Free resource
Readiness against the AICPA Trust Services Criteria: the mandatory Common Criteria (Security) plus optional Availability, Confidentiality, Processing Integrity and Privacy. Covers Type I vs Type II and the operating-over-time evidence a service auditor actually tests.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A readiness check against the AICPA Trust Services Criteria (TSC). Security (the Common Criteria) is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are included only if you commit to them. It shows where a service auditor will push before the examination. |
| How to score | Yes = in place and you can show the evidence today. Partly = it exists but is incomplete, informal or unevidenced. No = not in place. Only a clear Yes counts when it is audited. |
| Type I vs Type II | Type I tests whether controls are designed correctly at a point in time. Type II tests whether they operated effectively over a period (typically 3-12 months). Type II is what buyers actually want - so evidence must exist across the whole period, not just on audit day. |
| ISO 27001 gives you a head start | If you run an ISO 27001 ISMS, most of the Common Criteria are already covered - access, change, incident and vendor controls map across. SOC 2 adds the AICPA reporting model and the operating-over-time evidence burden. |
Sheet: SOC 2 Readiness
Score each item. The Common Criteria (Security) are mandatory; the other categories apply only if in your scope. The middle columns show what a pass looks like and the failure service auditors see most.
| Criteria area | Check item | What good looks like | Most common failure (the red flag) | Status (Yes / Partly / No) | Owner | Evidence / gap |
|---|---|---|---|---|---|---|
| Scope & report type | The report type (Type I or Type II), TSC categories and the review period are decided | A defined scope: Security plus any of Availability / Confidentiality / Processing Integrity / Privacy, and a Type II period | Starting the audit before deciding scope, then discovering the period has no evidence | - | - | - |
| CC1 - Control environment | Governance, org structure, and security roles and responsibilities are defined | An org chart, defined security ownership, and board/management oversight of security | Security 'owned by everyone', so owned by no one | - | - | - |
| CC2 - Communication & information | Policies are documented, communicated, and staff acknowledge them | A policy set staff have read and signed, plus internal security comms | Policies that exist in a drawer and no one has seen | - | - | - |
| CC3 - Risk assessment | A risk assessment identifies and addresses risks to the service commitments | A documented, periodically-refreshed risk assessment feeding a treatment plan | A risk register created once for the audit and never revisited | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources