OathhelmStart free trial

SOC 2 compliance checklist for startups

A step-by-step guide to preparing for your first SOC 2 audit — and how to get there without the enterprise price. Use it as a working checklist, whether you prepare by hand or with Oathhelm.

1. Define scope and report type

  • Choose Type I (point in time) or Type II (operating over a period).
  • Pick your Trust Services Criteria — Security is mandatory, the rest are optional.
  • List the systems, people, vendors and data that are in scope.

2. Run a gap assessment

  • Compare your current practices against the SOC 2 Common Criteria (CC1–CC9).
  • Record each control as not started, in progress, implemented or not applicable.
  • Assign an owner and a due date to every gap.

3. Write and approve your policies

  • Information security, access control, change management, incident response, vendor management, business continuity and acceptable use at minimum.
  • Have leadership approve them and set a yearly review date.
  • Collect employee acceptance of each policy.

4. Implement technical controls

  • Enforce MFA and least-privilege access; review access regularly.
  • Protect production code: branch protection, required code reviews and secret scanning.
  • Encrypt data at rest and in transit; keep backups and test restores.
  • Track vulnerabilities and patch within defined timelines.

5. Cover people and vendors

  • Background checks and security awareness training for every employee.
  • Onboarding and offboarding checklists, including device compliance.
  • Risk-tier your vendors and review the critical ones.

6. Assess and track risk

  • Keep a risk register scored by likelihood and impact.
  • Link each risk to the controls that reduce it.

7. Collect evidence continuously

  • Screenshots, exports, tickets and configuration proof for every control.
  • Note when each piece of evidence expires so nothing is stale at audit time.

8. Choose an auditor and run the audit

  • Select a licensed CPA firm and agree on the audit period.
  • Answer auditor requests with linked evidence, then review and close them.
  • For Type II, keep controls operating through the whole observation window.

Affordable SOC 2 compliance with Oathhelm

Oathhelm turns this checklist into a workspace: enable SOC 2 and you get controls, policies, tests and tasks generated for you.

Cross-mapped controls

One control satisfies requirements in SOC 2, ISO 27001, HIPAA and more — so the work you do now counts toward your next framework.

Starter policies

Policy drafts and a template library ready to tailor, approve and send for employee acceptance.

Automated tests

Connect GitHub and other tools to check branch protection, reviews and secret scanning on a schedule.

AI evidence review

Upload documents and get each control's coverage, missing or stale proof and next steps.

Audit hub

Give your auditor read-only access, manage requests and export the evidence package.

Trust center

Share your security posture with prospects on a public page.

Plans start at $149/month with flat pricing and no per-seat charges, and every workspace starts with a 14-day free trial.

Frequently asked questions

What is the difference between SOC 2 Type I and Type II?

A Type I report checks that your controls are designed properly at a single point in time. A Type II report checks that they actually operated over a period, usually 3 to 12 months. Many startups start with Type I to unblock deals, then move to Type II.

How long does SOC 2 take for a startup?

Preparation typically takes a few weeks to a few months, depending on how many controls are already in place. A Type II report then needs an observation window of at least 3 months before the auditor can issue it.

Do we need all five Trust Services Criteria?

No. Security (the Common Criteria) is required. Availability, Confidentiality, Processing Integrity and Privacy are optional — include them only when customers ask or they fit your product.

Can software replace the auditor?

No. Only a licensed CPA firm can issue a SOC 2 report. Compliance software prepares you for the audit: it tracks controls, collects evidence and gives the auditor organized, read-only access.