On this page
- First SOC 2 audit: the six phase gates
- Phase 1: Define the report decision
- Phase 2: Turn scope into owned work
- Phase 3: Establish the evidence path
- Phase 4: Operate controls and review exceptions
- Phase 5: Select and brief the CPA firm
- Phase 6: Freeze the fieldwork package
- What to do when a gate is blocked
- Before you ask the CPA firm to start fieldwork
Preparing for your first SOC 2 audit means turning a customer requirement into a controlled project: make the report decision, assign each control and evidence path to an owner, then give the CPA firm a stable system description and evidence package. Treat each phase as a gate. Do not move forward because a policy exists; move forward when someone can show the agreed artifact and pass the acceptance test.
The AICPA’s Trust Services Criteria are the criteria a SOC 2 examination evaluates for Security, Availability, Processing Integrity, Confidentiality, and Privacy. The SOC 2 Description Criteria guide management’s description of the system. They are starting points for your program, not a generic list of software settings to copy.
This page is the runbook. Use the SOC 2 compliance checklist for the complete task list, the readiness assessment guide to diagnose gaps, the SOC 2 controls list for criterion-level control and evidence examples, and the SOC 2 timeline guide when you need to back-plan a buyer deadline.
First SOC 2 audit: the six phase gates
Each phase ends with an artifact another person can inspect. The handoff happens only after the exit gate passes:
- Report decision
- Owner/decision: Executive sponsor approves the buyer requirement, report type, scope, and criteria.
- Exit gate: A reader can name the service, boundary, criteria, intended report, and decision owner in the scope statement and decision register. A changing boundary blocks the phase.
- Handoff: Readiness owner.
- Owned work
- Owner/decision: Compliance lead assigns every readiness finding to a control owner.
- Exit gate: The remediation plan gives each open item an owner, decision date, and acceptance test. Unowned gaps block the phase.
- Handoff: Control owners.
- Evidence path
- Owner/decision: Control owner decides how the procedure creates and stores evidence.
- Exit gate: A second person can use the control-to-evidence map to retrieve a dated example without relying on memory. Missing lineage blocks operating-period planning.
- Handoff: Evidence coordinator.
- Control operation
- Owner/decision: Control owners perform the approved procedures and log exceptions.
- Exit gate: The evidence index covers the agreed period, and each exception has an outcome or open-owner record.
- Handoff: CPA-firm selection and briefing.
- CPA-firm briefing
- Owner/decision: Executive sponsor selects an independent licensed CPA firm against a common scope.
- Exit gate: The signed engagement and briefing package use the report, boundary, criteria, dates, and deliverables the team approved. Scope ambiguity blocks fieldwork scheduling.
- Handoff: Fieldwork coordinator.
- Fieldwork package
- Owner/decision: Management approves the system description, control matrix, and request process.
- Exit gate: The CPA firm’s opening requests can be routed from the versioned package to named people and sources. Material open changes require a scope conversation.
- Handoff: CPA fieldwork.
Phase 1: Define the report decision
Start with the customer or contract requirement, not a tool purchase. Record what the buyer asked for, whether they require a Type 1 report or a Type 2 report over a specified period, and which Trust Services Criteria are relevant to the commitments you make. Keep the system boundary specific enough that the people doing the work know what is in it and what is not.
The output is a one-page scope statement. It should name the service, systems, data categories, people or teams with responsibilities, subservice organizations, criteria in scope, report type, target audience, and accountable executive. The AICPA Description Criteria are useful here because a SOC 2 report includes management’s description of the system, not only a list of controls.
Do not treat a buyer deadline as proof that the scope is settled. If a buyer’s request is unclear, get the requirement in writing before committing the report type or observation-period plan. Use the timeline guide for the calendar decisions that follow.
Phase 2: Turn scope into owned work
Run a readiness assessment against the agreed scope, then convert each finding into a small piece of owned work. The assessment is not the deliverable; the decision to accept, remediate, redesign, or exclude a finding is.
Use the readiness assessment guide for the gap-analysis method. Keep this page’s project record compact:
- Decision: The choice made, such as a system’s inclusion in scope or a control design.
- Why: The buyer requirement, risk, or criterion connection that supports the choice.
- Accountable owner: The person who can approve the decision or remove the blocker.
- Due condition: The evidence or acceptance test that closes the item; use a date only when your project has one.
- Open consequence: What cannot proceed while the item remains unresolved.
This register prevents a common first-audit failure: a team remembers why it made a choice until the reviewer, system, or buyer changes. It also gives the CPA firm a short, honest record of decisions that affect the report boundary.
Phase 3: Establish the evidence path
For each in-scope control, decide before fieldwork how it will produce evidence of operation. A policy may explain the rule; the evidence path shows how a reviewer can trace the rule to a performed procedure and a dated record. The Trust Services Criteria evaluate controls against the applicable criteria, while the specific evidence request and sampling approach remain the CPA firm’s responsibility. The AICPA’s March 2026 software-tools FAQ also makes completeness, accuracy, auditor responsibilities, and independence explicit when software tools produce or process evidence.
An evidence-lineage record can be simple:
- Control and procedure: What must happen, and who performs it?
- Source system or repository: Where does the original record live?
- Evidence object: Which dated export, ticket, approval, log, or record demonstrates the procedure?
- Coverage and retrieval: Which period does it cover, and can a backup person retrieve it?
- Review and exception trail: Who reviewed it, and where are exceptions and remediation recorded?
Test the path with someone other than the control owner. If they cannot retrieve an example, the process depends on memory rather than a usable record. For detailed control-to-evidence examples, use the SOC 2 controls list.
Phase 4: Operate controls and review exceptions
Once the scope and procedures are approved, run them as written. Preserve the source records, link them in the evidence index, and record changes that affect the boundary, procedure, or evidence source. A Type 2 report addresses control operation over a specified period, so the team and CPA firm must agree on the period and what evidence will be available for it; this is not a universal calendar you can copy from another company.
Review exceptions as work items. Record what happened, whether the control still met its objective, what was changed, who owns the follow-up, and what evidence supports that conclusion. Do not delete inconvenient records or fill a gap with a freshly created document. If a control was changed, tell the CPA firm early enough to decide how it affects the engagement.
The exit artifact is an evidence index that points to original records and an exception log that separates resolved items from open ones. The SOC 2 Type 2 controls guide covers operating-effectiveness evidence in more detail.
Phase 5: Select and brief the CPA firm
Compare proposals against the same written brief: report type, intended period, system boundary, Trust Services Criteria, entities and locations, readiness status, expected deliverables, and any work excluded from the fee. A lower number is not comparable if it describes a different engagement.
The selected firm must be independent and licensed to issue the report. Read the auditor selection guide for the full comparison process. Before kickoff, give the firm the scope statement, decision register, current system description draft, control matrix, known exceptions, and a contact list. Ask which questions remain open and who must answer them.
If you want proposals based on one consistent scope, compare scoped SOC 2 audit quotes. The directory returns available matches and quotes based on fit; it does not promise a fixed number of firms.
Phase 6: Freeze the fieldwork package
The fieldwork package is the handoff from the operating team to the CPA firm’s request process. It normally includes the approved system description, control matrix, evidence index, exception log, organizational contacts, and the engagement’s agreed scope. Version each document so the team can tell which description and control design the auditor received.
The system description deserves its own approval step. It should describe the system management says it operates, within the report boundary, rather than repeat generic policy language. Compare it against the AICPA Description Criteria and reconcile it with the control matrix before fieldwork begins.
Set one request coordinator, one source of truth for evidence links, and a way to route CPA questions to the right control owner. If a material system, scope, or procedure change is underway, make that visible instead of quietly updating a document after the fact. The CPA firm can then decide whether it needs more evidence, a revised description, or a changed plan.
What to do when a gate is blocked
Do not solve a blocked gate by widening the project or collecting more documents at random. Name the blocker, its accountable owner, the decision needed, and the next review point in the decision register. The usual categories are a moving scope, an unowned control, an untested evidence path, an exception without a conclusion, or a CPA engagement that does not match the approved brief.
That record gives the team a practical answer to “what is stopping fieldwork?” and gives a new project owner enough context to continue without reconstructing the program from meeting notes.
Before you ask the CPA firm to start fieldwork
Confirm that you can hand over:
- a stable scope statement and decision register;
- a control matrix with accountable owners and procedure references;
- an evidence index that points to original, dated records;
- an exception log with open owners and resolutions;
- a system description aligned to the actual boundary; and
- a contact and request-routing plan.
For the detailed preparation tasks behind those artifacts, return to the SOC 2 compliance checklist. For a project schedule, use the SOC 2 timeline guide. Those pages own the depth; this runbook tells you when each body of work is ready to hand off.