---
title: SOC 2 Checklist | Thoropass
description: Choose objectives, perform a gap analysis, implement controls, prepare for audit, and maintain compliance effortlessly.
---

[Skip to content](https://info.thoropass.com/soc-2-checklist#main-content)

[![Thoropass](https://info.thoropass.com/hs-fs/hubfs/Thoropass/Logos/Thoropass-Logo-Black.png?width=150&name=Thoropass-Logo-Black.png)](https://thoropass.com/)

- Frameworks 
    - [SOC 2](https://thoropass.com/frameworks/soc-2/)
    - [ISO 27001](https://thoropass.com/frameworks/iso-27001/)
    - [PCI DSS](https://thoropass.com/frameworks/pci-dss/)
    - [GDPR](https://thoropass.com/frameworks/gdpr/)
    - [HIPAA](https://thoropass.com/frameworks/hipaa/)
    - [HITRUST](https://thoropass.com/frameworks/hitrust/)
    - [Other Frameworks](https://thoropass.com/frameworks/other-frameworks/)
- Platform 
    - [Overview](https://thoropass.com/platform/overview/)
    - [Seamless Audit Experience](https://thoropass.com/platform/security-audit-experience/)
    - [Penetration Testing](https://thoropass.com/platform/penetration-testing/)
    - [Security Questionnaire Tools](https://thoropass.com/platform/security-questionnaire-tools/)
    - [Integrations](https://thoropass.com/platform/integrations/)
- Why Thoropass 
    - [Our Difference](https://thoropass.com/advantage/about/)
    - [Meet the Experts](https://thoropass.com/advantage/meet-the-experts/)
    - [Customer Stories](https://thoropass.com/advantage/customer-stories/)
- Learn 
    - [University](https://thoropass.com/learn/thoropass-university/)
    - [Blog](https://thoropass.com/learn/blog/)
    - [Guides](https://thoropass.com/learn/guides/)
    - [Events](https://thoropass.com/learn/events/)
- Company 
    - [Careers](https://thoropass.com/company/careers/)
    - [Become a Partner](https://thoropass.com/company/become-a-partner/)
    - [Newsroom](https://thoropass.com/company/newsroom/)
    - [Contact Us](https://thoropass.com/company/contact/)
- [Sign In](https://login.thoropass.com/)

[![Talk to an Expert](https://no-cache.hubspot.com/cta/default/7851520/ac852395-8e6d-45cf-9e9f-7dbb758e8133.png)](https://cta-redirect.hubspot.com/cta/redirect/7851520/ac852395-8e6d-45cf-9e9f-7dbb758e8133)

- Frameworks 
    - [SOC 2](https://thoropass.com/frameworks/soc-2/)
    - [ISO 27001](https://thoropass.com/frameworks/iso-27001/)
    - [PCI DSS](https://thoropass.com/frameworks/pci-dss/)
    - [GDPR](https://thoropass.com/frameworks/gdpr/)
    - [HIPAA](https://thoropass.com/frameworks/hipaa/)
    - [HITRUST](https://thoropass.com/frameworks/hitrust/)
    - [Other Frameworks](https://thoropass.com/frameworks/other-frameworks/)
- Platform 
    - [Overview](https://thoropass.com/platform/overview/)
    - [Seamless Audit Experience](https://thoropass.com/platform/security-audit-experience/)
    - [Penetration Testing](https://thoropass.com/platform/penetration-testing/)
    - [Security Questionnaire Tools](https://thoropass.com/platform/security-questionnaire-tools/)
    - [Integrations](https://thoropass.com/platform/integrations/)
- Why Thoropass 
    - [Our Difference](https://thoropass.com/advantage/about/)
    - [Meet the Experts](https://thoropass.com/advantage/meet-the-experts/)
    - [Customer Stories](https://thoropass.com/advantage/customer-stories/)
- Learn 
    - [University](https://thoropass.com/learn/thoropass-university/)
    - [Blog](https://thoropass.com/learn/blog/)
    - [Guides](https://thoropass.com/learn/guides/)
    - [Events](https://thoropass.com/learn/events/)
- Company 
    - [Careers](https://thoropass.com/company/careers/)
    - [Become a Partner](https://thoropass.com/company/become-a-partner/)
    - [Newsroom](https://thoropass.com/company/newsroom/)
    - [Contact Us](https://thoropass.com/company/contact/)
- [Sign In](https://login.thoropass.com/)

[![Thoropass](https://info.thoropass.com/hubfs/Thoropass/Logos/Thoropass-Logo-Black.png)](https://thoropass.com/)

# The SOC 2 Checklist: it's time to kickstart your compliance journey

It can be challenging to understand the first steps when starting the SOC 2 process. Businesses implement and maintain SOC 2 in a variety of ways. We broke down the basic process to tackle SOC 2 compliance into a checklist below.

[Start Reading](https://info.thoropass.com/soc-2-checklist#checklist)

1\. Choose objectives and TSCs

The first action item on your SOC 2 checklist involves the purpose of your SOC 2. Before diving into controls, an organization needs to determine the objective of their SOC 2 report and choose relevant TSCs.

There are two types of SOC 2 reports, Type 1 and Type 2. Businesses typically start with a Type 1 and build up to a Type 2. We recommend this order for our own clients.

**How do you determine which trust services principles to test for?**

SOC 2 TSCs are driven by the commitments you make to your customers. What are your responsible for managing and maintaining? **SOC 2 encompasses 5 TSCs**:

- Security
- Privacy
- Processing Integrity
- Confidentiality
- Availability

The only required criteria is security. For more information on Trust Service Criteria, [click here](https://thoropass.com/university/principles-for-soc-2/).

2\. Perform a gap analysis and develop a remediation plan

A compliance team examines the practices and procedures a business has in place and compares the security posture to SOC 2 best practices to identify gaps. Based on the gaps found, a strategic remediation plan is set to tackle SOC 2 in the most efficient way possible. Take a look behind the curtain at our own SOC 2 gap analysis and remediation plan [here](https://thoropass.com/blog/compliance_101/soc-2-gap-analysis/).

3\. Implement stage-appropriate controls

SOC 2 is a flexible framework. In light of this, a startup might have a lighter control set to meet certain requirements than an enterprise customer.

From logging and monitoring to HR tasks and vendor management, a compliance team can identify ways to save time and money by implementing the correct tools and processes.

4\. Preparing for audit

After the risk assessment mitigation and acceptance process, the business needs to prepare for an audit.

**How do you prepare for a SOC 2 audit?**  
While this means gathering evidence of implemented controls, it also means preparing an internal team to answer questions and work with auditors throughout the audit process.

**How do you determine your company’s readiness for a SOC 2 audit?**  
After your team collects and compiles evidence for auditors and assesses and accepts risk, the organization is ready for audit.

5\. Execute the audit

SOC 2 audits last between 2 weeks and a couple of months. This depends on the number of questions or evidence requests from the auditors.

Based on the results of your audit, you may or may not need to adjust for discrepancies identified by the auditor. 

6\. Maintain and monitor compliance over a 12-month period

Best practices state that organizations should undergo a new SOC 2 Type 2 assessment every 6 to 12 months. This helps to demonstrate to customers that your controls are in place and have been operating effectively year-over-year.

We recommend that our clients set up integrations to automatically collect evidence and monitor practices over time. This helps avoid heavy time commitments from team members and continues to secure information.

## Start your SOC 2 journey with Thoropass

Check off the boxes on this list with the help of powerful automation and expert guidances from Thoropass—helping you reach compliance in less time, with less manual effort.

[Talk to an expert](https://thoropass.com/talk-to-an-expert/)

![Thoropass-Logo-Black](https://info.thoropass.com/hs-fs/hubfs/Thoropass/Logos/Thoropass-Logo-Black.png?width=150&name=Thoropass-Logo-Black.png)

- Frameworks 
    - [SOC 2](https://thoropass.com/frameworks/soc-2/)
    - [ISO 27001](https://thoropass.com/frameworks/iso-27001/)
    - [PCI DSS](https://thoropass.com/frameworks/pci-dss/)
    - [GDPR](https://thoropass.com/frameworks/gdpr/)
    - [HIPAA](https://thoropass.com/frameworks/hipaa/)
    - [HITRUST](https://thoropass.com/frameworks/hitrust/)
    - [Other Frameworks](https://thoropass.com/frameworks/other-frameworks/)
    - Company
    - [Careers](https://thoropass.com/company/careers/)
    - [Become a Partner](https://thoropass.com/company/become-a-partner/)
    - [Newsroom](https://thoropass.com/company/newsroom/)
    - [Contact Us](https://thoropass.com/company/contact/)
    - [Trust Center](http://trust.thoropass.com/)
- Platform 
    - [Overview](https://thoropass.com/platform/overview/)
    - [Integrated Security Audit](https://thoropass.com/platform/integrated-security-audit/)
    - [Penetration Testing](https://thoropass.com/platform/penetration-testing/)
    - [Security Questionnaire Tools](https://thoropass.com/platform/security-questionnaire-tools/)
    - [Integrations](https://thoropass.com/platform/integrations/)
    - Legal
    - [MSA](https://thoropass.com/master-subscription-agreement/)
    - [DPA](https://thoropass.com/data-processing-addendum/)
    - [Terms & Conditions](https://thoropass.com/terms-and-conditions/)
    - [Privacy Policy](https://thoropass.com/privacy-policy/)
- Why Thoropass 
    - [Our Difference](https://thoropass.com/advantage/about/)
    - [Meet the Experts](https://thoropass.com/advantage/meet-the-experts/)
    - [Customer Stories](https://thoropass.com/advantage/customer-stories/)
- Learn 
    - [University](https://thoropass.com/learn/laika-university/)
    - [Blog](https://thoropass.com/learn/blog/)
    - [Guides](https://thoropass.com/learn/guides/)

© Copyright 2026 Thoropass, Inc.

**Thoropass is committed to ensuring digital accessibility for people with disabilities.** We are continually improving the user experience for everyone, and applying the relevant accessibility standards.

[![X logo](https://info.thoropass.com/hubfs/X%20logo.svg)](https://twitter.com/thoropass) [![](https://info.thoropass.com/hubfs/Thoropass/Theme%20Assets/SVGs/linkedin-in%201.svg)](https://www.linkedin.com/company/thoropass/) [![](https://info.thoropass.com/hubfs/Thoropass/Theme%20Assets/SVGs/instagram%203.svg)](https://www.instagram.com/thoropass/)