SOC 2 Readiness Checklist
65 controls across Access, Infrastructure, Change Management, Policies, and more. Tick off what's done. 37 require continuous evidence collection — the hardest part to do manually. TrailProof automates those. The rest are one-time HR, policy, and process tasks. Progress saves in your browser.
Optimised for AWS-based startups · covers IAM, S3, RDS, CloudTrail, GuardDuty, VPC, GitHub, Google Workspace and Okta
0
Complete
65
Remaining
37
Need monitoring
Access Control
· 10 automatedMonitoring & Detection
· 6 automatedInfrastructure Security
· 11 automatedChange Management
· 4 automatedData Protection
· 1 automatedRisk Management
Policies & Governance
· 5 automatedHR & Training
Get the free SOC 2 Preparation Guide
8–10 pages covering Type I vs Type II, picking an auditor, the evidence you need, the biggest mistakes startups make, and a 90-day action plan. Free, no strings.
37 controls need continuous evidence collection
These are the ones auditors spend the most time on — infrastructure configuration, access logs, encryption state, branch protection. They change constantly and need to be re-evidenced for every audit period. TrailProof monitors them automatically across AWS, GitHub, Google Workspace and Okta, and AI writes the executive summary and all 8 policy documents.
TrailProof · SOC 2 evidence automation · trailproof.app