← Strondex

SOC 2 Checklist

Free preview. You're seeing the first 10 of 85 controls. 85 controls mapped to AICPA Trust Services Criteria. Know your audit readiness score.
CC1 — Control Environment 7 controls
HIGH CC1-01 Control Environment

Maintain an organizational chart that shows clear lines of authority and responsibility.

How to verify / fix

Publish a current org chart and role descriptions defining who reports to whom and who owns what. Evidence: the dated org chart and role descriptions; auditors test that authority and accountability are formally assigned (CC1.3).

HIGH CC1-02 Control Environment

Assign security and compliance responsibilities to specific, named individuals.

How to verify / fix

Name an accountable owner (e.g., CISO or security lead) and document each person's security duties. Evidence: a responsibility/RACI matrix or charter naming individuals; tests that the entity holds people accountable for internal control (CC1.1, CC1.5).

MEDIUM CC1-03 Control Environment

Maintain an information security policy that leadership approves and reviews annually.

How to verify / fix

Write a top-level infosec policy, have an executive sign it, and re-approve it each year. Evidence: the policy with a leadership approval date and version history showing annual review (CC1.1).

MEDIUM CC1-04 Control Environment

Communicate security policies to all employees.

How to verify / fix

Distribute policies through onboarding and a place staff can find them, with an acknowledgement step. Evidence: acknowledgement records or training-platform logs showing each employee received the policies (CC1.1, CC2.2).

MEDIUM CC1-05 Control Environment

Put a code of conduct or acceptable use policy in place and have employees sign it.

How to verify / fix

Adopt a code of conduct / AUP and require signed acceptance at hire and on update. Evidence: signed acknowledgements for a sample of employees; tests commitment to integrity and ethical values (CC1.1).

LOW CC1-06 Control Environment

Run background checks for employees in sensitive roles.

How to verify / fix

Define which roles require screening and complete checks before granting sensitive access. Evidence: a screening policy plus completion records (dates, not results) for sampled hires; supports competence and integrity (CC1.4).

LOW CC1-07 Control Environment

Include security responsibilities in job descriptions for relevant roles.

How to verify / fix

Add security duties and expectations to job descriptions for roles that handle data or systems. Evidence: sampled job descriptions showing security responsibilities; supports attracting and retaining competent staff (CC1.4).

CC2 — Communication & Information 3 controls
HIGH CC2-01 Communication

Document and version-control security policies and procedures.

How to verify / fix

Store policies in a system that tracks changes, owners, and approval dates. Evidence: the version history / change log for sampled policies; tests that the entity uses quality information internally (CC2.1, CC2.2).

HIGH CC2-02 Communication

Give every new hire security awareness training during onboarding.

How to verify / fix

Require security training before or during the first week and track completion. Evidence: training-completion records for a sample of new hires with dates (CC2.2).

HIGH CC2-03 Communication

Repeat security awareness training at least once a year.

How to verify / fix

Schedule annual refresher training for all staff and chase non-completers. Evidence: a completion report covering the audit period showing all active employees trained (CC2.2).

75 more controls — unlock the full checklist

The full SOC 2 Checklist has 85 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.

Not ready to buy? Try the free Cyber Insurance Readiness Score.