Back to blog
    Playbooks

    Preparing for your first SOC 2 Type II

    A 12-week readiness plan covering evidence, sampling windows, and the questions auditors will actually ask.

    Andreas Van Nimmen Mar 14, 2026 9 min readLast verified Mar 14, 2026

    A first SOC 2 Type II typically takes 12 weeks of focused readiness work before fieldwork begins, followed by a 3–12 month observation window during which the auditor will test that your controls operated effectively. Get the readiness phase right and the rest of the engagement is largely mechanical. Get it wrong and you'll be remediating in real time while the clock is running.

    Weeks 1–3: scoping and gap assessment

    Decide which Trust Services Criteria you're committing to (Security is mandatory; most SaaS companies add Availability and Confidentiality). Inventory every system that touches customer data: production, staging, identity providers, support tooling, the lot. Run a gap assessment against the relevant controls and produce a remediation backlog ranked by effort and risk.

    Weeks 4–8: control implementation

    This is where most of the real work happens. Common gaps include formal access reviews (quarterly, with evidence), vendor risk reviews, incident response runbooks that have actually been exercised, secure SDLC controls (code review enforcement, dependency scanning), and HR controls around onboarding/offboarding. If you're using a compliance automation platform, this is when you wire up the integrations and start collecting evidence automatically.

    Weeks 9–11: policy refresh and tabletop exercises

    Your information security policy, acceptable use policy, incident response plan, and business continuity plan all need to be current, board-approved (or equivalent), and demonstrably communicated to employees. Run at least one incident response tabletop and one BCP exercise. Auditors will ask for evidence that these aren't just documents.

    Week 12: pre-audit dry run

    Walk through the auditor's expected request list with whoever will own evidence delivery internally. Pull sample evidence for every control and confirm it would satisfy a skeptical reviewer. Identify the two or three controls most likely to generate findings and decide in advance how you'll respond. By the time fieldwork starts, there should be no surprises. Just execution.

    Frequently asked questions

    How long does SOC 2 Type II readiness take before fieldwork begins?
    A first SOC 2 Type II typically takes 12 weeks of focused readiness work before fieldwork begins. That includes scoping, gap assessment, control implementation, policy refresh, and a pre-audit dry run.
    What is the observation window in a SOC 2 Type II audit?
    After readiness, the auditor tests that your controls operated effectively over a period, usually 3, 6, or 12 months. This observation window is separate from the 12-week readiness phase.
    What happens if a control fails during the observation window?
    A good readiness plan identifies the two or three controls most likely to generate findings before fieldwork starts. Ask your auditor upfront whether you get a chance to remediate a failing control or whether it lands in the report.
    What is the biggest readiness risk in a first SOC 2 Type II?
    Trying to remediate while the observation clock is running. Get the 12-week readiness phase right and the rest of the engagement is largely mechanical; get it wrong and you'll be fixing gaps while the auditor is already testing.
    What should be ready before the auditor starts fieldwork?
    By the end of the 12-week plan, you should have completed a gap assessment, implemented controls, refreshed policies, run tabletop exercises, and done a dry run of the auditor's evidence request list. There should be no surprises by the time fieldwork starts.

    Ready to find your auditor?

    Browse independent firms or post a bid request and let qualified auditors come to you.