Free SOC 2 Readiness Checklist
Free SOC 2 Readiness Checklist
Instant download. Editable files. One-organization licence. 5-day fit guarantee.
Couldn't load pickup availability
A 15-minute, honest view of how close your SaaS company is to a SOC 2 audit, before you spend money on auditors or platforms. Answer 30 questions and get a score, results by area and next steps.
What you get
- Readiness Checklist (Excel): 30 questions in six areas (scope and governance, policies and people, risk and vendors, access and endpoints, engineering and operations, resilience and response), with Yes / Partly / No dropdowns, automatic scoring, results by area and a first step for every gap.
- Printable checklist (PDF, 3 pages) with scoring instructions and four readiness bands.
- Start Here note (PDF, 1 page).
How to use it
- Set aside 15 minutes with the people who know your engineering, IT and HR practices.
- Answer every question. When torn between Yes and Partly, choose Partly: auditors need evidence, not intentions.
- Read the next steps for your band and repeat in a month to see progress.
Want the full system?
The SOC 2 Readiness Assessment & Control Matrix ($59) checks all 61 criteria with 148 controls. The SOC 2 Starter Bundle ($199) adds 20 policies and the risk and vendor kit, and the SOC 2 Compliance Toolkit ($249) has everything.
Good to know
- Free instant download. Excel (.xlsx) and PDF; no macros.
- Criteria are referenced by number and summarized in our own words; the AICPA criteria are free to download from the AICPA.
- A self-assessment for planning. It is not an audit and does not predict an auditor's opinion.

What every download includes
Templates refer to Trust Services Criteria numbers (for example CC6.1) and describe them in our own words; they do not reproduce AICPA text. A SOC 2 report is issued by a licensed CPA firm. Templates help you prepare; they do not guarantee a clean report.
Questions about Free SOC 2 Readiness Checklist
What does the SOC 2 readiness checklist cover?
Thirty questions across scope and governance, policies and people, risk and vendors, access and endpoints, engineering and operations, and resilience and response. They reflect what auditors typically test for the Security category: MFA, access reviews, change control, logging, vulnerability management, incident response, backups, vendor reviews and evidence.
How is the score calculated?
Yes scores 2, Partly scores 1 and No scores 0, for a maximum of 60. Your percentage places you in one of four bands, from Early stage to Close to audit-ready, each with next steps and a rough time to Type 1 readiness. The Excel version calculates everything and suggests a first step for each gap.
Does a high score mean we will pass SOC 2?
No. SOC 2 is an attestation report by a licensed CPA firm, and there is no pass mark. The auditor forms an opinion based on evidence that your controls are designed and, for Type 2, operating. The checklist shows where to focus; it does not predict the opinion.
Should we include Privacy or Processing Integrity?
Only when customers ask for them. Security is always included. Each optional category adds criteria, evidence and cost, so most first-time SaaS reports cover Security, sometimes with Availability or Confidentiality. Question 2 of the checklist prompts you to make this decision deliberately.
How will I receive the files?
A download button appears on the order confirmation page and the same link is emailed to you within a few minutes. Bundles arrive as one ZIP file.
Can I get a refund?
Yes. With our 5-day fit guarantee, if the files do not fit your SOC 2 program you can ask for a full refund within 5 days of your order. It applies once per customer and organization, covers the whole product, and requires you to confirm you have deleted the files. We also refund non-delivery, defective files, wrong items and duplicate purchases within 30 days. Read the full refund policy.
Can I see the files before I buy?
Yes. The images above show real pages from the files, and the free SOC 2 readiness checklist lets you check where you stand before you buy.
Can I use the templates with more than one company?
Each purchase is licensed to one organization. Consultants and groups need one licence per client or legal entity. See the licence agreement.
Templates that work with this one
Useful next steps when you prepare for a SOC 2 audit.