SOC 2 · CHECKLIST · FIVE CRITERIA

A tick is not evidence.

Every checklist lists policies. Fieldwork samples evidence. This one pairs each criterion with the artefact that answers it.


A reviewer with curly dark hair, in a charcoal blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Independent means no stake in the answer
Security Availability Confidentiality Processing Integrity Privacy

Our promise

“A control you cannot evidence is a claim.”

Every line is read against the artefact behind it — the dated record fieldwork will ask to sample, not the policy that says you do it. The fee is fixed at $12,500, and nothing is charged until you approve it.

Request this readiness scan
The case file

The checklist, in three chapters

The Law

There are five trust services criteria and only one is compulsory. Security is in scope for every SOC 2, while Availability, Confidentiality, Processing Integrity and Privacy are elected. Each one you add brings its own controls and its own evidence to gather, across the very same window.

The Gap

There is no official control list. The AICPA publishes criteria rather than a numbered catalogue, so a checklist promising sixty controls is describing a vendor product. What is fixed is the five criteria, and what each one asks you to show is true about your own system.

The Office

Our job is the read before the audit. We take each criterion you have elected, find the control you actually run against it, name the dated artefact that answers it, and mark every line where no artefact exists. We issue no opinion and sell no software of our own, so no gap here is there to sell a tool.

The Act, split

Five criteria. Only one is compulsory.

The opinion is signed by a licensed CPA firm. The read before it is ours.

What Security always asks for № 01
  • Access control - reviewed, dated, and with a reviewer
  • MFA and encryption - read from the running system
  • Vulnerabilities - scanned, triaged and closed out
  • Incident response - a plan, and one rehearsal of it
SOC 2 · iDharma · Presented for assay
What the elected criteria add № 02
  • Availability - monitoring, and a restore that actually ran
  • Training and vendors - completions, and a reviewed list
  • Confidentiality - classification, retention and disposal
  • Privacy - a rights route, and the consent trail behind it
SOC 2 · iDharma · Presented for assay
Know your role

The list is easy. The evidence is not.

The criteria

Security, then what you elect

Security is always in scope. Availability, Confidentiality, Processing Integrity and Privacy are elected, and each one you add brings its own criteria, its own controls and its own evidence to collect across the same window. Elect what a buyer has asked for in writing, not what merely looks thorough.

The CPA firm

Who actually tests the list

A licensed CPA firm tests the controls and signs the opinion. They decide what satisfies a criterion for your own system - not a vendor checklist, and certainly not us. We are not a CPA firm and we issue no report of any kind. What we can do is read you the way they will, while changing things is still cheap.

The catch

A tick is not evidence

Fieldwork does not test whether a policy exists. It tests whether a control actually operated, and asks for the dated record that proves it. Teams tick every line of a published checklist and yet still fail a Type II, because nothing in that year produced the artefact the auditor then asks to sample.

What most teams assume

“We have all the policies. We should pass.”

What the contract says

Fieldwork samples records, not policies.

It is the most common finding we write up.

  • Who it is for
  • SaaS & platform vendors
  • Startups selling upmarket
  • Security & GRC leads
  • Engineering leads
  • Founders answering an RFP
Where teams fail
A long black archive box closed on a dark desk under a low warm light, a blank brass label plate screwed to its front with a single stud, a fountain pen and reading glasses beside it, and a small card propped in front reading EVIDENCE OVER PROMISES above a pair of scales.
01 The largest line on most SOC 2 budgets is not an invoice at all. It is your own people gathering evidence, every quarter, for the length of the window.
02

Two firms can quote the same report and differ several times over, because they are quoting different scopes, windows and testing depths.

03

A Type II covers a period you choose. Nobody bills you for the window, and it is the line that decides when you can answer the buyer.

04

The report expires with its period. Budget SOC 2 as a subscription rather than a project, or year two arrives as a surprise.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Criteria -

Security is not optional. The other four are elected, and each one brings its own controls and its own evidence across the same window - so elect what a buyer asked for in writing, not what reads as thorough.

Policies -

Approved, and true. A policy that contradicts what your team actually does is worse at fieldwork than a shorter one that is accurate - the auditor reads it, then samples against it.

Evidence -

This is what a Type II is built from. Not whether the control exists - whether something recorded it operating, on a date, in a form an auditor can sample months later.

The calendar

Four phases, and the last one is elapsed time.

The middle two are work you control. The last one is elapsed time, and no amount of effort makes a window pass faster than it passes.

  1. Scoped

    Weeks 1-2

    The boundary drawn, the criteria elected, a gap assessment run and an owner put against each area.

  2. Written

    Weeks 2-6

    Policies drafted and approved - access control, change management, incident response, vendor risk.

  3. Implemented

    Weeks 6-14

    Controls actually running: access managed, logging and monitoring on, staff trained, tools deployed.

  4. Evidenced

    Then the window

    Evidence collected right across the period, and then fieldwork samples it. A Type I stops before this part.

The trap

Teams tick the list and stop there. The thing fieldwork samples is not on any checklist — it is the dated record showing the control operated, and it cannot be created after the window has run.

Requirement & coverage

What the criteria ask, what answers them

12 things to settle, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.

Access control and joiners Security - always in scope
A dated access review with the reviewer named, and leaver records that match your HR dates rather than your intentions.
Multi-factor authentication Security - and the first thing sampled
Configuration proof for every system in the boundary, plus the exceptions list and who approved each one.
Encryption in transit and at rest Security, and Confidentiality where elected
Settings read out of the running system rather than a policy sentence asserting that encryption is enabled.
Vulnerability management Security - scanning, triage and closure
Scan output with dates, the triage decision on each finding, and evidence that the fix or the acceptance happened.
Incident response Security - the plan and the rehearsal
The plan, plus one real or tabletop incident with timestamps, decisions and who was told - a plan alone samples badly.
Security awareness training Security - completion, not availability
Completion records per person per period, which is the artefact, rather than a link to a course nobody finished.
Vendor and subservice risk Security - and it reaches your own suppliers
The vendor list, what each one touches, the review you performed, and the carve-out or inclusive decision recorded.
Availability and recovery Availability - only if you elect it
Monitoring and alerting proof, plus a restoration test that actually restored something, with the date it ran.
Backup restoration testing Availability - the test, not the backup
Evidence that a restore was performed and verified, because a backup nobody has restored is an untested assumption.
Change management Processing Integrity, and Security throughout
A sample of real changes showing review, approval and deployment - traceable from ticket to release.
Data classification and retention Confidentiality - and disposal counts
The classification scheme in use, where each class lives, and proof that disposal happens on the stated schedule.
Data subject rights and consent Privacy - the least-elected criterion
A working request route, response records inside your stated window, and the consent trail behind each use.
The engagement

Your control set, independently read

From Security alone to all five criteria.

  1. Elect

    Security is in scope already. Which of the other four your buyer actually asked for.

  2. Check

    Every control area read against what you run, and against the evidence it produces.

  3. Close and sign off

    You see the draft first. Then the gap list, the evidence index and the shortlist - dated.

Request your readiness review
An auditor in a forest-green trouser suit and cream blouse, with braided hair in a high bun, standing against a warm pale wall and pointing into the open space alongside.
The record is what you are buying.
Struck in your favour

Why teams ask iDharma to read the list with them

We sell no software

No platform to license and no seats to grow, so we have no reason to call your spreadsheet a gap.

We do not issue the SOC 2

A licensed CPA firm signs that opinion. We read you before it, and we say so on every page.

Evidence, not ticks

Every line is checked against the dated artefact behind it, which is what fieldwork samples.

One fixed fee, published

The readiness price is on this page and in the checkout, and no finding we make changes it.

Four marks, struck on every readiness report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Readiness report, by criterion

The whole checklist answered in one document: which criteria you elected and why, every control area underneath each of them, what you run against it today, which dated artefact answers it, where that artefact does not exist yet, and what closing each remaining gap takes in money and in hours before fieldwork begins.

Workbook

Criteria checklist workbook

Every control area as a row you can work through, with the elected criteria marked and an owner against each line.

Index

Evidence index

What artefact answers each criterion, where it lives, who produces it and how often - the part a checklist leaves out.

Ranked

Policy gap list

Which policies the criteria actually require, which of yours exist, and which describe a process nobody follows now.

Memo

Scope memo

What sits inside the boundary, which criteria were elected and why, and what was deliberately left out of both.

Ranked

Remediation shortlist

What to fix before fieldwork and what can wait, ranked by what the opinion is at risk on rather than what is quickest.

Memo

Type I or Type II memo

Which report your buyer actually asked for, what each one tests, and what the window costs you in evidence hours.

Format & fee

Real numbers, upfront.

Scope
Set by the criteria you elect
Input
Your controls, policies, evidence
Re-read
Annually, or on a scope change - a new system, a new criterion, a new buyer asking.

The scope is fixed before the meter starts, so the fee is flat - and nothing is charged until you approve it.

Request your scan
SOC 2 · Readiness review $12,500 flat
  • Independent readiness report, costed
  • Pipeline trace, transform by transform
  • Vendor-clause review included
  • A dated evidence trail you keep
Show your hand

Four things fieldwork asks you to produce

Good faith is not a document. Each of these is either in your hand on the day somebody asks, or it is not.

The policy,
approved

Written, dated and approved by somebody with the authority to approve it. The weakest kind of evidence there is, and the only kind most checklists collect.

The control,
running

The setting read out of the live system rather than the policy sentence describing it. Configuration is what gets sampled when a policy claims something.

The record,
dated

Proof the control operated on a date - the review performed, the ticket approved, the restore tested. This is the artefact a Type II is actually built from.

The exception,
owned

Where a control did not operate, the record saying so, who accepted it and until when. Exceptions handled openly cost far less than exceptions discovered.

Four artefacts, and only the first one is a document.

FAQ

Plain answers

Scope, timing, and the cost of getting it wrong. Answered straight.

Request your scan
How many controls are in SOC 2?

There is no official number. The AICPA publishes criteria, not a numbered control catalogue - so any "60 controls" list is a vendor's own taxonomy. What is fixed is the five criteria, and Security is the only one always in scope.

Do we need all five trust services criteria?

No. Security is always in scope; Availability, Confidentiality, Processing Integrity and Privacy are elected. Each one you add brings its own controls and its own evidence across the same window, so elect what a buyer asked for in writing.

Type I or Type II - which do we need?

Most enterprise buyers mean Type II. A Type I tests design at a point in time; a Type II tests whether controls operated across a period. Paying for the wrong one is the most common waste on a first SOC 2, and one email settles it.

How long does it take to be audit-ready?

Commonly three to four months of work before the window opens - scope and gap read, policies, then controls actually running. The window itself is extra, and a Type II cannot be shortened by working harder inside it.

What evidence does the auditor actually ask for?

Dated artefacts, sampled. Access reviews with a reviewer and a date, tickets showing approval, scan output with the triage decision, training completion per person, a restore that actually ran. Not the policy that says you do these things.

Get started

Request your readiness review

Tell us what you generate and where it goes, and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which systems sit inside the boundary
  2. Where that content is published, and who gets to see it
  3. Any documentation - policies, prior reports
  4. Whether you host the model, buy it, or fine-tune one
  5. A published asset or two, exactly as your readers get them

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • AICPA Trust Services Criteria (2017, rev. 2022)
  • AICPA SSAE No. 18, AT-C section 205
Criteria
TSC 2017, rev. 2022
Last read
14 September 2026

What it means

  • General information about what the criteria ask — not legal or accounting advice, and no professional relationship arises from reading it. It determines nothing about your own systems.
  • Where a scope question is arguable, our reports say so rather than the convenient one.

Scope & limitation

  • Control areas are our reading of the criteria, not an AICPA mapping.
  • The AICPA publishes criteria, not a numbered control list - see above.
  • Do not rest a binding decision on it; engage qualified counsel.

Something on this page out of date?

Tell us