Prepare for SOC 2 audit with a Gantt chart. Track readiness assessment, control implementation, evidence collection, pen testing, and auditor review on a 6-month timeline.
SOC 2 is not a checklist you complete once. It's an audit of your security controls operating consistently over an observation period. SOC 2 Type I is a point-in-time assessment of whether controls exist. SOC 2 Type II is an assessment of whether those controls operated effectively for a defined period — typically 3–12 months.
Most SaaS companies need Type II. And that's where the timeline planning gets critical: you can't rush the observation period. If auditors need 6 months of evidence, you need 6 months of controls running before the audit begins.
A Gantt chart makes this concrete. It shows the observation window as a real bar on the timeline, which immediately reveals that "we'll be SOC 2 certified by Q3" requires controls to be live by Q1.
| Phase | Work | Duration | Dependency |
|---|---|---|---|
| Readiness assessment | Evaluate controls against Trust Services Criteria | 2–3 weeks | None |
| Gap remediation planning | Prioritize and assign remediation tasks | 1 week | Assessment complete |
| Control implementation | Technical and process controls | 4–8 weeks | Plan approved |
| Policy documentation | Security policies required by auditors | 3–4 weeks | Assessment complete (parallel) |
| Vendor reviews | Third-party vendor security assessments | 2–3 weeks | Policy framework in place |
| Staff training | Security awareness for all employees | 1–2 weeks | Policies drafted |
| Pen testing | External penetration test (required for most auditors) | 3–4 weeks total | Controls implemented |
| Observation period | Controls operating and evidence collected | 3–6 months minimum | All controls live |
| Auditor engagement | Fieldwork, evidence review, walkthroughs | 4–6 weeks | Observation period complete |
| Report issuance | Auditor issues SOC 2 Type II report | 2–4 weeks | Audit complete |
This decision shapes the entire timeline.
Most buyers require Type II. If prospects are asking for SOC 2 today, you're likely 9–12 months from Type II.
Place your target report date as a fixed milestone in gantt-chart.io. Then build backward.
Add the observation period as a long bar. It starts when all controls are implemented and operational. It ends when the auditor engagement begins.
For Type II, this bar is a minimum of 3 months (some auditors require 6). The observation start date determines when control implementation must complete.
Create three swim lane sections:
Technical Controls
Process and Documentation
Vendor and Third-Party
Technical and documentation tracks run in parallel after the assessment is complete.
Pen testing is on the critical path. Most auditors require an annual penetration test. Book the pen test firm 6–8 weeks before you need results.
Add pen test scheduling as a task in week 1, even if the test won't happen until month 4. Pen test firms at reputable shops are often booked 4–8 weeks out.
If pen test findings require remediation, budget 2–4 weeks after the report before the observation period can credibly include "pen test remediation complete."
Audit fieldwork is not a single meeting. It involves evidence requests, walkthrough sessions with your engineering and ops teams, and follow-up questions. Budget 4–6 weeks for the full auditor engagement, including fieldwork and report drafting.
Schedule your audit engagement to start immediately after the observation period ends. If the auditor isn't booked in advance, you'll wait another 4–8 weeks for availability.
Assuming Type I is a stepping stone to Type II. A Type I audit covers a point in time. The observation period for Type II starts when your controls are live, not when Type I is complete. Starting with Type I adds cost without shortening the Type II timeline.
Starting the observation window before controls are complete. Evidence collected before a control is implemented cannot count toward the observation period. All controls must be live and operating before the clock starts.
Not tracking evidence collection as ongoing work. Evidence collection isn't passive. Someone must be collecting screenshots, logs, policy acknowledgments, and vendor reviews throughout the observation period. Add "monthly evidence collection" as a recurring task.
Ignoring the logical access review. Most SOC 2 audits surface access control issues: terminated employees still with access, admin credentials shared, no quarterly access review process. Implement and document an access review before the observation period starts.
No remediation tracking for pen test findings. Pen test reports have findings. Auditors will check whether critical and high findings were remediated. Track pen test remediation in the chart with due dates.
Months 1-2: Foundation
Readiness Assessment |████░░░░░░░░░░░░░░░░░░░░|
Gap Remediation Planning |░░░░██░░░░░░░░░░░░░░░░░░|
Audit Firm Selection |████████░░░░░░░░░░░░░░░░| (book early)
Months 2-4: Control Implementation (parallel tracks)
Technical Controls |░░░░████████████░░░░░░░░|
Policy Documentation |░░░░████████████░░░░░░░░|
Vendor Reviews |░░░░░░░░████████░░░░░░░░|
Staff Training |░░░░░░░░░░░░████░░░░░░░░|
Month 4: Pen Testing
Pen Test Engagement |░░░░░░░░░░░░████░░░░░░░░|
Pen Test Remediation |░░░░░░░░░░░░░░████░░░░░░|
Months 4-10: Observation Period (6 months)
Evidence Collection |░░░░░░░░████████████████████░░░░░░░░|
Months 10-12: Audit
Auditor Fieldwork |░░░░░░░░░░░░░░░░░░░░░░░░░░░░████░░░|
Report Drafting |░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░████|
Milestones
Controls Live Month 4 ◆
Observation Period Start Month 4 ◆
Observation Period End Month 10 ◆
Audit Fieldwork Start Month 10 ◆
SOC 2 Report Issued Month 12 ◆
Start your SOC 2 preparation timeline in gantt-chart.io. Pin your target report date as a milestone, add the observation period bar working backward, and confirm when control implementation must begin. Share the chart with your CISO, engineering lead, and audit firm before your project kickoff.