A structured Word document mapping all 33 Common Criteria controls across CC1-CC9 to their evidence requirements. Includes a Readiness Summary Scorecard, Required Policy Library tracker, and Gap Remediation table. Know exactly where you stand before the observation period starts.
33
controls mapped
9
CC categories
15
policies tracked
.docx
editable format
What Is Included
Cover page with document control fields and status legend (NS / IP / Done / N/A)
Readiness Summary Scorecard: count of controls by status with overall readiness percentage
Checklist tables for all 9 CC categories with evidence requirements per control
Required Policy Library tracker: 15 policies with approval status and date fields
Gap Remediation tracker: 8 pre-built entries for the most common SOC 2 gaps
All bracketed placeholders for organization name, dates, and owner assignments
Notes column in every table for capturing auditor questions or evidence locations
US Letter format, professional layout with header and page numbers
Common Criteria Coverage
CC1Control Environment (5 controls)
CC2Communication & Information (3 controls)
CC3Risk Assessment (4 controls)
CC4Monitoring Activities (2 controls)
CC5Control Activities (3 controls)
CC6Logical & Physical Access (8 controls)
CC7System Operations (5 controls)
CC8Change Management (1 control)
CC9Risk Mitigation & Vendors (2 controls)
Evidence Requirements per Control
Each control row includes a specific evidence column describing what auditors typically request. For example:
CC6.1MFA configuration screenshots; SSO setup documentation; access control policy with formal approval
CC6.3Quarterly access review sign-off records; termination date vs. account deactivation date logs; offboarding checklists
CC7.2SIEM or log management configuration; alert history export; documented evidence of log review activities
CC8.1Change request records showing approval before deployment; QA sign-off; pull request review history or deployment logs
CC9.2Vendor inventory; completed vendor risk questionnaires; vendor contracts with security terms; SOC 2 reports from critical vendors
Who Needs This
This checklist is built for:
SaaS companies beginning their first SOC 2 Type II engagement
IT managers or security leads who need to understand their gap posture before engaging an auditor
MSPs helping clients assess SOC 2 readiness
Startups that received a SOC 2 questionnaire from an enterprise prospect and need to understand what it takes
Organizations with an upcoming observation period start date who want to confirm controls are in place
Frequently Asked Questions
The checklist covers all nine Common Criteria categories: CC1 (Control Environment), CC2 (Communication and Information), CC3 (Risk Assessment), CC4 (Monitoring Activities), CC5 (Control Activities), CC6 (Logical and Physical Access Controls), CC7 (System Operations), CC8 (Change Management), and CC9 (Risk Mitigation and Vendor Management). All 33 individual controls across these nine categories are included with evidence requirements.
A SOC 2 Type I report covers the design of your controls at a single point in time. A Type II report covers both design and operating effectiveness over an observation period, typically 6 to 12 months. Enterprise customers and procurement teams almost universally require Type II. This checklist is structured for Type II readiness: confirming that controls are designed correctly AND that you are generating evidence of ongoing operation.
The checklist includes a Required Policy Library tracker covering 15 policies: Information Security Policy, Access Control Policy, Acceptable Use Policy, Change Management Policy, Incident Response Plan, Risk Assessment Policy, Business Continuity Plan, Disaster Recovery Plan, Vendor Management Policy, Data Classification Policy, Password and Authentication Policy, Encryption Policy, and others. Each must be formally approved, dated, and acknowledged by relevant staff.
A typical timeline is 12 to 18 months from start to finished report. Readiness and gap remediation typically take 2 to 4 months, followed by a 6 to 12 month observation period, then 2 to 3 months for fieldwork and report issuance. Starting the readiness process now means your controls will be operating before the observation period begins, which is what drives the timeline forward.
The Gap Remediation table includes 8 pre-built rows covering the most common SOC 2 gaps: access review process, offboarding deprovisioning timelines, vendor assessment coverage, MFA enrollment, log review evidence, change approval records, policy acknowledgment tracking, and vulnerability scan remediation. For each gap you document current state, target state, owner, and target date. This gives auditors visibility into how you are managing identified weaknesses.