Skip to content
One Circle Solutions

Guide · 12 min read

SOC 2 readiness: what the first 90 days actually look like

A realistic sequencing of scoping, gap assessment, and evidence collection — and where teams most often lose a quarter.

By One Circle Solutions · Published

SOC 2 timelines slip for predictable reasons: scope creep, policies written before anyone knows what they should cover, and evidence collection left for the month before the audit. Here's the sequencing that actually works, based on taking real companies through it.

Days 1–30: scope before anything else

The single biggest cost driver in SOC 2 is scope. Before writing a single policy, decide: which product or platform is in scope, which Trust Services Criteria you're pursuing (start with Security alone unless customers demand more), and which systems actually touch customer data.

  • Inventory the systems in the audit boundary — production, CI/CD, identity, ticketing
  • Choose Type I vs Type II deliberately: Type I proves design at a point in time; Type II proves operation over a window
  • Run a gap assessment against the criteria — this becomes your entire roadmap
  • Pick your audit firm now; good ones book out months ahead

Days 31–60: close the gaps that take calendar time

Some controls can be implemented in an afternoon; others need weeks of runway before an auditor can observe them operating. Start the slow ones first.

  • Access reviews: run the first one now — a Type II needs evidence of them happening on schedule
  • Onboarding/offboarding checklists with evidence they're followed
  • Vendor risk review process, applied to your critical vendors
  • Monitoring and alerting with response records — auditors ask what fired and what you did
  • Policies written to match reality, not templates describing a company you aren't

Days 61–90: make evidence automatic

Teams that suffer during audits are the ones collecting evidence by hand in the final month. Wire evidence into the tools you already use: tickets for access requests, PRs for change management, alert records for monitoring. If a control operates without leaving a trail, fix the trail now.

By day 90 you should have: a signed audit engagement, every gap either closed or scheduled, and evidence accumulating automatically. That's what 'ready' means — not a binder, but an operation that produces proof as it runs.

Where the quarter gets lost

  • Writing policies before scoping (they'll all be rewritten)
  • Buying a compliance platform and assuming it closes gaps by existing
  • Letting engineering treat audit tickets as optional until the deadline panic
  • Starting the Type II observation window before controls are actually operating

Want a practitioner's take on your situation?

Book a no-obligation consultation. We'll review your coverage and obligations, and you'll leave with a written findings brief either way.