🛡️ SOC 2 Trust Services Criteria · UPDATED JULY 2026

SOC 2 Checklist:
A Practical CC1–CC9 + Availability Guide for SMBs

SOC 2 is the standard every enterprise buyer asks for the moment your SaaS contract crosses $50K ARR. Sprinto, Drata, Defendify, and Vanta are the dominant SMB-facing automation platforms — but the fastest and cheapest path starts with a free readiness gap analysis. Here's exactly what CC1–CC9 + Availability actually look like in practice for a 10–250 person business, including a 6-step roadmap and the platform comparison that picks the right fit for your team.

📅 July 29, 2026 📊 AICPA TSC · CC1–CC9 + Availability · 64 criteria points 👥 SMBs 5–500 employees pursuing enterprise SaaS contracts

Get Your Free SOC 2 Readiness Score →

See exactly which CC1–CC9 controls you already have, which you need, and which platform (Sprinto / Drata / Defendify / Vanta) matches your team's technical depth. Free, no signup. The gap analysis is the cheapest way to enter a SOC 2 conversation with an auditor.

Why SOC 2 Matters for SMBs Selling to Enterprise

70.5%
Of data breaches target SMBs — the same SMBs selling to enterprise
Verizon DBIR 2024
46
SOC 2 control criteria points across CC1–CC9 + Availability
AICPA TSC 2017 (rev. 2022)
$50K–$100K+
Typical first-year SOC 2 Type II cost for an SMB
AICPA SMB benchmarks
9–18 mo
SOC 2 Type II end-to-end timeline for an SMB
AICPA SMB benchmarks

SOC 2 closes enterprise deals, not legal compliance. Unlike HIPAA or PCI DSS, SOC 2 is not a regulator-issued mandate — it's a market-driven attestation that enterprise procurement teams ask for. The audit is performed by a licensed CPA firm (not an ISO certification body), and the output is a SOC 2 report you share with customers under NDA. SMBs pursuing SOC 2 are almost always in the same situation: an enterprise prospect's security questionnaire has progressed from a checkbox exercise to a "send your SOC 2 report by Q3 or we go to your competitor" demand.

What SOC 2 Actually Means

SOC 2 is short for "Service Organization Control 2" — a voluntary audit framework administered by the American Institute of Certified Public Accountants (AICPA) that evaluates how well a service organization handles customer data. The audit is anchored on the AICPA's Trust Services Criteria (TSC), a set of five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only required category; the four others are added based on what your customers actually need you to demonstrate.

Ad-Hoc SMB Approach (Pre-SOC 2) SOC 2-Prepared Approach
Enterprise security questionnaire: "we have MFA, sometimes" SOC 2 Type II report on file — auditor-attested evidence for any control
No access reviews, no provisioning/termination SLAs CC6.1–CC6.8 controls + quarterly access reviews with screenshots on file
Change management improvised — edits ship hot, no rollback CC8.1 change controls: peer review, segregation of duties, change tickets, rollback evidence
Vendor SOC 2 reports — never requested, never read CC9.2 vendor risk management: subprocessor inventory + annual SOC 2 review for every critical vendor
Incident response: ad-hoc Slack channel + founder approval on everything CC7.4 incident response plan, tabletop-tested annually, with documented incidents and lessons learned
Risk register: a list a consultant made 2 years ago, never updated CC3.1–CC3.4 risk assessment refreshed annually, aligned with auditor-expected change-detection evidence

The core idea is simple: every security decision rolls up to one of CC1–CC9 + the criteria you adopt. When someone asks "do we need MFA?" the answer is yes — it lives under CC6 Logical & Physical Access. When the auditor asks "how do you detect incidents?" the answer is under CC7 System Operations. Every control has a stable address, and your SOC 2 report walks an enterprise buyer through that address system in language they understand.

The SOC 2 Checklist (CC1–CC9 + Availability)

The Common Criteria (CC1–CC9) include roughly 46 control criteria points and are required in every SOC 2 audit. Availability (A1) is one of the four optional Trust Services Criteria — most SMBs pursuing SOC 2 for SaaS customers adopt it at the same time as Security because enterprise buyers ask about uptime and recovery the same week they ask about security.

CC1
Control Environment
Governance, ethics, organizational structure, board oversight, and assignment of authority/responsibility. SMB implementation: a 1-page charter naming the security owner, defined reporting lines, and a code of conduct that employees sign at hire.
CC2
Communication & Information
Internal/external communication of security responsibilities and the information systems that support them. SMB implementation: a security awareness training program with annual completion records, plus documented customer-facing security messaging.
CC3
Risk Assessment
Identification, analysis, and mitigation of risks to the achievement of objectives. SMB implementation: an annual risk register with top 10–20 risks, likelihood × impact scoring, and a documented risk treatment decision for each.
CC4
Monitoring Activities
Ongoing and separate evaluations of the internal control system's effectiveness. SMB implementation: monthly control health reviews, quarterly internal audits with documented findings, and an annual external SOC 2 read by leadership.
CC5
Control Activities
Policies and procedures that support the achievement of objectives through risk mitigation. SMB implementation: a written policy library (acceptable use, data classification, password, incident response, vendor management) with version control and annual review.
CC6
Logical & Physical Access
The largest category. User provisioning, authentication (MFA), authorization, segregation of duties, encryption at rest/in-transit, physical facility access, and data disposal. SMB implementation: SSO + MFA on every production system, role-based access reviews quarterly, encrypted laptops with documented disk disposal.
CC7
System Operations
Detection and response to anomalies, vulnerability management, and ongoing monitoring of infrastructure. SMB implementation: EDR on every endpoint, centralized log retention ≥90 days, monthly vulnerability scans, documented incident response plan with tabletop testing.
CC8
Change Management
SDLC controls, segregation of duties, change authorization, testing, and rollback procedures. SMB implementation: pull-request-based deploys with peer review, separated dev/staging/prod environments, quarterly audit of who can deploy to production.
CC9
Risk Mitigation
Vendor management, business continuity, insurance, and other activities that reduce business disruption risk. SMB implementation: subprocessor inventory with annual SOC 2 review for each critical vendor, tested business continuity plan, cyber insurance with documented coverage limits.
A1
Availability OPTIONAL TSC
System uptime commitments, capacity planning, environmental protections, and recovery testing. SMB implementation: customer-facing SLA (e.g. 99.9% monthly), infrastructure-as-code deploys with automated failover, quarterly DR restore tests, tested backup procedures with documented RTO/RPO.

Optional TSCs most SMBs also adopt: Confidentiality (C1) — for handling sensitive customer data beyond PII; Processing Integrity (PI1) — for SaaS products where customers care about data accuracy (payments, claims processing); Privacy (P1–P8) — for organizations subject to GDPR/CCPA/CPRA, or whose customers specifically demand AICPA-aligned privacy attestation.

Sprinto / Drata / Defendify / Vanta / CyberStackHub — SMB SOC 2 Platform Comparison

This is the question every SMB asks the moment SOC 2 enters a sales conversation: which platform should we pay for? The answer depends on three things — your team's technical depth, your budget, and whether you need SOC 2 readiness (pre-audit) or full audit-automation (post-platform). The table below summarizes the SMB-facing options as of 2026. Pricing is annualized in USD and reflects publicly-listed starting prices — most organizations sign annual contracts at higher tiers.

Platform Starting Price Time to First Audit-Ready State Requires Technical Staff Best For
Sprinto ~$7,000–$12,000/yr (estimated) 2–6 weeks Yes — configures AWS/GCP/Azure, Okta, HR systems, GitHub integrations Funded SaaS startups with a dedicated DevOps/compliance owner; deep integration ecosystem
Drata ~$9,000+/yr 2–6 weeks Yes — similar integrations to Sprinto Mid-stage SaaS with a compliance program manager; risk-register depth
Defendify ~$4,000–$8,000/yr (estimated) Days (lighter integration footprint) No — designed for non-technical SMB owners via guided setup Traditional SMBs (agencies, MSPs, professional services) without a dedicated compliance owner
Vanta ~$7,000+/yr 2–6 weeks Yes — extensive integration catalog Same buyer profile as Sprinto/Drata; slightly broader framework coverage (SOC 2, ISO 27001, HIPAA)
Secureframe ~$6,000/yr 2–4 weeks Yes — integrations + compliance templates Fast-growing SaaS that needs SOC 2 + ISO 27001 in parallel
CyberStackHub FREE READINESS Free 5 minutes No — plain-English questionnaire, instant gap report SMBs entering the SOC 2 conversation; pre-readiness before paying for any platform

The right path for most SMBs: run the free Compliance Gap Analysis first to identify exactly which CC1–CC9 controls you already have and which you need — then compare platforms based on the gaps. SMBs that skip the readiness step frequently over-buy a Sprinto/Drata/Vanta tier when a Defendify or CyberStackHub foundation would have produced the same SOC 2 outcome at a fraction of the cost.

SMB-Relevant Mappings: CC Categories → Concrete Controls

Each CC category is written as an outcomes criteria — auditor evaluates whether you have the control and whether you can demonstrate it with evidence. The mappings below show what the controls look like for a typical SMB without a dedicated security team.

CC1 CC1.1–CC1.5 — Control Environment

SMB control: A 1–2 page security charter that names the security owner, defines authority and reporting lines, and includes a code of conduct signed by every employee at hire. CC1 is where the auditor verifies that someone at the company owns security — without this, the rest of the report has no foundation.

CC2 CC2.1–CC2.3 — Communication & Information

SMB control: An annual security awareness training program with completion records (KnowBe4, Proofpoint, or a simple internal LMS), and a customer-facing security page that explains what controls protect customer data. Auditors expect to see dated training completion for every active employee.

CC3 CC3.1–CC3.4 — Risk Assessment

SMB control: An annual risk register documenting the top 10–20 risks with likelihood × impact scoring, a risk treatment decision (accept / mitigate / transfer / avoid), and an executive review signature. Auditors ask for change-detection evidence — meaning the register is refreshed at least annually and on material changes.

CC6 CC6.1, CC6.2, CC6.6 — Logical Access (the largest Category)

SMB control: SSO + MFA on every production system (Okta, Microsoft Entra, Google Workspace Identity), role-based access control (RBAC) with documented roles, immediately-deprovisioned access on termination (HR-system-driven), and quarterly user access reviews with screenshots. CC6 is the Category that most often makes or breaks a SOC 2 audit.

CC6 CC6.7 — Encryption (in transit, at rest)

SMB control: TLS 1.2+ enforced on every internet-facing service (AWS ALB/CloudFront config + screenshot), encryption at rest on every database and laptop (BitLocker/FileVault + KMS screenshot), documented key management procedure. Auditors pull encryption configuration evidence directly from your cloud console — Sprinto, Drata, and Vanta automate this pull.

CC7 CC7.1–CC7.5 — System Operations & Vulnerability Management

SMB control: EDR on every endpoint (Microsoft Defender for Endpoint included in M365 Business Premium, CrowdStrike, SentinelOne), centralized log retention ≥90 days, monthly vulnerability scans with documented remediation of high/critical findings within 30 days, and a documented incident response plan that has been tabletop-tested at least once in the audit observation window.

CC8 CC8.1 — Change Management

SMB control: Pull-request-based deploys with mandatory peer review, separated dev/staging/production environments, infrastructure-as-code with version control, and a quarterly audit of production access. CC8.1 is the change control Category that catches "shipped hot with no rollback" SMBs.

CC9 CC9.1–CC9.2 — Vendor Management

SMB control: A maintained subprocessor inventory, a documented vendor risk review procedure, an annual SOC 2 report request for every critical vendor (AWS, Stripe, your data warehouse, etc.), and a business continuity plan + cyber insurance policy with documented coverage limits.

A1 A1.1–A1.3 — Availability

SMB control: Customer-facing SLA with uptime commitment (e.g. 99.9% monthly), infrastructure-as-code deployment with automatic failover across availability zones, active monitoring with alerting (Datadog, CloudWatch + PagerDuty), tested backups with documented RTO/RPO targets, and quarterly DR restore tests (not just backup success — actual restore to a clean environment).

SOC 2 Implementation Roadmap for SMBs

You don't need a 12-month enterprise-wide project to start. These 6 steps are ordered by impact, speed, and how directly they map to CC6 Logical & Physical Access — the Category that drives more SOC 2 audit outcomes than any other.

1 Run the free SOC 2 readiness self-assessment

Start by scoring where you stand against CC1–CC9 + Availability. The free Compliance Gap Analysis gives you a maturity score (0–100), a prioritized gap list, and the precise controls that move your score the most. This is the launch point — everything else in the roadmap depends on knowing your starting point.

2 Pick the right TSC subset

Security (CC1–CC9) is the only required category — most SMBs adopt it first, then layer the four optional criteria based on customer demand. Add Availability (A1) if customers ask about uptime. Add Confidentiality (C1) if you handle sensitive customer data beyond PII. Add Privacy (P1–P8) if your customers are GDPR/CCPA-regulated or specifically demand AICPA-aligned privacy attestation. The smallest viable SOC 2 audit is Security-only Type I.

3 Map CC1–CC9 to existing controls

You probably already have ~30–40% of CC6 (Logical Access) through off-the-shelf identity tools, and ~50% of CC5 (Control Activities) through written policies. Build a "control-to-CC" matrix mapping every existing technical and policy control to one or more CC criteria points. The free Compliance Gap Analysis produces this matrix as part of the gap report.

4 Stand up evidence automation

The auditor's observation window (typically 6–12 months) requires you to produce dated evidence — access reviews, change tickets, scan reports — for every control every period. Evidence automation is what platforms like Sprinto, Drata, and Vanta sell. If you skip a platform, you'll be screenshotting AWS console exports and GitHub access lists on a quarterly cadence by hand.

5 Pick your SOC 2 automation platform

Once you know your gaps and your team capacity, choose the platform. Technical teams (in-house DevOps, compliance owner) do well on Sprinto, Drata, or Vanta for deep integration. Non-technical SMBs often prefer Defendify for the guided setup flow. For most SMBs, this decision should follow the gap analysis — not lead it. Don't pay for a platform before you know what your gaps are.

6 Engage auditor + 6–12 month Type II observation window

A SOC 2 Type II audit is conducted by a licensed CPA firm (not ISO certification bodies, not international SOC shops). Engage an auditor early — through your platform's auditor marketplace (Sprinto, Drata, Vanta all offer this), a referral, or a direct engagement with a mid-tier CPA firm experienced in SaaS SOC 2. Type II requires a 6–12 month observation window where the auditor reviews control evidence in production. Most SMBs deliver their first SOC 2 Type II 9–18 months after starting.

SOC 2 vs Related Frameworks

You don't need to pick one framework — SOC 2 is one trust attestation among several. Here's how the major frameworks relate, and when you need each.

SOC 2 vs. ISO 27001. SOC 2 is a market-driven attestation that enterprise SaaS buyers request, anchored in the AICPA's Trust Services Criteria. ISO 27001 is the international certifiable Information Security Management System (ISMS) standard, with audit, certification, and ongoing surveillance costs (~$30K–$80K for SMBs). ISO 27001 is required for enterprise contracts in the EU; SOC 2 covers most US enterprise B2B SaaS buyer asks. SOC 2 is faster (Type I in 3–6 months, Type II in 9–18) and significantly cheaper than ISO 27001 for most SMBs.

SOC 2 vs. HIPAA. HIPAA is a US healthcare regulation — it's not a voluntary attestation, it's a federal requirement for any organization that handles Protected Health Information (PHI). SOC 2 addresses the same underlying security domains as HIPAA but as a market-driven audit. Most healthcare-focused SaaS companies pursue HIPAA compliance (which is a continuous operating model, not an audit) AND SOC 2 Type II (which is the customer-facing attestation). The two reinforce each other but they are not substitutes.

SOC 2 vs. PCI DSS. PCI DSS (Payment Card Industry Data Security Standard) is required for any organization that stores, processes, or transmits cardholder data. SOC 2 is broader and customer-driven; PCI DSS is narrow and card-network-driven. If you accept payment cards, you need PCI DSS regardless of SOC 2 status. SOC 2 typically crosswalks most PCI DSS requirements, but completing SOC 2 does not exempt you from PCI DSS.

SOC 2 vs. NIST CSF 2.0. NIST CSF is a voluntary risk management framework that any organization can adopt for free — it tells you what to think about across 6 Functions (Govern, Identify, Protect, Detect, Respond, Recover). SOC 2 is an audited attestation against 9 Common Criteria + Availability. CSF is the operating program; SOC 2 is the third-party proof that the program meets a specific bar. Most SMBs that pursue SOC 2 first build the operating program using NIST CSF as the underlying scaffolding — the crosswalk makes the audit dramatically easier.

Benchmark Your SOC 2 Readiness

The free Compliance Gap Analysis scores you against CC1–CC9 + Availability — showing the prioritized gap list, the controls that move your SOC 2 audit-readiness score the most, and which platform (Sprinto / Drata / Defendify / Vanta / Secureframe) fits your team's technical depth. Use it as the launch point for a 9–18 month SOC 2 journey, or as evidence for an enterprise buyer who is asking for SOC 2 faster than you can produce it.

Know Exactly Where You Stand Against CC1–CC9 + Availability

SOC 2 isn't a project you finish — it's an operating program you attest over 6–12 months. Start with your current score; the gap analysis gives you the exact roadmap. From there, the CyberStackHub tool library maps each CC Category to a concrete action.

Need the full SOC 2 framework deep-dive? Read the full SOC 2 framework guide →  |  Browse all SOC 2-aligned tools →

Sources & Citations

1. AICPA Trust Services Criteria (TSC) — 2017 (revised 2022). American Institute of Certified Public Accountants. The 5 categories — Security, Availability, Processing Integrity, Confidentiality, Privacy — and the CC1–CC9 Common Criteria points audited in every SOC 2. aicpa-cica.com
2. SOC 2 Reporting on an Examination of Controls at a Service Organization. AICPA SSAE 18 / SOC 2 Type I vs Type II distinction and observation window guidance. aicpa.org/topic/audit-assurance/soc-2
3. Verizon 2024 Data Breach Investigations Report (DBIR). 30,458 incidents, 9,341 confirmed breaches across 139 countries. 70.5% of breaches target SMBs (used in stat grid). verizon.com/business/resources/reports/dbir/
4. IBM Cost of a Data Breach Report 2024. Ponemon Institute. Average breach cost, detection/containment time, and impact of tested incident response on breach severity. ibm.com/reports/data-breach
5. Coalition Cyber Claims Report — MFA Denial Drivers. Coalition Inc. 82% of denied cyber insurance claims involve MFA compliance failures (CC6.x crosswalk). coalitioninc.com
6. Sprinto — SOC 2 Automation Platform. Pricing, integration catalog, and SMB onboarding timelines (~$7K–$12K/yr, AWS/GCP/Azure/Okta/GitHub integrations). sprinto.com
7. Drata — SOC 2 Automation Platform. Pricing and integration catalog (~$9K+/yr, mid-stage SaaS buyer profile). drata.com
8. Defendify — All-in-One Cybersecurity for SMBs. Pricing and guided-setup flow (~$4K–$8K/yr, designed for non-technical SMB owners). defendify.com
9. Vanta — SOC 2 + ISO 27001 + HIPAA Automation. Pricing and integration catalog (~$7K+/yr). vanta.com
10. CyberStackHub SOC 2 Gap Analysis. Free CC1–CC9 + Availability readiness checker — the pre-audit readiness layer for SMBs entering the SOC 2 conversation. cyberstackhub.ai/soc2-gap-analysis