SOC 2 Checklist
CC1 — Control Environment 7 controls
Maintain an organizational chart that shows clear lines of authority and responsibility.
How to verify / fix
Publish a current org chart and role descriptions defining who reports to whom and who owns what. Evidence: the dated org chart and role descriptions; auditors test that authority and accountability are formally assigned (CC1.3).
Assign security and compliance responsibilities to specific, named individuals.
How to verify / fix
Name an accountable owner (e.g., CISO or security lead) and document each person's security duties. Evidence: a responsibility/RACI matrix or charter naming individuals; tests that the entity holds people accountable for internal control (CC1.1, CC1.5).
Maintain an information security policy that leadership approves and reviews annually.
How to verify / fix
Write a top-level infosec policy, have an executive sign it, and re-approve it each year. Evidence: the policy with a leadership approval date and version history showing annual review (CC1.1).
Communicate security policies to all employees.
How to verify / fix
Distribute policies through onboarding and a place staff can find them, with an acknowledgement step. Evidence: acknowledgement records or training-platform logs showing each employee received the policies (CC1.1, CC2.2).
Put a code of conduct or acceptable use policy in place and have employees sign it.
How to verify / fix
Adopt a code of conduct / AUP and require signed acceptance at hire and on update. Evidence: signed acknowledgements for a sample of employees; tests commitment to integrity and ethical values (CC1.1).
Run background checks for employees in sensitive roles.
How to verify / fix
Define which roles require screening and complete checks before granting sensitive access. Evidence: a screening policy plus completion records (dates, not results) for sampled hires; supports competence and integrity (CC1.4).
Include security responsibilities in job descriptions for relevant roles.
How to verify / fix
Add security duties and expectations to job descriptions for roles that handle data or systems. Evidence: sampled job descriptions showing security responsibilities; supports attracting and retaining competent staff (CC1.4).
CC2 — Communication & Information 3 controls
Document and version-control security policies and procedures.
How to verify / fix
Store policies in a system that tracks changes, owners, and approval dates. Evidence: the version history / change log for sampled policies; tests that the entity uses quality information internally (CC2.1, CC2.2).
Give every new hire security awareness training during onboarding.
How to verify / fix
Require security training before or during the first week and track completion. Evidence: training-completion records for a sample of new hires with dates (CC2.2).
Repeat security awareness training at least once a year.
How to verify / fix
Schedule annual refresher training for all staff and chase non-completers. Evidence: a completion report covering the audit period showing all active employees trained (CC2.2).
75 more controls — unlock the full checklist
The full SOC 2 Checklist has 85 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.
Not ready to buy? Try the free Cyber Insurance Readiness Score.