Start with the buyer block
The checklist assumes an enterprise customer is asking for SOC 2, security posture, SSO/MFA, logs, vendor review, and access answers before a deal can move. That pressure decides the first pass scope.
A first SOC 2 checklist for small SaaS and AI startup teams that need weekly Type I scope, owners, and evidence examples before enterprise procurement stalls.
Complete triageThe checklist assumes an enterprise customer is asking for SOC 2, security posture, SSO/MFA, logs, vendor review, and access answers before a deal can move. That pressure decides the first pass scope.
Name the production SaaS system, cloud, identity provider, code host, HR system, support system, customer-data boundary, and whether AI workflow evidence needs change-management language.
A five-to-twenty person startup should not create a committee. The navigator maps executive, technical, people, and customer owners to the first evidence each can collect.
The output gives auditor-readable examples such as identity exports, GitHub review evidence, backup policy screenshots, incident tabletop notes, and vendor inventory rows.
The checklist avoids enterprise program language and focuses on the smallest credible packet: one scope statement, one accountable executive, one technical owner, one people owner, one customer owner, and the proof a buyer can understand.
Confirm scope, owners, and current evidence before buying another tool or requesting a consultant block.
No. It is founder-grade readiness guidance for a first Type I pass and should be reviewed with an auditor for final examination needs.
No. The v1 planner runs in the browser and warns teams not to enter secrets, customer records, private keys, or legal conclusions.
Use the Navigator to align scope, owners, and evidence before auditor review. This is founder-grade readiness guidance, not legal advice, auditor attestation, or a SOC 2 certification. Do not enter secrets, customer records, private keys, or legal conclusions.