Decisions to make first
- Type 1 or Type 2. Ask the customers who are requesting the report which they need. See Type 1 vs Type 2.
- Scope. Which product, which systems and which teams the report will cover.
- Criteria. Security is required. Availability, Confidentiality, Processing Integrity and Privacy are optional and add work.
- Dates. When you want the audit period to start and when you need the report.
- Platform. Which compliance platform you use or plan to use, and whether the auditor works in it.
Documents to have ready
- A short description of what your product does and who uses it.
- A diagram or list of the systems it runs on, including your cloud hosting provider.
- An org chart and headcount.
- The list of your important vendors.
- Your security policies, even in draft.
- The names of the people who own engineering, IT, HR and security.
Know where you stand
Do a readiness review before the audit period begins, either yourself or with help. The goal is to find the gaps while there is still time to close them, not during the audit. If you use a compliance platform, the list of failing tests is a good starting point.
Choose one point of contact
The auditor will send a steady stream of questions and requests. They need one person to send them to, and that person needs the time to respond. Audits slow down most when requests are spread across several people.
Questions to ask the audit firm
Have these ready for the call. We cover them in more detail in how to choose a SOC 2 auditor.
- How many companies of our size and type have you audited?
- Do you work inside our compliance platform?
- What is your timeline from the end of the audit period to the final report?
- What does the fee include, and what would next year cost?
What the auditor does not do
The auditor tests your controls and issues the report. To stay independent, they do not design your controls, write your policies or fix your gaps. That work is yours, or your partner's.
We run the readiness review, get everything prepared and then act as the auditor's point of contact. See SOC 2 readiness and audit management.
