Free toolkit

SOC 2 Readiness Toolkit

The 33 Security criteria in plain English, what evidence usually looks like, a risk register, and 35 questions for vendors without their own SOC 2 report.

ExcelGoogle SheetsNotionPDFMarkdown
SOC 2 Readiness Guide cover
SOC 2 Readiness Toolkit dashboard
What’s inside

A working file, not a whitepaper

Five tabs that take you from criteria to evidence to vendors, plus a guide that explains each criterion in plain English.

CC1.1 → CC9.2

Readiness Checklist

All 33 Security criteria, what each looks like in practice, and the evidence teams typically collect.

Likelihood × Impact

Risk Register

Score gaps from 1 to 25, assign owners and dates, and start from example risks that are never counted.

Report or 35 questions

Vendor review

Record what a vendor’s SOC 2 report actually says, or send a 35-question DDQ when there is no report.

Live counts

Dashboard

Criteria complete, evidence linked, open high-risk items, and vendor reviews pending, updated as you work.

What it is

✦A working file for organizing readiness against the SOC 2 Security criteria (CC1.1 through CC9.2) from AICPA TSP section 100.
✦Plain-English notes on what each criterion looks like in practice and the evidence teams typically keep.
✦Free to use and share. No account needed.
Download

Pick the format your team already uses

Same content in each. The guide reads well on its own or beside the workbook.

.xlsx

Excel workbook

Formulas, dropdowns, and the live dashboard. Works offline.

Download .xlsx
Google Drive

Google Sheets

The same workbook as a copy in your Drive, ready to share with your team.

Make a copy
Template

Notion

Linked databases for criteria, risks, and vendors, with owners and dates.

Duplicate in Notion
PDF · Markdown

Readiness guide

Every criterion and vendor question, written to read on its own.

Markdown on GitHub
About Asteros

Need the Penetration Test?

The audit asks whether a test was performed. An enterprise security review asks how. Asteros runs manual-first web application pentests based on OWASP ASVS, with one report written for executives, engineers, and auditors, and retesting included at no additional charge.

Let’s talk about your application.