SOC 2 checklist for startups: 20 items for a first audit
Short answer
This checklist covers the 20 items most first-time teams need to settle before an auditor arrives: five decisions, four people items, five systems items, three policy items and three audit items. Print it and tick it off; it is a planning aid, not the AICPA criteria themselves.
Which decisions come first?
What about people?
Which systems items matter most?
Which policies and records are needed?
What do you need for the audit itself?
How does a tool change this list?
A compliance tool turns many of these items into tracked tasks and collects evidence for items 10 to 14 from connected systems. It does not choose your scope or your auditor. If you have no security lead, an expert-guided tool also takes on items 1 to 5 with you.
What should you read next?
Next lesson · 7 of 10SOC 2 policies for startups: what your first audit needs
Questions founders ask
Is there an official SOC 2 checklist?
No official checklist exists for startups. The AICPA publishes the Trust Services Criteria and guidance for auditors; checklists like this one are planning aids.