SOC 2 Type II Readiness Checklist: A 90-Day Path for SMBs
A week-by-week SOC 2 Type II readiness plan for small and mid-sized companies — scope, controls, evidence, and the mistakes that add months to an audit.
Last updated:
Most SMBs do not fail SOC 2 Type II because their security is bad. They fail because nobody owned the evidence trail. A Type II report tests whether your controls actually operated over a window of time — typically three to twelve months — so the audit is really a test of operational discipline, not of your firewall.
Here is the 90-day readiness path we run with clients before the observation window opens.
Days 1–15: Scope and Trust Services Criteria
- Decide which Trust Services Criteria apply. Nearly everyone needs Security. Add Availability, Confidentiality, Processing Integrity, or Privacy only when a customer contract demands it — each one adds controls and cost.
- Draw the system boundary: production systems, the cloud accounts they live in, the SaaS tools that touch customer data, and the people with access.
- Name an accountable owner. An auditor will ask who runs the security program. "The CTO, when he has time" is the answer that costs you a qualified opinion.
Days 16–40: Policies That Match Reality
Buy or borrow a policy library, then rewrite it to describe what you actually do. Auditors test policy against practice; an aspirational policy is worse than a modest one.
- Information security, access control, change management, incident response, vendor management, business continuity, and secure SDLC.
- Annual review dates with a documented approver.
- Employee acknowledgement captured in your HR system, not an email thread.
Days 41–65: Controls and Automation
- MFA everywhere, enforced by policy in your identity provider — not requested politely.
- Formal onboarding and offboarding with access removed within one business day, and a ticket to prove it.
- Change management: pull requests, reviewer approval, and a link from the deploy back to the ticket.
- Vulnerability management with defined remediation SLAs by severity, and evidence that you met them.
- Logging and alerting retained for the full observation window.
Days 66–90: Evidence Rehearsal
Run a mock audit against your own controls. For each control, answer: what artifact proves this operated, where does it live, and who produces it on demand? If the answer requires a screenshot taken the day the auditor asks, the control is not ready.
The Four Mistakes That Add Months
- Starting the observation window before controls are live. The window only counts if the control was operating on day one.
- Over-scoping. Adding Privacy criteria "just in case" can double your control count.
- Treating the compliance tool as the program. Automated evidence collection is helpful; it does not decide risk acceptance or write your risk register.
- No named executive owner. Auditors, customers, and boards all want one accountable person.
Where a Fractional CISO Fits
A fractional CISO engagement gives you the accountable owner the audit expects, without a full-time hire. We run readiness, sit in the auditor calls, and hand your enterprise buyers a defensible answer instead of a spreadsheet of promises.
Want a baseline before you commit to a window? Start with the Senticit Intelligence Score to see where your posture stands today.
This article is part of our comprehensive Compliance guide.
Read the complete guide →