The systems you need to be compliant, by department.

SOC 2 does not require specific products. It requires proof that things are done consistently, and that proof comes from the systems each department runs on. Here is what to have in place.

Systems guide · By Elevated Vibration · Updated October 2026

HR

  • An HR system as the single record of who works for you, with hire and departure dates. See the HR system setup checklist.
  • Onboarding and offboarding checklists that are followed every time.
  • Security awareness training with completion records.
  • Policy acceptance recorded for every employee.
  • Background checks, if your policy calls for them.

IT

  • An identity provider with single sign-on and multi-factor authentication turned on for everyone.
  • Device management so every laptop is encrypted, locked and kept up to date.
  • A password manager for shared credentials. See how to roll one out.
  • Backups that are tested.
  • Regular access reviews of key systems. See how to run a user access review.

Web and engineering

  • A code repository where every change is reviewed before release.
  • Cloud hosting with logging and monitoring turned on.
  • Vulnerability scanning with a record of fixes.
  • A ticketing system that ties changes and incidents to a record.
  • For your website: updates applied on a schedule, security monitoring and backups.

Finance

  • An accounting system with individual logins and role-based access.
  • Approval steps for payments, so one person cannot both create and approve.
  • Contract and invoice records for every vendor.

SOC 2 is not a financial audit, but access control and vendor records in finance systems are in scope when they touch customer data or company security.

Operations

  • A compliance platform to monitor controls and hold evidence.
  • A vendor list with owners, renewal dates and security reviews. See building a vendor list.
  • A home for documentation, where policies and procedures are kept current. See how to write an SOP.
  • An incident log and a tested response plan.
  • A risk assessment, reviewed at least once a year.

RevOps

  • A CRM with role-based access, so people see only the customer data they need.
  • Contract storage and e-signature with controlled access.
  • A support desk that records customer requests and how they were handled.
  • A clear handoff to billing. See bookings to billings.

What ties it together

Each of these systems needs an owner, individual logins and a record of who has access. Most also need to be connected to your identity provider and compliance platform. The tools matter less than whether they are set up properly and kept that way.

We select, set up and manage these systems across departments. See systems selection and setup and our suggested tools.

Related articles

Setting Up BambooHR: What to Think About First

The decisions to make before you configure BambooHR, from access levels to time off policies.

How to Roll Out a Password Manager at a Small Company

A practical rollout plan: structure, settings, moving shared logins and getting everyone to actually use it.

SOC 2 Policies: Which Ones You Need

The policies most SOC 2 audits expect, what each covers, and how to make them match reality.

Common questions

Straight answers.

Does SOC 2 require specific software?

No. SOC 2 requires that controls exist and operate consistently. Software is how most companies carry out those controls and produce evidence.

Which systems should we set up first for SOC 2?

An identity provider with multi-factor authentication, an HR system, device management and a password manager. A compliance platform then connects to them.

Do small companies need all of these systems?

Not every item needs a dedicated product. A small company can cover several with one tool, as long as each control has an owner and leaves a record.

Want the full picture for your company?

Tell us which systems you have today. We'll tell you what's missing.

Book a free call