Checklist · Worldwide

SOC 2 and ISO 27001 Audit Readiness Checklist

Most first audits fail on evidence, not on controls. This checklist covers scoping, the control areas auditors examine in both SOC 2 Type II and ISO/IEC 27001:2022, the artifacts you must retain, and a 90-day sequence that gets you to a clean report.

Scope and governance

  • Define the systems, products, and locations in scope, and write the system description.
  • Select Trust Services Criteria for SOC 2 (security is required; add availability, confidentiality, processing integrity, or privacy only when customers ask).
  • For ISO 27001, complete the Statement of Applicability against all 93 Annex A controls with justification for exclusions.
  • Assign an accountable owner for the information security management system and record management review minutes.
  • Publish an approved risk assessment methodology and a current risk register with treatment decisions.

Control areas auditors test

  • Access management: joiner, mover, and leaver evidence, quarterly access reviews, privileged access approval.
  • Authentication: enforced multi-factor authentication for staff, administrators, and production systems.
  • Change management: peer-reviewed code, approvals, and traceability from ticket to deployment.
  • Vulnerability management: scan cadence, remediation service levels by severity, and exception approvals.
  • Logging and monitoring: centralized logs, alert rules, retention period, and evidence of alert triage.
  • Vendor management: risk-tiered inventory, due diligence records, and contractual security terms.
  • Business continuity: tested recovery plan, restore evidence, and documented recovery objectives.
  • Incident response: plan, severity matrix, post-incident reviews, and at least one exercise per year.
  • Human resources: background checks, onboarding security training, and signed acceptable use policy.
  • Physical and environmental controls for offices and any self-managed facilities.

Evidence you must retain through the audit window

  • Ticket and approval trails for every change to production during the observation period.
  • Dated screenshots or exports of configuration for each automated control you claim.
  • Signed policy acknowledgements for all staff and contractors with system access.
  • Completed access review records with reviewer identity and date.
  • Training completion records, phishing simulation results, and remediation for repeat clickers.
  • Backup restore test results, penetration test report, and remediation tracker.

90-day readiness sequence

  1. 01Days 1 to 15: confirm scope, choose the framework, and select the audit firm and observation window.
  2. 02Days 1 to 15: run a gap assessment against the criteria and rank findings by audit risk.
  3. 03Days 15 to 40: approve the policy set, appoint control owners, and stand up the risk register.
  4. 04Days 15 to 40: close identity gaps first, since access findings are the most common cause of exceptions.
  5. 05Days 40 to 65: implement evidence automation for access reviews, change approvals, and monitoring.
  6. 06Days 40 to 65: complete penetration testing and vendor due diligence for critical suppliers.
  7. 07Days 65 to 85: run an internal audit or readiness assessment and remediate every finding.
  8. 08Days 85 to 90: hold management review, freeze the control set, and open the observation period.

Preparing for your first SOC 2 or ISO 27001 audit?

Dephiant runs readiness assessments, builds the evidence engine, and sits with your team through auditor fieldwork so surprises do not appear in the final report.