Avirio
Sign in
← Resources
GuideJune 2025·12 min read

The Complete SOC 2 Type II Checklist for 2025

Everything a startup or growth company needs to achieve SOC 2 Type II certification from scoping your environment to closing your first audit.

What is SOC 2 Type II?

SOC 2 Type II is an audit framework developed by the AICPA (American Institute of CPAs) that evaluates a service organization's controls over a period of time typically 6 or 12 months. Unlike SOC 2 Type I which only checks that controls exist at a single point in time, Type II tests whether those controls operated effectively over the audit period. This is what enterprise customers, investors, and partners ask for when they want proof that you take security seriously.

Step 1 Define your scope

The first decision is which Trust Services Criteria (TSC) to include in your audit. Security (CC) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional add-ons. Most SaaS startups start with Security only, adding Availability if their customers have uptime SLAs. Get this wrong and you'll either over-scope (costing time and money) or under-scope (failing to satisfy enterprise requirements).

  • Security (CC) always required
  • Availability required for SaaS with uptime guarantees
  • Confidentiality required for data handling assurances
  • Processing Integrity required for financial, healthcare processing
  • Privacy required for consumer data handling

Step 2 Gap assessment

Before you can remediate, you need to know where you stand. A gap assessment maps your current practices against every control in the selected criteria. Expect to find gaps in change management, vendor reviews, and access recertification these are the most common failure points for first-time audits. Document everything: what control exists, how it works, who owns it, and what evidence will be collected.

Step 3 Build your policy library

SOC 2 requires documented policies covering information security, access control, incident response, change management, risk assessment, and vendor management at minimum. Auditors will review both the existence of these policies and evidence that employees have acknowledged them. Use templates as a starting point but ensure they reflect how your organization actually operates, not an idealized version.

Step 4 Implement and test controls

This is where most of the work happens. Every control needs to be implemented, tested, and generating evidence. The good news: most modern cloud environments already generate the logs and configuration data that constitute SOC 2 evidence. The work is connecting your tools, ensuring evidence is being captured correctly, and fixing gaps before your auditor sees them.

  • Access control: SSO, MFA, provisioning/deprovisioning workflows
  • Change management: code review, deployment approvals, change records
  • Vulnerability management: scanning, patching SLAs, penetration testing
  • Incident response: documented runbooks, tested response procedures
  • Vendor management: due diligence questionnaires, review schedules

Step 5 Evidence collection (the ongoing part)

Once your observation period starts, evidence collection runs continuously for 6–12 months. Manual evidence collection screenshots, spreadsheets, email chains is the old way. Modern compliance platforms connect directly to your cloud, identity, and dev tools to collect evidence automatically. This eliminates the pre-audit scramble and means your evidence room is always current.

Step 6 The audit

Find an AICPA-accredited CPA firm that specializes in SOC 2 audits. The audit process typically takes 4–8 weeks and involves document review, walkthroughs, and evidence testing. Your auditor will test a sample of evidence for each control. Exceptions (where evidence doesn't support the control) will need to be addressed or disclosed. The final SOC 2 report is typically ready 2–4 weeks after fieldwork completes.

Common failure points to avoid

After reviewing hundreds of SOC 2 audits, these are the controls companies most frequently fail on:

  • Access reviews: not running quarterly reviews of user access
  • Vendor reviews: not completing annual security reviews for critical vendors
  • Change management: missing approvals for emergency changes
  • Security training: employees not completing annual training
  • Incident response: not testing the IR plan with a tabletop exercise

Ready to automate this?

Avirio automates evidence collection, control testing, and audit management so you can focus on building.

Get a demo →
Related reading