A practitioner's SOC 2 checklist that runs from scoping to audit, with the Trust Services Criteria folded in so you know exactly which controls each phase covers.
Short version: A SOC 2 project runs through five phases: (1) scope, deciding Type I vs Type II and which Trust Services Criteria apply; (2) gap analysis, comparing your current controls against the criteria; (3) remediate, closing the gaps and standing up missing controls; (4) observe, which for a Type II means running the controls and collecting evidence across the observation window (3-12 months); and (5) audit, where the CPA firm examines your controls and issues the report. The Trust Services Criteria (TSC) are what you are being measured against the whole way through: Security (the Common Criteria) is always required, and Availability, Processing Integrity, Confidentiality, and Privacy are added only if they are relevant to what you do. This checklist walks each phase and folds the criteria in, so you always know which controls the phase is about.
Use the phase checklist below as your working plan, and track it control by control.
| Phase | What you do | Output | Typical duration |
|---|---|---|---|
| 1. Scope | Choose Type I vs II; select applicable TSC; define the system boundary | Scoping decision, system description | 1-2 weeks |
| 2. Gap analysis | Map current controls to the criteria; find what is missing | Gap report / readiness assessment | 2-4 weeks |
| 3. Remediate | Build missing controls, write policies, fix design gaps | Controls in place, policies published | 4-12 weeks |
| 4. Observe (Type II) | Operate controls; collect evidence across the window | Evidence for the full window | 3-12 months |
| 5. Audit | CPA firm tests controls; issues Type I or Type II report | SOC 2 report | 4-8 weeks |
Durations are indicative; the observation window dominates a first Type II. For the full timing picture, see how long does SOC 2 take.
Your SOC 2 is an examination against the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022). This is still the current standard as of 2026 — the 2022 update revised only the points of focus (the interpretive guidance under each criterion); the five criteria themselves are unchanged since 2017. Here is what each category covers and when it applies.
Security is mandatory in every SOC 2. It is expressed through the Common Criteria (CC1-CC9), which every report includes:
If you do nothing else, the CC series is your SOC 2. The other four categories add criteria on top of the Common Criteria.
| Category | When to include it | What it adds |
|---|---|---|
| Availability | You make uptime or SLA commitments | Capacity, backup, disaster recovery, and monitoring criteria |
| Processing Integrity | You process transactions where completeness/accuracy matters (e.g., payments, data pipelines) | Criteria that system processing is complete, valid, accurate, timely, authorized |
| Confidentiality | You handle confidential data beyond personal information (e.g., customer IP, contracts) | Criteria for protecting and disposing of confidential information |
| Privacy | You collect and process personal information | Criteria aligned to notice, choice, collection, use, retention, and disposal of personal data |
The practitioner's rule: add a category only if you can commit to and evidence it. Scoping in Privacy because it looks thorough, then failing to operate its controls, produces exceptions. Most first-time SaaS reports are Security only or Security plus Availability and Confidentiality.
A common mistake: treating the optional categories as a maturity ladder to climb. They are not levels — they are relevance decisions. Include Availability because you sell an SLA, not because omitting it looks weak.
The failure mode is not missing a control — it is missing evidence for a control during the observation window. Teams stand everything up in Phase 3, then quietly let an access review slip in month four, and it surfaces as an exception in the Type II. The fix is to treat evidence as a continuous output, not an audit-week scramble.
Compliance automation platforms built for SOC 2 help here by collecting evidence through integrations and flagging freshness gaps before they become exceptions, and a disciplined calendar with named control owners does the same job by hand. The controls you run for SOC 2 also overlap heavily with NIST SP 800-171, so a working SOC 2 program gives you a head start if you later pursue federal work. That federal program is what Compli.ai runs, inside your own Microsoft 365 tenant.
Work through the phase checklist above to track your controls, see SOC 2 Type I vs Type II to choose your report, or book a demo to see how Compli.ai runs a federal program in your tenant. Budgeting the project? See SOC 2 cost.
A SOC 2 checklist runs through five phases: scope (Type I vs II and which Trust Services Criteria apply), gap analysis (map current controls to the criteria), remediation (build missing controls and policies), observation (operate controls and collect evidence over the window for a Type II), and the audit itself (a CPA firm examines the controls and issues the report).
The Trust Services Criteria are the AICPA's control criteria that SOC 2 is measured against: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security (the Common Criteria) is always required; the other four are included only if they are relevant to your service. The current standard is the 2017 criteria with revised points of focus from 2022.
Yes. Security, expressed as the Common Criteria (CC1 through CC9), is mandatory in every SOC 2 report. The other four categories — Availability, Processing Integrity, Confidentiality, and Privacy — are optional and added only when relevant to what your organization does.
SOC 2 does not prescribe a fixed number of controls. It defines criteria (the Common Criteria plus any optional categories in scope), and you implement whatever controls are needed to meet them. The number of controls varies by organization, scope, and how many Trust Services Criteria categories you include.
Scope the report and criteria, run a gap analysis against the Trust Services Criteria, remediate the gaps, and — for a Type II — operate the controls and collect evidence across the observation window before the CPA firm examines them. The most common preparation failure is letting a control lapse mid-window, which becomes an exception in the report.
Always include Security. Add Availability if you make uptime or SLA commitments, Processing Integrity if transaction accuracy matters, Confidentiality if you handle confidential data beyond personal information, and Privacy if you process personal information. Include a category only if you can commit to and evidence its controls.
Compli.ai runs a defense contractor's NIST SP 800-171 and CMMC program inside its own Microsoft 365 tenant, with evidence tagged to the assessment objectives assessors actually test. Book a demo.