Compliance

Preparing for SOC 2 Type II: A 90-Day Roadmap

February 10, 2026  ·  By Priya Sundaram

SOC 2 Type II is increasingly a procurement prerequisite for B2B SaaS companies. Unlike Type I (which evaluates design of controls at a point in time), Type II examines whether controls operated effectively over an observation period—typically six to twelve months.

Days 1–15: Scoping. Define which Trust Services Criteria apply to your product. Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are optional. Most early-stage companies scope to Security + Availability. Identify in-scope systems and write your system description.

Days 16–30: Gap assessment. Map your current controls to the selected criteria and document gaps. Common first-timer gaps include: absence of formal access review processes, no background check policy, no vendor risk management program, and incomplete incident response procedures.

Days 31–60: Control implementation. Stand up the missing controls. Prioritize controls with the longest evidence collection window first—user access reviews, security awareness training completion records, and vulnerability scan results all accumulate over time.

Days 61–75: Evidence collection automation. Manual evidence collection is the single biggest time sink in an audit. Integrate your cloud provider, identity provider, and ticketing system with a compliance platform to collect evidence continuously.

Days 76–90: Readiness assessment. Engage your auditor for a pre-audit readiness check. Walk through evidence packages for high-risk controls. Remediate gaps. Confirm the observation period start date.

← Back to Blog