PW-SOC2-002 SOC 2 readiness spoke
90-day SOC 2 Type 1 checklist for SaaS founders
TL;DR. In 90 days most seed SaaS teams can scope Common Criteria, assign control owners, stand up MFA and access reviews, collect a starter evidence pack, pick an auditor, and complete Type 1 fieldwork—if leadership treats readiness as a weekly operating rhythm, not a side quest.
Days 1–30 — Scope and owners
- Write a one-page system description: product, data classes, hosting, subprocessors.
- Choose Trust Services Categories (usually Security only for first Type 1).
- Name a control owner per domain: identity, change, vendors, HR/security awareness, incidents.
- Inventory systems in scope (IdP, cloud, code host, ticketing, laptop management).
- Shortlist auditors; request sample engagement letters.
Days 31–60 — Operate the basics
- Enforce MFA on production and corporate identity; document exceptions.
- Run a full access review for in-scope systems; ticket removals.
- Publish policies that match reality (security, access, change, incident, vendor).
- Stand up vulnerability intake and patch SLAs you can keep.
- Start weekly evidence pulls into a named folder or GRC tool.
Days 61–90 — Auditor and fieldwork
- Sign engagement letter; freeze scope.
- Complete readiness self-check against your control list.
- Respond to PBC (provided-by-client) lists within SLA.
- Close gaps before opinion date; schedule report delivery for procurement.
If you miss a week, slide the calendar—do not compress evidence into a heroic weekend. Auditors sample operating rhythm.
Questions founders ask
Do we need a GRC tool in the first 90 days?
Not strictly. You need owners, evidence, and an auditor. Tools help when integrations save weekly hours.
Who should own the checklist?
A single accountable lead (often a founder or Head of Eng) with named control owners.
What if we miss day 90?
Extend honestly. Do not fabricate operating history.