Skip to content

SOC 2 Type 1 — readiness

Everything an auditor asks for, in one place: where we stand on all 68 controls, which policy answers each one, and what evidence to capture.

Generated from GetAgency's checklist (received 2026-08-07) · last built 2026-08-23.

Where we stand

Controls
✅ Done 26 38%
🟡 In progress 36 53%
⬜ Not started 2 3%
➖ N/A 4 6%
Total 68

26 of 68 controls (38%) are audit-ready today.

What the statuses mean

A SOC 2 Type 1 report tests that controls exist at a point in time — so a control only counts as Done when it exists and we can capture the evidence now. In progress usually means the policy is written but still draft (not yet owner-approved) — approving the existing drafts converts many of these at once.

What blocks the audit

These are things to do, not things to write — the documentation largely exists.

# Control Status Owner
59 Annual incident response test ⬜ Not started Olaf
66 Tabletop disaster recovery test (annual) ⬜ Not started Olaf
2 Confidentiality agreements (NDAs) 🟡 In progress Olaf
3 Employment agreements 🟡 In progress Olaf
4 Contractor agreements 🟡 In progress Olaf
8 Org chart & defined reporting lines 🟡 In progress Olaf
10 Job descriptions & competence 🟡 In progress Olaf
14 Security awareness training 🟡 In progress Olaf
18 Customer-facing security commitments ✅ Done Olaf
28 Periodic control self-assessment 🟡 In progress Olaf
29 Track and remediate deficiencies 🟡 In progress Olaf
34 MFA on all critical systems 🟡 In progress Thomas
36 Data classification policy 🟡 In progress Olaf
38 Access provisioning on hire 🟡 In progress Thomas
39 Access removal on departure & quarterly review 🟡 In progress Thomas
40 Physical access / office & devices 🟡 In progress Thomas
43 Customer data deletion on departure 🟡 In progress Thomas
45 Network segmentation & diagram 🟡 In progress Thomas
46 Annual firewall rule review 🟡 In progress Thomas
49 Encryption key management 🟡 In progress Thomas
52 Annual penetration test 🟡 In progress Olaf
53 Hardening standards 🟡 In progress Olaf
57 Security incidents evaluated 🟡 In progress Olaf
60 Recovery from incidents (backups & restore test) 🟡 In progress Melvin
65 Business continuity / disaster recovery plan 🟡 In progress Olaf
67 Vendor management & review 🟡 In progress Olaf
68 Vendor agreements with confidentiality terms 🟡 In progress Olaf

The three pages

How SOC 2 fits with ISO 27001

Soon is pursuing ISO/IEC 27001 (primary) and SOC 2 Type 1 (via GetAgency) on the same control set. The overlap is high — one control, one piece of evidence, two frameworks:

Evidence folder structure the auditor expects

One SOC 2 Evidence folder with a subfolder per CC series (CC1 – Control Environment … CC9 – Risk Mitigation), each file named with its row number and CC reference, e.g. 34-CC6.1-MFA-enforced-aws.png. Our S3 evidence store keys artefacts by control in the same way.