Categories
Uncategorized

SOC 2 Readiness Guide

Ten years leading the IT side of SOC 2 compliance in life sciences, and a founding member of the compliance function we built to get there.

I documented it all down, and sharing what I think will help others.

A practical, field-tested guide to preparing for a SOC 2 audit, written from the perspective of an IT leader who has actually lived this process inside life sciences organization, not just read about it.

It covers the full standard SOC 2 body of knowledge, scoping, access control, change management, incident response, vendor risk, evidence collection, plus the parts most generic guides skip entirely: where SOC 2 overlaps with GxP, 21 CFR Part 11, and HIPAA, and how to build a program that satisfies all of it without duplicating work across teams.

Thirteen sections. Including policy templates. An evidence tracker and RACI matrix you can actually use. Free, open, on GitHub.

If you’re building or rebuilding a SOC 2 program right now, especially in a regulated space where GxP and SOC 2 have to coexist, I hope this saves you some of the harder lessons I had to learn the slow way.

And if you’re in the middle of it and want to talk through where you’re stuck, I’m here. Always happy to compare notes with someone doing this work.

https://jermsmit.github.io/soc2-readiness-guide

#SOC2 #LifeSciences #ITSecurity #Compliance #GRC #OpentoWork