SOC 2 Compliance Readiness Checklist
All 5 Trust Service Criteria with linked tools for each control
0 / 32 controls complete
Not Started — 0%
Security (CC6)
Protection against unauthorized access, use, or disclosure
TLS/SSL encryption enforced
All traffic uses HTTPS with valid certificates
Use TLS Certificate CheckerSecurity headers configured
HSTS, CSP, X-Frame-Options, X-Content-Type-Options
Use Security Headers AnalyzerAvailability (A1)
System operational and accessible as committed
Uptime monitoring
Automated alerts for service disruption
Incident response plan
Documented procedures for outages
Backup and recovery
Tested backup procedures with RTO/RPO
Capacity planning
Monitoring and alerting for resource limits
Disaster recovery plan
Documented DR with regular testing
Processing Integrity (PI1)
System processing is complete, valid, accurate, and authorized
Error handling
Graceful errors without data leakage
Audit logging
All processing logged with timestamps
Change management
Documented approval process for changes
Confidentiality (C1)
Information designated as confidential is protected
Data classification policy
Documents labeled by sensitivity level
Access controls
Role-based access to confidential data
Data retention policy
Defined retention and deletion schedule
NDAs with sub-processors
Contractual confidentiality obligations
Privacy (P1)
Personal information is collected, used, and disclosed in accordance with commitments
Privacy policy published
Clear notice about data collection and use
Consent mechanism
Opt-in/opt-out for data processing
Data subject rights
Process for access, correction, deletion
Data minimization
Only collect data necessary for purpose
Third-party data sharing
Documented sub-processor list
About the Soc2 Checklist
SOC 2 (System and Organization Controls 2) is the auditing framework used by service organizations to demonstrate how they handle customer data. It covers five Trust Service Criteria: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy (optional). Most B2B SaaS companies need SOC 2 Type II to close enterprise deals.
This interactive checklist breaks down each criterion into specific, actionable controls. Where possible, it links directly to free tools on this site that help you implement or verify the control. Track your progress as you complete items — the grade updates in real time (A = audit ready).
How to use
- Start with the Security criterion (CC6) — it is required for all SOC 2 audits.
- Check off each control you have implemented.
- Click the linked tools to verify controls (e.g., use the Security Headers Analyzer for CC6.1).
- Work through Availability, Processing Integrity, Confidentiality, and Privacy.
- Aim for 90%+ completion before scheduling your audit.
Frequently Asked Questions
What is the difference between SOC 2 Type I and Type II? ▾
Type I audits the design of controls at a point in time. Type II audits the operating effectiveness of controls over a period (typically 3-12 months). Type II is more valuable and takes longer because it requires evidence of consistent operation.
Which Trust Service Criteria are required? ▾
Security (CC6) is always required. Availability, Processing Integrity, Confidentiality, and Privacy are optional — most SaaS companies include Availability and Confidentiality. The checklist above covers all five.
How long does SOC 2 compliance take? ▾
For a typical startup with cloud infrastructure: 3-6 months for Type I, 6-12 months for Type II. The Readiness Checklist above gives you an honest assessment of where you are today.
Can I use these tools as audit evidence? ▾
Yes — screenshots and output from these tools serve as evidence of control verification. For example, Security Headers Analyzer results demonstrate CC6.1 compliance, and the TLS Checker output documents encryption in transit.
Is this tool free to use? ▾
Yes! This tool is 100% free. No signup, no credit card, no limits. It's part of Formatho's privacy-first developer toolkit.
Is my data safe? Does this tool send data to a server? ▾
Absolutely. This tool runs entirely in your browser. Your data never leaves your device. Zero server-side processing, zero tracking.