CloudCompliance

Cloud compliance roadmap

The order matters more than the speed. Structure first, then identity and logging, then the evidence routine, then the window. Doing it the other way round creates exceptions you have to explain.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

From a working but unstructured cloud account to an audit-ready one takes three to six months for a 20 to 150 person company. The phases below are in the order that avoids rework. A SOC 2 Type 2 then adds an observation window of three to twelve months before the report.

Cloud compliance roadmap, typical durations
PhaseWeeksOutcome
1. Scope and decide1 to 2Standard, report type, date, in-scope accounts written down
2. Structure2 to 6Production isolated, landing zone guardrails in place
3. Identity and logging1 to 3Federated access with MFA, audit logs retained and protected
4. Baseline and harden2 to 6Encryption, exposure, backups, scanning fixed and monitored
5. Policies and routine3 to 6, overlappingPolicies approved, first access review, first restore test
6. Window and audit12 to 52Type 1 date or Type 2 period, then fieldwork

Phase 1: scope and decide

Ask the customer which report, which criteria and by when. Decide which accounts, subscriptions or projects hold the system. Write architecture decisions for region and structure. If the deadline is close, consider a SOC 2 Type 1 first; GetSOC2 covers the choice.

Phase 2: structure

Separate production. Build the minimum landing zone: management, security, log archive, production and non-production. This is the phase most likely to involve moving workloads, so it goes first. Account structure for audits covers the layout.

Phase 3: identity and logging

Federate every cloud to your identity provider with MFA and remove local users. Turn on organization-wide audit logs to the log archive with retention of at least fifteen months. Logging cannot be applied backwards, so it starts as early as possible.

Phase 4: baseline and harden

Assign a configuration baseline, fix what it flags, set up backups with immutability, and turn on vulnerability scanning with a remediation target. Common findings is the checklist.

Phase 5: policies and routine

Write policies that describe what you actually do. Run the first quarterly access review, the first restore test and the first triage cycle before the window opens, so the routine is proven.

Phase 6: window and audit

Open the observation window when the controls have run at least once. Avoid structural changes during it. Keep evidence by control and period so fieldwork is an export.

How long does it take to get SOC 2 on AWS from scratch?

Three to six months to get ready, then a Type 1 on a date or a Type 2 window of three to twelve months, then four to eight weeks of fieldwork and report writing. Six to eighteen months overall, depending on the window.

Can phases run in parallel?

Policies and the evidence routine can run alongside hardening. Structure and logging should come first, because changing them later disrupts everything built on top.

Want the roadmap run for you?

Firms in the network take a cloud estate from phase one to fieldwork.

Get matched