SOC 2 / ISO 27001 Readiness Checklist
Prepare for compliance audits with a structured gap assessment.
Critical items (marked ★) carry higher weight. This checklist covers 40 controls across 8 domains aligned to SOC 2 Trust Services Criteria and ISO 27001 Annex A. Address critical gaps first to avoid major audit findings.
Governance & Policy
Establish the policy framework that underpins all controls.
Access Control
Ensure only authorised individuals access systems and data.
Change Management
Control changes to systems to prevent unauthorised or disruptive modifications.
Incident Management
Detect, respond to, and learn from security incidents.
Business Continuity
Ensure critical services can continue or recover during disruptions.
Monitoring & Audit
Maintain visibility into security posture through logging, monitoring, and audit.
Physical & Environmental
Protect physical assets and environments housing information systems.
People & Training
Ensure personnel understand and fulfil their security responsibilities.