Generate a detailed SOC2 Type II compliance checklist with control mappings, evidence requirements, and gap analysis.
You are a compliance and security auditor. Generate a comprehensive SOC2 Type II audit checklist. ## Organization Details - **Company Type**: [COMPANY e.g. SaaS startup / fintech / healthcare IT / cloud provider] - **Trust Service Criteria**: [TSC e.g. Security, Availability, Confidentiality, Processing Integrity, Privacy] - **Cloud Provider**: [CLOUD e.g. AWS / Azure / GCP / multi-cloud] - **Team Size**: [SIZE e.g. 20 / 100 / 500] - **Current Maturity**: [MATURITY e.g. no formal controls / basic / intermediate] ## Checklist Sections ### CC1: Control Environment - [ ] Board/management commitment to security documented - [ ] Organizational structure with security responsibilities - [ ] Code of conduct and ethics policy - [ ] Background checks for employees - [ ] Security awareness training program (annual + onboarding) - [ ] Competency requirements for security roles - **Evidence needed**: Org chart, policies, training records, background check process ### CC2: Communication and Information - [ ] Information security policy published and acknowledged - [ ] Acceptable use policy - [ ] Internal communication of security responsibilities - [ ] External communication process for security incidents - [ ] Third-party communication protocols - **Evidence needed**: Policies with sign-off, communication templates, incident notification process ### CC3: Risk Assessment - [ ] Annual risk assessment process - [ ] Risk register with likelihood and impact ratings - [ ] Third-party/vendor risk assessments - [ ] Risk treatment plans with owners and timelines - [ ] Fraud risk consideration - **Evidence needed**: Risk assessment reports, risk register, vendor assessments ### CC4: Monitoring Activities - [ ] Continuous monitoring of security controls - [ ] Internal audit program - [ ] Vulnerability management program - [ ] Penetration testing (annual minimum) - [ ] Management review of control effectiveness - **Evidence needed**: Monitoring dashboards, audit reports, pentest reports, review minutes ### CC5: Control Activities - [ ] Logical access controls (RBAC, least privilege) - [ ] Change management process - [ ] System development lifecycle (SDLC) with security gates - [ ] Configuration management standards - [ ] Data backup and recovery procedures - **Evidence needed**: Access reviews, change tickets, SDLC docs, backup logs ### CC6: Logical and Physical Access Controls - [ ] Multi-factor authentication for all remote access - [ ] Password policy (length, complexity, rotation) - [ ] Quarterly access reviews - [ ] Privileged access management - [ ] Physical security for offices/data centers - [ ] Visitor management - [ ] Network segmentation - **Evidence needed**: MFA configuration, access review reports, PAM logs, physical access logs ### CC7: System Operations - [ ] Incident response plan tested annually - [ ] Security event monitoring and alerting - [ ] Vulnerability scanning (weekly minimum) - [ ] Patch management within defined SLAs - [ ] Endpoint protection on all devices - [ ] Data loss prevention controls - **Evidence needed**: IR plan, SIEM alerts, scan reports, patch records, EDR deployment ### CC8: Change Management - [ ] Formal change request and approval process - [ ] Separation of duties (dev/staging/prod) - [ ] Code review requirements - [ ] Rollback procedures - [ ] Emergency change process - **Evidence needed**: Change tickets, approval workflows, deployment logs ### CC9: Risk Mitigation - [ ] Vendor management program - [ ] Business associate agreements - [ ] SLA monitoring for critical vendors - [ ] Vendor security assessment process - **Evidence needed**: Vendor list, BAAs/DPAs, SLA reports, assessment results ## Gap Analysis For each control, assess: - Current state: Implemented / Partial / Not Implemented - Gap description and remediation steps - Effort estimate: Low / Medium / High - Priority: P1 / P2 / P3 - Owner assignment - Target completion date Generate the complete checklist tailored to [COMPANY] with specific guidance for [CLOUD] environment.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro.
Fill in your organization details and select applicable Trust Service Criteria. Work through each section marking current state. Use the gap analysis to create a remediation roadmap with your security team.
Initial release
Sign in and download this prompt to leave a review.