Skip to content
L Luxeran

Free resource

The 40 SOC 2 controls that actually fail.

Every SOC 2 checklist lists the criteria. That's not where anyone gets stuck — the control set comes predefined. This list is the next step: the 40 places where a generic control meets a real 10-to-100-person company and doesn't survive contact, why each one breaks, and whether it's worth automating.

No email wall, no download form. Read it, copy it, hand it to your team.

How to use this

Go down the list and mark each control red, amber, or green against what your organization does today — not what the policy says. The reds are your scope. Then look at the verdict column: the automatable reds are where a few weeks of engineering removes a recurring burden for the life of the program, and the ones that stay human are where you need to book real time on someone's calendar. Teams that stall usually inverted this, spending their budget on the manual half and hand-collecting the automatable half forever.

Automation verdict

Automatable
A pipeline or platform can collect this evidence on a schedule with no human in the loop.
Partly automatable
The check can run itself, but a person still has to make a judgment call or fix the underlying gap.
Stays human
Automating this produces evidence of a process that didn't really happen. Do the work instead.

Access management

CC6
  1. 1

    MFA on every admin console, not just the identity provider

    Everything behind SSO looks covered, so nobody checks the AWS root account, the DNS registrar, the billing portal, or the break-glass login.

    Automatable
  2. 2

    Named accounts only, no shared logins

    The shared ops@ credential sitting in the password manager is the single most common finding we see.

    Partly automatable
  3. 3

    Least privilege that someone actually scoped

    Everyone lands in the Admin group because defining real roles was never anyone's job, and nobody wants to be the one who breaks a deploy.

    Stays human
  4. 4

    Quarterly access reviews with evidence of the review itself

    Teams produce a user list. Your auditor wants the reviewer, the date, and the decision for each line.

    Automatable
  5. 5

    Privileged access that is time-bound or separately approved

    Standing production admin for every engineer, granted on day one and never revisited.

    Partly automatable

Joiner, mover, leaver

CC6
  1. 6

    Offboarding inside the SLA your own policy claims

    The policy says 24 hours. The ticket history says nine days. The policy is the control you get measured against.

    Automatable
  2. 7

    Offboarding that reaches past the identity provider

    The tool someone bought on a personal card never made it into SSO, so the account is still live.

    Partly automatable
  3. 8

    Role changes that remove access, not just add it

    Movers accumulate. The person who went from support to sales still has the admin console.

    Automatable
  4. 9

    Expiry dates on contractor and vendor accounts

    Contractor accounts outlive the contract by months because nothing forces a review.

    Automatable
  5. 10

    A traceable link from termination to deprovisioning

    You need HR record → ticket → system log as one chain. Most teams can show two of the three.

    Automatable

Change management

CC8
  1. 11

    Every production change traceable to an approved change record

    Hotfixes pushed straight to prod during an incident are the gap, and they're exactly what gets sampled.

    Automatable
  2. 12

    Peer review enforced by branch protection, not by team convention

    "We always review" is not a control. Your auditor samples merges, and self-merges will surface.

    Automatable
  3. 13

    Separation between who writes code and who releases it

    Hard for a small team. You need either the separation or a documented compensating control — not silence.

    Partly automatable
  4. 14

    Emergency changes documented after the fact with the same rigor

    The 2am fix nobody wrote up is the sample that fails.

    Stays human
  5. 15

    Infrastructure changes going through the same path as application code

    Console clicks in AWS bypass the entire change process and leave no reviewable record.

    Partly automatable

Logging and monitoring

CC7
  1. 16

    Log retention covering the full observation window

    Cloud defaults are 30 to 90 days. A 12-month Type II window needs 12 months of logs, and you can't backfill.

    Automatable
  2. 17

    Logs that can't be quietly edited

    Write-once storage or a separate account. If an admin can rewrite the log, it isn't evidence.

    Partly automatable
  3. 18

    Alerts with a named owner and a defined response time

    Alerts routed to a channel nobody owns are worse than no alerts, and it's visible.

    Stays human
  4. 19

    Evidence that a human actually responded to an alert

    The alert fired and the graph recovered. Nothing records that a person looked.

    Automatable
  5. 20

    Vulnerability scanning with remediation SLAs that are actually met

    Scanning is easy to turn on. Closing criticals inside the window you promised is where it falls apart.

    Automatable

Vendors and third parties

CC9
  1. 21

    A vendor inventory that is current

    Shadow SaaS bought on expense cards never reaches the list, and procurement doesn't know it exists.

    Partly automatable
  2. 22

    Risk tiering so review effort matches exposure

    Reviewing your design tool as hard as your data processor burns the time you needed for the one that matters.

    Stays human
  3. 23

    Subservice organization reports collected and read

    Downloading your cloud provider's report isn't the control. Reading it is.

    Partly automatable
  4. 24

    Complementary user entity controls reviewed and mapped

    The CUECs in your vendors' reports are obligations transferred to you. Almost every team skips this entirely.

    Stays human
  5. 25

    Vendor reviews on a calendar instead of at renewal panic

    Reviews done the week before someone asks are visibly backdated by their own timestamps.

    Automatable

Risk and governance

CC3–CC5
  1. 26

    A risk assessment performed inside the period

    One dated 18 months ago fails. It has to have happened during the window being examined.

    Stays human
  2. 27

    Risks with named owners and a treatment decision

    A risk register with no owner and no accept/mitigate decision is a spreadsheet, not a control.

    Stays human
  3. 28

    Management oversight with real meeting records

    You need minutes, attendees, and decisions — not a recollection that security gets discussed.

    Stays human
  4. 29

    Documented org structure and security responsibilities

    Small teams assume it's obvious. The control asks you to write down who is accountable for what.

    Stays human
  5. 30

    An ethics or whistleblower channel that people know exists

    Having the channel isn't enough; you have to show it was communicated.

    Stays human

Resilience and incidents

A1, CC7
  1. 31

    A restore that was actually tested, not just backups configured

    Backups running is the easy half. Proving you restored from one during the period is the half that fails.

    Partly automatable
  2. 32

    RTO and RPO targets that match what your architecture can do

    Publishing a 1-hour RTO you've never hit creates the finding yourself.

    Stays human
  3. 33

    A continuity test performed and documented in the period

    Tabletop is fine. No record of one is not.

    Stays human
  4. 34

    An incident response plan with a real severity scale

    Generic templates fail the moment your auditor asks how sev-1 is defined for your product.

    Stays human
  5. 35

    Post-incident reviews for anything customer-facing

    Incidents get fixed and never written up, so there's no evidence the process ran.

    Stays human

People and policy

CC1–CC2
  1. 36

    Policies reviewed and approved annually, with the approval recorded

    The document exists. The record of who approved it and when usually doesn't.

    Automatable
  2. 37

    Policy acceptance from everyone, including mid-period joiners

    The original team signed at rollout. The five people who joined in month seven never did.

    Automatable
  3. 38

    Security awareness training completed on time by everyone

    Ninety percent completion is a finding. Your auditor samples the ten percent.

    Automatable
  4. 39

    Background checks run wherever your policy says they are

    Write the policy to match what you actually do. Claiming checks you skip for contractors is self-inflicted.

    Partly automatable
  5. 40

    Confidentiality agreements on file for staff and contractors

    Contractor NDAs live in someone's inbox instead of a system anyone can produce them from.

    Partly automatable

Red on more than a handful?

That's normal, and it's the whole reason the readiness phase exists. A 30-minute call is usually enough to tell you which reds are three weeks of work and which are three months.

Luxeran is not a CPA firm. We do not perform SOC 2 examinations and we do not issue SOC 2 reports — we do readiness, implementation, control remediation, and evidence management.