Free resource
The 40 SOC 2 controls that actually fail.
Every SOC 2 checklist lists the criteria. That's not where anyone gets stuck — the control set comes predefined. This list is the next step: the 40 places where a generic control meets a real 10-to-100-person company and doesn't survive contact, why each one breaks, and whether it's worth automating.
No email wall, no download form. Read it, copy it, hand it to your team.
How to use this
Go down the list and mark each control red, amber, or green against what your organization does today — not what the policy says. The reds are your scope. Then look at the verdict column: the automatable reds are where a few weeks of engineering removes a recurring burden for the life of the program, and the ones that stay human are where you need to book real time on someone's calendar. Teams that stall usually inverted this, spending their budget on the manual half and hand-collecting the automatable half forever.
Automation verdict
- Automatable
- A pipeline or platform can collect this evidence on a schedule with no human in the loop.
- Partly automatable
- The check can run itself, but a person still has to make a judgment call or fix the underlying gap.
- Stays human
- Automating this produces evidence of a process that didn't really happen. Do the work instead.
Access management
CC6- 1
MFA on every admin console, not just the identity provider
Everything behind SSO looks covered, so nobody checks the AWS root account, the DNS registrar, the billing portal, or the break-glass login.
Automatable - 2
Named accounts only, no shared logins
The shared ops@ credential sitting in the password manager is the single most common finding we see.
Partly automatable - 3
Least privilege that someone actually scoped
Everyone lands in the Admin group because defining real roles was never anyone's job, and nobody wants to be the one who breaks a deploy.
Stays human - 4
Quarterly access reviews with evidence of the review itself
Teams produce a user list. Your auditor wants the reviewer, the date, and the decision for each line.
Automatable - 5
Privileged access that is time-bound or separately approved
Standing production admin for every engineer, granted on day one and never revisited.
Partly automatable
Joiner, mover, leaver
CC6- 6
Offboarding inside the SLA your own policy claims
The policy says 24 hours. The ticket history says nine days. The policy is the control you get measured against.
Automatable - 7
Offboarding that reaches past the identity provider
The tool someone bought on a personal card never made it into SSO, so the account is still live.
Partly automatable - 8
Role changes that remove access, not just add it
Movers accumulate. The person who went from support to sales still has the admin console.
Automatable - 9
Expiry dates on contractor and vendor accounts
Contractor accounts outlive the contract by months because nothing forces a review.
Automatable - 10
A traceable link from termination to deprovisioning
You need HR record → ticket → system log as one chain. Most teams can show two of the three.
Automatable
Change management
CC8- 11
Every production change traceable to an approved change record
Hotfixes pushed straight to prod during an incident are the gap, and they're exactly what gets sampled.
Automatable - 12
Peer review enforced by branch protection, not by team convention
"We always review" is not a control. Your auditor samples merges, and self-merges will surface.
Automatable - 13
Separation between who writes code and who releases it
Hard for a small team. You need either the separation or a documented compensating control — not silence.
Partly automatable - 14
Emergency changes documented after the fact with the same rigor
The 2am fix nobody wrote up is the sample that fails.
Stays human - 15
Infrastructure changes going through the same path as application code
Console clicks in AWS bypass the entire change process and leave no reviewable record.
Partly automatable
Logging and monitoring
CC7- 16
Log retention covering the full observation window
Cloud defaults are 30 to 90 days. A 12-month Type II window needs 12 months of logs, and you can't backfill.
Automatable - 17
Logs that can't be quietly edited
Write-once storage or a separate account. If an admin can rewrite the log, it isn't evidence.
Partly automatable - 18
Alerts with a named owner and a defined response time
Alerts routed to a channel nobody owns are worse than no alerts, and it's visible.
Stays human - 19
Evidence that a human actually responded to an alert
The alert fired and the graph recovered. Nothing records that a person looked.
Automatable - 20
Vulnerability scanning with remediation SLAs that are actually met
Scanning is easy to turn on. Closing criticals inside the window you promised is where it falls apart.
Automatable
Vendors and third parties
CC9- 21
A vendor inventory that is current
Shadow SaaS bought on expense cards never reaches the list, and procurement doesn't know it exists.
Partly automatable - 22
Risk tiering so review effort matches exposure
Reviewing your design tool as hard as your data processor burns the time you needed for the one that matters.
Stays human - 23
Subservice organization reports collected and read
Downloading your cloud provider's report isn't the control. Reading it is.
Partly automatable - 24
Complementary user entity controls reviewed and mapped
The CUECs in your vendors' reports are obligations transferred to you. Almost every team skips this entirely.
Stays human - 25
Vendor reviews on a calendar instead of at renewal panic
Reviews done the week before someone asks are visibly backdated by their own timestamps.
Automatable
Risk and governance
CC3–CC5- 26
A risk assessment performed inside the period
One dated 18 months ago fails. It has to have happened during the window being examined.
Stays human - 27
Risks with named owners and a treatment decision
A risk register with no owner and no accept/mitigate decision is a spreadsheet, not a control.
Stays human - 28
Management oversight with real meeting records
You need minutes, attendees, and decisions — not a recollection that security gets discussed.
Stays human - 29
Documented org structure and security responsibilities
Small teams assume it's obvious. The control asks you to write down who is accountable for what.
Stays human - 30
An ethics or whistleblower channel that people know exists
Having the channel isn't enough; you have to show it was communicated.
Stays human
Resilience and incidents
A1, CC7- 31
A restore that was actually tested, not just backups configured
Backups running is the easy half. Proving you restored from one during the period is the half that fails.
Partly automatable - 32
RTO and RPO targets that match what your architecture can do
Publishing a 1-hour RTO you've never hit creates the finding yourself.
Stays human - 33
A continuity test performed and documented in the period
Tabletop is fine. No record of one is not.
Stays human - 34
An incident response plan with a real severity scale
Generic templates fail the moment your auditor asks how sev-1 is defined for your product.
Stays human - 35
Post-incident reviews for anything customer-facing
Incidents get fixed and never written up, so there's no evidence the process ran.
Stays human
People and policy
CC1–CC2- 36
Policies reviewed and approved annually, with the approval recorded
The document exists. The record of who approved it and when usually doesn't.
Automatable - 37
Policy acceptance from everyone, including mid-period joiners
The original team signed at rollout. The five people who joined in month seven never did.
Automatable - 38
Security awareness training completed on time by everyone
Ninety percent completion is a finding. Your auditor samples the ten percent.
Automatable - 39
Background checks run wherever your policy says they are
Write the policy to match what you actually do. Claiming checks you skip for contractors is self-inflicted.
Partly automatable - 40
Confidentiality agreements on file for staff and contractors
Contractor NDAs live in someone's inbox instead of a system anyone can produce them from.
Partly automatable
Red on more than a handful?
That's normal, and it's the whole reason the readiness phase exists. A 30-minute call is usually enough to tell you which reds are three weeks of work and which are three months.
Luxeran is not a CPA firm. We do not perform SOC 2 examinations and we do not issue SOC 2 reports — we do readiness, implementation, control remediation, and evidence management.