Skip to main content
    Compliance

    SOC 2 Type II Readiness Checklist: A 90-Day Path for SMBs

    A week-by-week SOC 2 Type II readiness plan for small and mid-sized companies — scope, controls, evidence, and the mistakes that add months to an audit.

    James Tuttle·Founder & Fractional CTO/CISO
    2 min readsoc 2 type ii readiness, soc 2 checklist, soc 2 for smb

    Last updated:

    Most SMBs do not fail SOC 2 Type II because their security is bad. They fail because nobody owned the evidence trail. A Type II report tests whether your controls actually operated over a window of time — typically three to twelve months — so the audit is really a test of operational discipline, not of your firewall.

    Here is the 90-day readiness path we run with clients before the observation window opens.

    Days 1–15: Scope and Trust Services Criteria

    • Decide which Trust Services Criteria apply. Nearly everyone needs Security. Add Availability, Confidentiality, Processing Integrity, or Privacy only when a customer contract demands it — each one adds controls and cost.
    • Draw the system boundary: production systems, the cloud accounts they live in, the SaaS tools that touch customer data, and the people with access.
    • Name an accountable owner. An auditor will ask who runs the security program. "The CTO, when he has time" is the answer that costs you a qualified opinion.

    Days 16–40: Policies That Match Reality

    Buy or borrow a policy library, then rewrite it to describe what you actually do. Auditors test policy against practice; an aspirational policy is worse than a modest one.

    • Information security, access control, change management, incident response, vendor management, business continuity, and secure SDLC.
    • Annual review dates with a documented approver.
    • Employee acknowledgement captured in your HR system, not an email thread.

    Days 41–65: Controls and Automation

    • MFA everywhere, enforced by policy in your identity provider — not requested politely.
    • Formal onboarding and offboarding with access removed within one business day, and a ticket to prove it.
    • Change management: pull requests, reviewer approval, and a link from the deploy back to the ticket.
    • Vulnerability management with defined remediation SLAs by severity, and evidence that you met them.
    • Logging and alerting retained for the full observation window.

    Days 66–90: Evidence Rehearsal

    Run a mock audit against your own controls. For each control, answer: what artifact proves this operated, where does it live, and who produces it on demand? If the answer requires a screenshot taken the day the auditor asks, the control is not ready.

    The Four Mistakes That Add Months

    1. Starting the observation window before controls are live. The window only counts if the control was operating on day one.
    2. Over-scoping. Adding Privacy criteria "just in case" can double your control count.
    3. Treating the compliance tool as the program. Automated evidence collection is helpful; it does not decide risk acceptance or write your risk register.
    4. No named executive owner. Auditors, customers, and boards all want one accountable person.

    Where a Fractional CISO Fits

    A fractional CISO engagement gives you the accountable owner the audit expects, without a full-time hire. We run readiness, sit in the auditor calls, and hand your enterprise buyers a defensible answer instead of a spreadsheet of promises.

    Want a baseline before you commit to a window? Start with the Senticit Intelligence Score to see where your posture stands today.

    Share

    This article is part of our comprehensive Compliance guide.

    Read the complete guide →

    We value your privacy

    We use cookies to analyze site traffic and improve your experience. You can customize your preferences or accept all cookies. Cookie Policy · Privacy Policy