Cloud compliance roadmap
The order matters more than the speed. Structure first, then identity and logging, then the evidence routine, then the window. Doing it the other way round creates exceptions you have to explain.
From a working but unstructured cloud account to an audit-ready one takes three to six months for a 20 to 150 person company. The phases below are in the order that avoids rework. A SOC 2 Type 2 then adds an observation window of three to twelve months before the report.
| Phase | Weeks | Outcome |
|---|---|---|
| 1. Scope and decide | 1 to 2 | Standard, report type, date, in-scope accounts written down |
| 2. Structure | 2 to 6 | Production isolated, landing zone guardrails in place |
| 3. Identity and logging | 1 to 3 | Federated access with MFA, audit logs retained and protected |
| 4. Baseline and harden | 2 to 6 | Encryption, exposure, backups, scanning fixed and monitored |
| 5. Policies and routine | 3 to 6, overlapping | Policies approved, first access review, first restore test |
| 6. Window and audit | 12 to 52 | Type 1 date or Type 2 period, then fieldwork |
Phase 1: scope and decide
Ask the customer which report, which criteria and by when. Decide which accounts, subscriptions or projects hold the system. Write architecture decisions for region and structure. If the deadline is close, consider a SOC 2 Type 1 first; GetSOC2 covers the choice.
Phase 2: structure
Separate production. Build the minimum landing zone: management, security, log archive, production and non-production. This is the phase most likely to involve moving workloads, so it goes first. Account structure for audits covers the layout.
Phase 3: identity and logging
Federate every cloud to your identity provider with MFA and remove local users. Turn on organization-wide audit logs to the log archive with retention of at least fifteen months. Logging cannot be applied backwards, so it starts as early as possible.
Phase 4: baseline and harden
Assign a configuration baseline, fix what it flags, set up backups with immutability, and turn on vulnerability scanning with a remediation target. Common findings is the checklist.
Phase 5: policies and routine
Write policies that describe what you actually do. Run the first quarterly access review, the first restore test and the first triage cycle before the window opens, so the routine is proven.
Phase 6: window and audit
Open the observation window when the controls have run at least once. Avoid structural changes during it. Keep evidence by control and period so fieldwork is an export.
How long does it take to get SOC 2 on AWS from scratch?
Three to six months to get ready, then a Type 1 on a date or a Type 2 window of three to twelve months, then four to eight weeks of fieldwork and report writing. Six to eighteen months overall, depending on the window.
Can phases run in parallel?
Policies and the evidence routine can run alongside hardening. Structure and logging should come first, because changing them later disrupts everything built on top.
Want the roadmap run for you?
Firms in the network take a cloud estate from phase one to fieldwork.
Get matched