Track: Running the program · Lesson 8 of 10
From readiness to report: the stages of a SOC 2 program
Short answer
A SOC 2 program runs in stages: scope, gap analysis, remediation, policies and evidence, then the audit. For a Type II there is a review period before fieldwork. The platform does most of its work in the middle stages; the auditor owns the last one.
By the SOC 2 Vendor Compare ledger desk · Published 2025-07-29 · Reviewed 2026-09-29 · Editorial assessment
Stage 1: scope
Decide which products, systems and teams are in scope, which trust services categories you need and which report type comes first. Write this down, because every later stage depends on it.
Stage 2: gap analysis
Compare what you do today with the criteria. Platforms help by showing a control library mapped to SOC 2 and running automated tests against connected tools. The gaps become a task list.
Stage 3: remediation, policies and evidence
Fix the gaps, adopt policies, train staff and let the platform collect evidence. This is where integrations save the most time and where AI features such as policy drafting and remediation suggestions are aimed. Where the vendor provides a dedicated expert, this is also where weekly check-ins keep the task list moving.
Stage 4: readiness check
Before booking fieldwork, review the evidence as an auditor would. Some teams use a readiness assessment from their auditor or advisor; some platforms and experts run their own review. Missing evidence found here is cheaper to fix than an exception in the report.
Stage 5: the audit
For a Type I, the auditor tests design as of a date. For a Type II, the review period runs first, and the platform should flag any control that fails during it. The auditor then samples evidence, asks questions and issues the report. Your platform's auditor access and your vendor's audit path, covered in How to choose a SOC 2 auditor, and what the platform's audit path changes, decide how smooth this stage is.
After the report
The report goes to customers under NDA, often through a trust center. Controls keep running, evidence keeps being collected, and the next report period starts. Trust centers and security questionnaires after your SOC 2 report covers the customer-facing side.
Who does what at each stage?
In most programs, your team owns scope and decisions, the platform does control mapping, testing and evidence collection, a vendor expert or partner (where one exists) guides remediation and readiness, and the CPA firm owns the audit. Write the split down at the start so no stage waits on an unclear owner.
What slows programs down?
The common delays are an unclear owner, scope that grows after the gap analysis, evidence that exists only in someone's inbox, and an auditor booked late. Platforms help with the evidence; the other three are decisions. A dedicated expert or partner can keep them on the agenda, which is one reason the expert model carries a high weight on our ledger.