Prepare

The SOC 1 Readiness Checklist

Most SOC 1 pain is self-inflicted: examinations start before the controls are ready. Work this checklist first and the examination becomes a verification exercise instead of an excavation.

Before you start

Confirm in writing what your customers will accept -- Type 1 or Type 2 -- and by when. Everything below flows from that decision. Take the 2-minute path quiz if you’re unsure.

The checklist

  • System description drafted. A written description of your services, system boundaries, and controls. The CPA firm will opine on its fairness -- start it early, because it forces every scoping decision.
  • Control objectives defined. The outcomes your controls must achieve, mapped to your customers’ ICFR needs. Vague objectives produce vague testing.
  • Risk assessment completed. Documented identification of what could go wrong in achieving each objective -- examiners expect to see it.
  • Controls designed and documented. For each objective: the control, its owner, its frequency, and how it’s evidenced. Undocumented controls don’t exist for examination purposes.
  • Logical access hygiene. User provisioning/deprovisioning, periodic access reviews, privileged access controls -- the most common finding area.
  • Change management. Documented approval, testing, and deployment controls for in-scope systems.
  • Reconciliations and processing controls. The ICFR heart of SOC 1: batch controls, exception handling, reconciliation of inputs to outputs.
  • Incident response and monitoring. Documented procedures plus evidence they were followed.
  • Vendor and subservice organization inventory. Every third party your controls depend on, with carve-out vs inclusive decisions made before scoping.
  • Complementary user entity controls (CUECs) drafted. What your customers must do on their side -- their auditors need these spelled out.
  • Evidence owners assigned. A named owner for every control’s artifacts, plus a backup. Key-person bottlenecks are the top delay cause.
  • Prior-period artifacts organized. For a Type 2, you need evidence across the whole observation period -- start collecting from day one of the period, not at fieldwork.

Evidence: what good looks like

Good evidence is contemporaneous (created when the control operated, not reconstructed), complete (covers the full period or population), and attributable (shows who did what, when). Screenshots taken the week before fieldwork are the classic failure mode -- build evidence collection into the control’s operation.

The observation-period decision

For a Type 2, start the 6–12 month observation period only when controls are stable and evidence collection is running. Starting early to ‘save time’ backfires: unstable controls during the period become report exceptions, and severe issues can force a restart of the clock. A readiness assessment is the usual gate before the period starts.

Readiness assessment vs DIY

A formal readiness assessment (2–6 weeks, planning estimate $5K–$25K) buys an independent gap list and remediation roadmap -- the highest-ROI spend for first-timers. DIY readiness using this checklist works if your team has been through examinations before. Either way, don’t start the observation period until readiness is genuinely done. See the full timeline.

Questions

Should we hire a firm for readiness or do it ourselves?

If your team has done SOC examinations before, a disciplined self-readiness using this checklist can work. First-timers almost always benefit from a formal readiness assessment -- it finds the gaps while fixes are cheap.

How long does readiness take?

2 to 6 weeks for the assessment itself; remediation after it typically runs 4 to 12 weeks depending on what it finds.

Independent directory note. This guide is educational content, not assurance advice. Confirm requirements with your CPA firm.

Related reading

Get quotes from SOC 1 CPA firms

Tell us about your environment once -- matched CPA firms reply with scoped quotes. Free, 2 minutes.

Get a free quote