The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Governance & policies
-
Do you have written, approved information-security policies that staff read and acknowledge?
Put your security policies in writing, get leadership to approve them, and have staff acknowledge them. Auditors start here, and so do most readiness gaps.
-
Do you run a documented risk assessment and track the issues it finds to closure?
Run a recurring risk assessment and track remediation. SOC 2 expects you to identify risks and show you act on them.
Access control
-
Is access to systems and data granted by role and reviewed periodically (least privilege)?
Grant access by role, remove what is not needed, and review access lists on a schedule. Document who approved what.
-
Is MFA enforced on production systems, admin accounts and anything internet-facing?
Enforce MFA on admin access and key systems. It is one of the controls auditors check first.
-
Is there a documented process to grant access when people join and revoke it the day they leave?
Document and follow a joiner/leaver process so access is provisioned and removed on time, with a record of each change.
Operations & monitoring
-
Do you collect and review logs and alerts from key systems, with someone responsible for them?
Centralise logs and alerts and make someone accountable for reviewing them. Monitoring evidence is core to SOC 2 Security.
-
Are changes to production reviewed, tested and recorded (change management)?
Use a lightweight change process: review, test and record production changes. The paper trail is the evidence.
-
Are systems backed up and is recovery tested (supporting availability and resilience)?
Automate backups and test recovery. If you scope in Availability, this becomes a graded control.
Vendors & risk
-
Do you track your vendors and subprocessors and review their security (for example their SOC 2 reports)?
Keep a vendor inventory and review the security of any vendor that touches your data, collecting their reports where they have them.
-
Do you have a documented incident-response plan, and have you tested it?
Document an incident-response plan and run a tabletop test. Auditors look for both the plan and proof you exercise it.
People
-
Does staff complete security-awareness training at least once a year?
Run annual (or more frequent) security training and keep completion records as evidence.
-
Could you produce evidence (tickets, logs, approvals, reviews) showing these controls actually operated over the last several months?
Start capturing evidence now. A SOC 2 Type II report covers a period, so controls must be running and documented well before the audit window.
SOC 2 is a project, and we have run it before
Getting audit-ready means closing the gaps above, writing the policies, turning on the controls, and gathering evidence for months before the auditor arrives. We help Canadian businesses get there without derailing the team, then keep the controls running so the next audit is the easy one.