Asteros SOC 2 Readiness Toolkit

The 33 Security criteria in plain English, a risk register, and a vendor review workflow. Built to sit beside the SOC 2 Readiness Guide.

You need policies and controls. Policies set the rules, controls put them into practice, and evidence shows the controls operate.

These are criteria, not a prescribed list of controls. Your controls, and the evidence you retain, are based on what is in scope for your environment: your systems, relevant risks, existing processes, and resources.

Start here

  1. Define your system boundary: the services, data, and infrastructure in scope.
  2. Readiness Checklist. Read each criterion, what it looks like in practice, and the evidence to collect. Set Status to In Progress while you gather evidence and Implemented once it is stored. Use N/A only for criteria outside your system boundary. N/A is not complete.
  3. Risk Register. Add the gaps you care about. Score Likelihood and Impact from 1 to 5. Critical 20-25, High 15-19, Medium 8-14, Low 1-7. Give every open risk an owner and a date. Starter ideas live in Risk Examples, which is a separate database and never counted. Copy a row over only if it applies to you.
  4. Vendors. Use SOC 2 Report Review when a vendor will share its report: record the type, period, opinion (Unmodified, Qualified, Adverse, or Disclaimer), and CPA firm. Use Vendor DDQ and DDQ Questions when there is no report to review. Rows with status Example are starters and are never counted; replace them.
  5. Link evidence as you go. The Evidence link column on the checklist is what a reviewer will ask for.

This toolkit organizes readiness work. It does not decide whether an auditor will accept a particular control or evidence set.

Status values

What a reviewer can actually test

A policy on paper doesn’t carry much weight by itself. For a Type 1, auditors want to see that the control is actually in place. For a Type 2, they want proof it operated consistently over the review period. Either way, the evidence is typically artifacts like dated exports, tickets, approvals, and acknowledgments that an independent reviewer can verify.

Areas that are often thin at a first SOC 2: