SOC 2 checklist
The TSC 2017 trust services mapped to fieldwork week.
The five trust services criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) — with the 2022 points-of-focus update the AICPA published — and the evidence each criterion demands. The full control walk-through and the pre-assembled evidence package format the auditor signs off on are written up in the long-form checklist.
Security · Availability · Confidentiality
What “SOC 2-ready” looks like
A working SOC 2 program at the Tier 2 Multi-framework level pairs the Common Criteria (the Security baseline every audit pulls on) with one or more of Availability, Confidentiality, or Processing Integrity — plus the descriptions of the system, the subservice-carrier roster, and the exception register the auditor requests before fieldwork opens.
The full checklist — the 60 controls, the points-of-focus update, and the evidence-package format prefilled with HIPAA-control overlap — is being written up against the founder’s first reviewer round. For now, the hub at /resources indexes all four framework checklists; SOC 2 ships at the $8K Multi-framework tier.
More frameworks
See all checklists →HIPAA, SOC 2, PCI DSS, GDPR — pick by the framework your auditor opens on first.