Skip to content
Ridgeline Compliance
Read this first. We are not a CPA firm, so we provide SOC 2 readiness, gap analysis and preparation consulting only. The formal SOC 2 examination and report are performed by a separate, licensed, independent CPA firm.

Guide

A SOC 2 controls list in plain words

There is no official SOC 2 controls list. Instead, the AICPA publishes criteria, and each company designs controls to meet them. So the list below shows the controls most companies end up with, grouped by criteria.

  • Readiness, not the audit
  • An independent CPA firm signs
  • Written estimate, no call
Soc 2 controls list: read the criteria, choose controls and keep evidence

Why there is no fixed SOC 2 controls list

The AICPA Trust Services Criteria describe outcomes, not tools. Therefore a startup and a bank can meet the same criterion in very different ways. Your controls must fit your size, but also prove the outcome.

A typical SOC 2 controls list by Common Criteria

Security-only scopes are built on the Common Criteria, numbered CC1 to CC9.

CriteriaTypical controls
CC1 to CC2 governanceCode of conduct, org chart, security roles.
CC3 risk assessmentAnnual risk assessment, so threats are recorded.
CC5 control activitiesApproved policies and procedures.
CC6 accessUnique accounts, MFA, access reviews, offboarding.
CC7 operationsLogging, monitoring and incident response.
CC8 changeReviewed and approved changes.
CC9 risk mitigationVendor reviews and business continuity.

Check your SOC 2 controls list

Tick the controls you run and can prove.

Your result appears here as you tick, so you can see what is still open.

Evidence for each control

Every control needs proof that it ran. For example, an access review needs a dated record, while change management needs approved pull requests. So design controls that leave evidence naturally.

Extra controls for extra criteria

Availability adds backup, recovery and capacity controls. Confidentiality adds classification and disposal. However, only add them if a customer asked, because each adds cost.

Turning a SOC 2 controls list into readiness

A list is a start, but the work is matching it to your stack and closing gaps. That is what our readiness engagement does, at a fixed fee of $5,000 to $40,000. We are not a CPA firm, so the examination is separate.

Also remember that controls overlap. For example, a single onboarding checklist can support access, training and asset controls at once, so one good process often satisfies several criteria. That keeps the list shorter and the evidence easier to collect.

SOC 2 controls list questions

How many controls are on a typical SOC 2 controls list?

Often 60 to 120, depending on scope and how controls are grouped.

Is there an official AICPA controls list?

No. The AICPA publishes criteria, so each company designs its own controls.

Can we download a SOC 2 controls list?

Templates exist. However, adapt them, because the auditor tests what you claim.

Do tools generate the controls?

Platforms suggest controls and gather evidence, but you still design and run them.

Related guides

Turn the SOC 2 controls list into your controls

Tell us your stack and criteria. We reply with a written scope and a fixed fee.

See if we can help