Governance. Risk. Compliance. Cybersecurity.
guide

SOC 2 Type 2 Readiness Playbook

A 12-week plan for SaaS and managed-service teams to reach a clean Type 2 report, covering the AICPA 2017 Trust Services Criteria with 2022 points of focus.

23 June 2026SOC 2GuideSaaS

Who this is for

B2B SaaS and managed-service teams in the UAE, KSA and India targeting their first SOC 2 Type 2 with a 6 or 12-month observation window.

The 12-week plan

Weeks 1-2 — Scope and design

  • Decide trust-services criteria: Security is mandatory; add Availability, Confidentiality, Processing Integrity or Privacy based on customer contracts.
  • Document the service description and system boundaries.
  • Map every TSC criterion to a control, an owner, and an evidence source.

Weeks 3-4 — Foundational controls

  • HR: background checks, onboarding/offboarding tickets, confidentiality agreements.
  • Access: SSO/MFA on production, quarterly access reviews, JML automation.
  • Change: branch protection, code review, deployment approvals.

Weeks 5-6 — Operational controls

  • Vulnerability management: scanner output, SLA-tracked remediation.
  • Logging and monitoring: SIEM coverage, alert runbooks, on-call rota.
  • Vendor management: register, risk tiering, annual reviews.

Weeks 7-8 — Resilience and incident response

  • Backup configuration and restore test evidence.
  • BCP/DR plan with last tabletop minutes.
  • Incident response runbook with severity matrix.

Weeks 9-10 — Internal evidence dry-run

  • Sample 25 changes, 25 access requests, 4 quarters of reviews.
  • Confirm every control owner can produce evidence within 24 hours.

Weeks 11-12 — Observation window opens

  • Freeze control design.
  • Brief the auditor on scope, exceptions and remediation plan.
  • Run a weekly evidence-collection cadence for the full window.

Common Type 2 exceptions to pre-empt

  • Terminated user retained access beyond 24 hours
  • Production change deployed without approver evidence
  • Backup restore test missed in the period
  • Vendor review overdue at year-end
  • Vulnerability past SLA without documented risk acceptance

Next step

MAST runs SOC 2 readiness sprints as a fixed-fee 12-week programme. Talk to the practice lead.

Related resources