F2 First SOC 2 Navigator
Startup SOC 2 search page

Use a first SOC 2 checklist that starts with scope, owners, and evidence.

A first SOC 2 checklist for small SaaS and AI startup teams that need weekly Type I scope, owners, and evidence examples before enterprise procurement stalls.

Complete triage

Start with the buyer block

The checklist assumes an enterprise customer is asking for SOC 2, security posture, SSO/MFA, logs, vendor review, and access answers before a deal can move. That pressure decides the first pass scope.

Define the first Type I scope

Name the production SaaS system, cloud, identity provider, code host, HR system, support system, customer-data boundary, and whether AI workflow evidence needs change-management language.

Assign one owner per control area

A five-to-twenty person startup should not create a committee. The navigator maps executive, technical, people, and customer owners to the first evidence each can collect.

Export proof examples

The output gives auditor-readable examples such as identity exports, GitHub review evidence, backup policy screenshots, incident tabletop notes, and vendor inventory rows.

What makes it startup-specific

The checklist avoids enterprise program language and focuses on the smallest credible packet: one scope statement, one accountable executive, one technical owner, one people owner, one customer owner, and the proof a buyer can understand.

Readiness boundary

Founder-grade readiness guidance, not an auditor opinion.

What should a startup do first for SOC 2?

Confirm scope, owners, and current evidence before buying another tool or requesting a consultant block.

Is this a full SOC 2 audit checklist?

No. It is founder-grade readiness guidance for a first Type I pass and should be reviewed with an auditor for final examination needs.

Does the navigator store compliance details?

No. The v1 planner runs in the browser and warns teams not to enter secrets, customer records, private keys, or legal conclusions.

Use the Navigator to align scope, owners, and evidence before auditor review. This is founder-grade readiness guidance, not legal advice, auditor attestation, or a SOC 2 certification. Do not enter secrets, customer records, private keys, or legal conclusions.