SOC 2 Type 1 — readiness¶
Everything an auditor asks for, in one place: where we stand on all 68 controls, which policy answers each one, and what evidence to capture.
Generated from GetAgency's checklist (received 2026-08-07) · last built 2026-08-23.
Where we stand¶
| Controls | ||
|---|---|---|
| ✅ Done | 26 | 38% |
| 🟡 In progress | 36 | 53% |
| ⬜ Not started | 2 | 3% |
| ➖ N/A | 4 | 6% |
| Total | 68 |
26 of 68 controls (38%) are audit-ready today.
What the statuses mean
A SOC 2 Type 1 report tests that controls exist at a point in time — so a
control only counts as Done when it exists and we can capture the evidence now.
In progress usually means the policy is written but still draft (not yet
owner-approved) — approving the existing drafts converts many of these at once.
What blocks the audit¶
These are things to do, not things to write — the documentation largely exists.
The three pages¶
- All 68 controls — status, how we meet it, and the evidence to capture.
- Policies SOC 2 expects — the required policy set mapped to our documents.
- Readiness register — the controlled ISMS document behind this section.
How SOC 2 fits with ISO 27001¶
Soon is pursuing ISO/IEC 27001 (primary) and SOC 2 Type 1 (via GetAgency) on the same control set. The overlap is high — one control, one piece of evidence, two frameworks:
- Policies and procedures live in the ISMS and are indexed in the document register.
- Evidence is collected per the Evidence Collection & Management Procedure and indexed in the Evidence Register.
- Many technical controls are checked automatically by our own GRC collectors — see Continuous Control Monitoring.
Evidence folder structure the auditor expects
One SOC 2 Evidence folder with a subfolder per CC series (CC1 – Control Environment …
CC9 – Risk Mitigation), each file named with its row number and CC reference, e.g.
34-CC6.1-MFA-enforced-aws.png. Our S3 evidence store keys artefacts by control in the
same way.