of the same controls Type I already assessed for design. This builds on the same foundation as Type I, rather than repeating the original criteria list from scratch.
Our recommendation:
- Start with Type I if you need to unblock a stalled deal fast. It proves your controls exist and are designed correctly, buying you credibility while you build evidence-collection habits.
- Move to Type II once quarterly evidence reviews feel routine instead of urgent. Enterprise buyers typically expect it as the next step.
Turning Your SOC 2 Checklist Into Audit-Ready Team Capability
Here's the part nobody warns you about: most SOC 2 failures don't happen on the first audit. They happen at Type II renewal, when the auditor asks for six months of consistent evidence and the team realizes the checklist got completed once but never became a habit.
This is a capability gap: teams pass the first audit on adrenaline and good intentions, then can't reproduce the same evidence trail a year later because nobody owns the process day to day.
This is the same gap QMS Learning was built to close, just in aerospace and defense first. Its Defense Cybersecurity Readiness pathway, covering CMMC, NIST 800-171, ISO 27001, and SOC 2, pairs role-specific training with an AI Workbench that flags control gaps and a Document Management System built for exactly this kind of evidence problem:
- Revision control keeps one live version of every policy, so there's never a question about which copy an auditor should be reading
- Append-only revision history proves a control was in place, or formally changed, throughout the observation window Type II auditors care about most
- Acknowledgment logging timestamps who read and understood each policy, replacing scattered email sign-offs with real proof of competence
- Clause mapping ties each document to the specific Trust Services Criteria it satisfies, so gaps surface before an auditor finds them
- Audit-evidence package export compiles documents, revisions, and acknowledgments into one indexed file on demand, instead of assembled by hand the night before fieldwork

The pathway's SOC 2 course is opening as a pilot cohort in Q3 2026, alongside CMMC, NIST 800-171, and ISO 27001 content. Early buyers join as design partners, shaping the curriculum before pricing locks.
The document management infrastructure behind it is already live today, built on the same architecture QMS Learning uses in its Aerospace & Defense Audit-Ready pathway. Clients like S3 AeroDefense and LG Machine have relied on the same root-cause and audit-discipline training model for AS9100D programs.
That combination, role-based training paired with embedded evidence tooling, is the transferable piece behind every pathway QMS Learning builds.
Frequently Asked Questions
What is a SOC 2 Type 2 compliance checklist?
A Type II checklist covers the same Trust Services Criteria-based controls as Type I. It also requires evidence collected over a monitoring period, typically 3 to 12 months, proving those controls actually operated as designed rather than simply existed.
Is SOC 2 a legal requirement?
No. SOC 2 is a voluntary AICPA standard, not a law. It's become a de facto business requirement, though, since most enterprise and SaaS buyers won't sign a contract without one.
How long does it take to become SOC 2 compliant in 2026?
Type I generally takes about 3 to 6 months end-to-end. Type II runs longer, roughly 6 to 15 months, since it requires an observation period on top of preparation and fieldwork.
Who can perform a SOC 2 audit?
Only a licensed, independent CPA or CPA firm can conduct and issue a SOC 2 report. No other consultant or vendor is authorized to sign one.
What's the difference between SOC 2 and ISO 27001?
SOC 2 is a flexible attestation report common in US procurement, built around your chosen Trust Services Criteria. ISO 27001 is an internationally recognized certification with a more prescriptive information security management system structure.
How much does a SOC 2 audit cost?
Costs vary by report type and company size. Drata's 2026 estimates put Type I audit fees around $7,500 to $15,000 for smaller companies, with Type II running $12,000 to over $100,000 for larger, more complex organizations.


