UprootSecurity
Book a demo
Checklist47 controls · 8 sectionsNo email required

The SOC 2 readiness checklist

All 47 controls, the evidence each one needs, and the system that owns it. Check items off as you close them, assign an owner to every gap, and watch readiness climb — your progress saves to this browser. Export to CSV, copy to Notion, or print the whole thing.

0%ready
0 of 47 controls complete47 to go
ControlCriterionEvidence path · owner
  • Enforce MFA on production access
    CC6.1
    okta.mfa.state
  • Unique IDs — no shared accounts
    CC6.1
    okta.users.unique
  • SSO enforced for critical apps
    CC6.1
    okta.sso.coverage
  • Least-privilege IAM roles defined
    CC6.3
    aws.iam.policies
  • Quarterly access review completed
    CC6.3
    jira.access_review
  • Offboarding revokes access < 24h
    CC6.2
    okta.deprovision.log
  • Privileged access approved & logged
    CC6.1
    aws.access_analyzer
  • Password policy meets baseline
    CC6.1
    okta.password_policy
  • Service accounts inventoried & rotated
    CC6.1
    secrets.rotation_log
ControlCriterionEvidence path · owner
  • PR approval required on main
    CC8.1
    github.branch_protection
  • Separate production deploy approval
    CC8.1
    github.environments
  • CI runs tests before merge
    CC8.1
    github.actions.status
  • Infrastructure changes via IaC
    CC8.1
    terraform.plan_log
  • Change tickets link to deploys
    CC8.1
    linear.deploy_refs
  • Rollback procedure documented
    CC8.1
    runbook.rollback
ControlCriterionEvidence path · owner
  • Encrypt data at rest (KMS-managed)
    CC6.7
    aws.kms.keys
  • Encrypt data in transit (TLS 1.2+)
    CC6.7
    aws.elb.tls_policy
  • Automatic key rotation enabled
    CC6.7
    aws.kms.rotation
  • Data classification policy in place
    C1.1
    policy.data_classification
  • Backups encrypted & restore-tested
    A1.2
    aws.backup.restore_test
  • Secrets stored in a managed vault
    CC6.7
    vault.secrets.inventory
  • Data retention & disposal enforced
    C1.2
    s3.lifecycle_rules
ControlCriterionEvidence path · owner
  • Network segmented (VPC, subnets)
    CC6.6
    aws.vpc.topology
  • Security groups least-open
    CC6.6
    aws.sg.rules
  • WAF / edge protection enabled
    CC6.6
    aws.waf.rules
  • Vulnerability scanning on hosts
    CC7.1
    scanner.findings
  • Endpoints managed (MDM)
    CC6.7
    jamf.device_state
  • Patch SLA enforced
    CC7.1
    patch.compliance
ControlCriterionEvidence path · owner
  • Centralized audit logging enabled
    CC7.2
    cloudtrail.enabled
  • Log retention ≥ 1 year
    CC7.2
    cloudwatch.retention
  • Alerting on security events
    CC7.2
    datadog.monitors
  • Anomaly / intrusion detection
    CC7.2
    guardduty.findings
  • Log integrity protected
    CC7.2
    cloudtrail.log_validation
ControlCriterionEvidence path · owner
  • Documented incident runbook
    CC7.4
    pagerduty.runbook
  • On-call & escalation defined
    CC7.4
    pagerduty.schedules
  • Postmortems for SEV-1/2
    CC7.5
    incident.postmortems
  • Breach notification process
    CC7.3
    policy.breach_notification
ControlCriterionEvidence path · owner
  • Vendor risk assessment on file
    CC9.1
    vendor.risk_scores
  • Vendor inventory maintained
    CC9.2
    vendor.registry
  • DPAs / BAAs signed & stored
    CC9.2
    vendor.agreements
  • Annual risk assessment performed
    CC3.1
    risk.assessment_log
  • Subprocessor list published
    CC9.2
    trust.subprocessors
ControlCriterionEvidence path · owner
  • Security policies approved annually
    CC1.1
    policy.registry
  • Security awareness training done
    CC1.4
    hris.training_log
  • Background checks on hire
    CC1.4
    hris.bgcheck
  • Code of conduct acknowledged
    CC1.1
    hris.policy_ack
  • Org chart & roles defined
    CC1.3
    hris.org_chart

A practical 47-control set covering the Security criterion in full plus common Availability and Confidentiality additions. Evidence paths show the typical system of record — provider-agnostic by intent. This is a readiness aid, not a substitute for your auditor's control matrix.

Stop checking boxes by hand

Every evidence path in this checklist is something Uproot can watch for you — pulling the live state from AWS, Okta, and GitHub every fifteen minutes and flagging the moment a control drifts. The checklist becomes a dashboard, not a quarterly fire drill.

See my live postureEstimate my timeline