simpl.
Cybersecurity GRC 22 items

SOC 2 Trust Services Criteria Readiness Assessment

Evaluates readiness for a SOC 2 Type II examination across the AICPA Common Criteria and the Availability and Confidentiality categories.

SOC 2AICPA TSC

Free PDF · enter your email to download.

Control Environment (CC1)

  • Is there a documented code of conduct that all personnel acknowledge? *
  • Does the board or an equivalent oversight body operate independently of management and review security matters? *
  • Are organizational structures, reporting lines, and authorities documented? *
  • Are background checks performed on new hires prior to granting system access? *
  • Are individuals held accountable for internal control responsibilities through performance evaluations? *

Communication & Information (CC2)

  • Are security commitments and system requirements communicated to internal users? *
  • Are security responsibilities communicated to external users, vendors, and partners? *
  • Is there a defined channel for personnel to report security issues or control failures? *

Risk Assessment (CC3)

  • Are specific, measurable security objectives defined for the system? *
  • Is a formal risk assessment performed at least annually to identify threats to objectives? *
  • Is the potential for fraud considered when assessing risks? *
  • Are changes that could significantly affect the system of internal control identified and assessed? *

Monitoring Activities (CC4)

  • Are ongoing and separate evaluations performed to verify controls are operating? *
  • Are identified control deficiencies communicated to parties responsible for corrective action? *
  • When was the most recent internal control self-assessment completed?

Control Activities & Availability (CC5, A1)

  • Are control activities selected and developed to mitigate risks to acceptable levels? *
  • Are technology general controls over infrastructure implemented? *
  • Is capacity monitored and forecast to meet availability commitments? *
  • Are environmental protections, backups, and recovery infrastructure maintained and tested? *
  • Are recovery plan procedures tested to meet availability objectives? *

Confidentiality (C1)

  • Is confidential information identified and maintained per commitments and requirements? *
  • Is confidential information disposed of securely when no longer required? *

Download the full SOC 2 Trust Services Criteria Readiness Assessment checklist

Get it as a clean, printable PDF — free.