85 controls · 11 categories

SOC 2 Checklist

SOC 2 audits fail on missing evidence, not missing intentions. This workbook maps 85 controls to all of the AICPA Trust Services Criteria, Control Environment through Confidentiality, so you can score your readiness, close gaps, and walk into your audit with the evidence already organized.

See exactly what you're buying before you pay, no email, no account. One-time purchase · instant download · 85 controls with verification & remediation steps.

What's inside

85 controls across 11 categories

Every control is plain-language, prioritized by severity, and paired with how to verify it and how to fix it. Organized into 11 sections.

Access Control13
Operations11
Change Management8
Control Environment7
Risk Assessment7
Risk Mitigation7
Availability7
Confidentiality7
Communication6
Monitoring6
Control Activities6

Real sample controls

A look at the highest-severity controls

These are taken directly from the checklist, no paraphrasing.

  • CC3-01CRITICALRisk Assessment

    Run a formal, documented risk assessment process.

  • CC6-01CRITICALAccess Control

    Require approval before any access is granted (formal access provisioning).

  • CC6-02CRITICALAccess Control

    Enforce MFA for all remote access to production systems.

  • CC6-03CRITICALAccess Control

    Limit privileged/admin access to personnel with a clear business need.

SOC 2 Checklist

$197one-time
  • 85 prioritized controls
  • Verify & fix steps for each control
  • 11 categories across 11 sections
  • Instant download · lifetime access

Upgrade to the Complete Bundle, save $285

Get all 6 checklists for $497 ($782 bought separately).

Add the bundle instead ›
Get the checklist ›

By purchasing you agree to our Terms. Digital products are non-refundable once accessed.

See it first, free

Preview the checklist before you pay

Open the first 10 controls in your browser, real, unredacted, exactly as they appear in the checklist. No login, no email, no card. See precisely what you're buying before you spend a cent.

Why teams buy with confidence

  • Instant access

    Pay and the download link lands in your inbox immediately, no waiting, no sales call.

  • Lifetime updates

    Frameworks change. When the controls do, you get the updated version at no extra cost.

  • Built by practitioners

    Controls drawn from CIS benchmarks, framework requirements, and real assessment findings.

  • Secure checkout

    Payment is processed by Stripe. We never see or store your card details.

Jason Dobbs, founder of Strondex

Built by practitioners, not a content mill

Built by Jason Dobbs, a technology leader and cybersecurity strategist with more than two decades of experience hardening Microsoft 365, Azure, and AWS for small and mid-sized businesses across regulated industries, healthcare, finance, law, real estate, energy, and the public sector. These controls are drawn from real assessments and the security questions cyber insurers actually ask.

Secured by StripeMapped to SOC 2AICPA Trust Services CriteriaNo subscription · no upsell

We'll always make it right.

If a checklist isn't what you needed, email us, we'll get you to the right one or find a resolution that works.

Exactly 85 controls, no inflated counts. One-time purchase · digital product · non-refundable once accessed.

“Before we worked with Strondex, SOC 2 felt like a moving target. Jason simplified the entire process. His team performed a thorough assessment, developed clear action plans, helped us implement the controls, and made sure we had the evidence the audit required. They were responsive at every step. We completed our SOC 2 audit successfully and came away with a much stronger understanding of security governance.”
Rebecca · Divisional Head of Operations, SOC 2 Compliance
“We engaged Strondex to prepare for a PCI DSS assessment and expected guidance. What we received was a true partnership. Jason and his team helped us close longstanding compliance gaps, improve our documentation, validate technical controls, and prepare our staff for the auditor’s questions. By the time the audit arrived, everything was organized and ready. We passed with ease and earned positive feedback from the assessor on the maturity of our security program.”
Michael · CEO, PCI DSS Compliance

Frequently asked questions

Is this a SOC 2 Type I or Type II workbook?

The readiness workbook prepares you for either. It focuses on the controls and evidence both report types require; your auditor determines the observation period for a Type II.

Does the workbook include policy templates?

Yes. It includes policy templates and evidence-collection guides alongside the 85 controls so you are not writing documentation from scratch.

Does this replace an auditor?

No. It is a pre-audit readiness tool. A SOC 2 report can only be issued by a licensed CPA firm, this workbook gets you organized and gap-free before that engagement begins.