SOC 2 compliance checklist for startups
A step-by-step guide to preparing for your first SOC 2 audit — and how to get there without the enterprise price. Use it as a working checklist, whether you prepare by hand or with Oathhelm.
1. Define scope and report type
- Choose Type I (point in time) or Type II (operating over a period).
- Pick your Trust Services Criteria — Security is mandatory, the rest are optional.
- List the systems, people, vendors and data that are in scope.
2. Run a gap assessment
- Compare your current practices against the SOC 2 Common Criteria (CC1–CC9).
- Record each control as not started, in progress, implemented or not applicable.
- Assign an owner and a due date to every gap.
3. Write and approve your policies
- Information security, access control, change management, incident response, vendor management, business continuity and acceptable use at minimum.
- Have leadership approve them and set a yearly review date.
- Collect employee acceptance of each policy.
4. Implement technical controls
- Enforce MFA and least-privilege access; review access regularly.
- Protect production code: branch protection, required code reviews and secret scanning.
- Encrypt data at rest and in transit; keep backups and test restores.
- Track vulnerabilities and patch within defined timelines.
5. Cover people and vendors
- Background checks and security awareness training for every employee.
- Onboarding and offboarding checklists, including device compliance.
- Risk-tier your vendors and review the critical ones.
6. Assess and track risk
- Keep a risk register scored by likelihood and impact.
- Link each risk to the controls that reduce it.
7. Collect evidence continuously
- Screenshots, exports, tickets and configuration proof for every control.
- Note when each piece of evidence expires so nothing is stale at audit time.
8. Choose an auditor and run the audit
- Select a licensed CPA firm and agree on the audit period.
- Answer auditor requests with linked evidence, then review and close them.
- For Type II, keep controls operating through the whole observation window.
Affordable SOC 2 compliance with Oathhelm
Oathhelm turns this checklist into a workspace: enable SOC 2 and you get controls, policies, tests and tasks generated for you.
Cross-mapped controls
One control satisfies requirements in SOC 2, ISO 27001, HIPAA and more — so the work you do now counts toward your next framework.
Starter policies
Policy drafts and a template library ready to tailor, approve and send for employee acceptance.
Automated tests
Connect GitHub and other tools to check branch protection, reviews and secret scanning on a schedule.
AI evidence review
Upload documents and get each control's coverage, missing or stale proof and next steps.
Audit hub
Give your auditor read-only access, manage requests and export the evidence package.
Trust center
Share your security posture with prospects on a public page.
Plans start at $149/month with flat pricing and no per-seat charges, and every workspace starts with a 14-day free trial.
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
A Type I report checks that your controls are designed properly at a single point in time. A Type II report checks that they actually operated over a period, usually 3 to 12 months. Many startups start with Type I to unblock deals, then move to Type II.
How long does SOC 2 take for a startup?
Preparation typically takes a few weeks to a few months, depending on how many controls are already in place. A Type II report then needs an observation window of at least 3 months before the auditor can issue it.
Do we need all five Trust Services Criteria?
No. Security (the Common Criteria) is required. Availability, Confidentiality, Processing Integrity and Privacy are optional — include them only when customers ask or they fit your product.
Can software replace the auditor?
No. Only a licensed CPA firm can issue a SOC 2 report. Compliance software prepares you for the audit: it tracks controls, collects evidence and gives the auditor organized, read-only access.