Skip to content

SOC 2 Compliance Checklist: What Your Device Management Needs to Cover

Josh Caliguire
Josh Caliguire

If someone on your team recently mentioned SOC 2, or a potential customer asked if you're SOC 2 compliant, you've probably realized there's a lot more to it than just a certificate on your website.

SOC 2 (Service Organization Control 2) is a security framework that shows your customers and partners that you take data protection seriously. It's become a standard requirement for B2B SaaS companies, especially when selling to enterprise clients. And one of the areas that gets the most scrutiny during an audit? How you manage the devices your employees use every day.

Here's what you need to have in order on the device management side before you go into a SOC 2 audit, or before you start working toward one.

What Is SOC 2, in Plain Terms?

SOC 2 is basically a third-party stamp of approval that says: "This company has controls in place to protect customer data." Many enterprise buyers require it before signing a contract.

There are two types:

  • SOC 2 Type I — a snapshot in time. Do you have the right policies and controls in place?
  • SOC 2 Type II — a look over time (usually 6–12 months). Are those controls actually working?

Device management touches several of the core "trust service criteria" that SOC 2 auditors look at, specifically around security, availability, and confidentiality.

The Device Management Checklist

1. Every Device Is Enrolled in an MDM (Mobile Device Management) System

An MDM is software that lets you manage, monitor, and control company devices from one place. If you don't have one, you have no way to enforce any of the requirements below, and an auditor will flag it immediately.

Every Mac, iPhone, and iPad used for work should be enrolled. Personally-owned devices (called BYOD) used for work email or Slack need a policy too, even if they're not fully enrolled.

2. Disk Encryption Is Enabled on All Devices

If a laptop gets lost or stolen, encryption is what keeps company and customer data from walking out the door with it.

On Macs, this is called FileVault. On iPhones and iPads, encryption is on by default, but your MDM should confirm it's actually enabled and hasn't been turned off.

SOC 2 auditors will ask for evidence that encryption is enforced across your fleet, not just recommended.

3. Screen Lock and Password Policies Are Enforced

"We tell employees to use strong passwords" isn't enough. You need to be able to prove it's enforced.

Your MDM should push minimum requirements:

  • Password length and complexity
  • Auto-lock after a set period of inactivity (usually 5–15 minutes)
  • Lock screen requiring a password or biometric to unlock

4. Operating System and App Updates Are Managed

Outdated software is one of the most common ways attackers get in. SOC 2 requires that you have a process for keeping devices patched and up to date.

Your MDM should let you see which devices are running outdated software and push updates, or at minimum alert users and enforce a deadline.

5. You Can Remotely Wipe a Device

When an employee leaves, their device needs to be wiped whether they return it or not. SOC 2 auditors will want to know you have the ability to remotely wipe a device if it's lost, stolen, or an employee is offboarded.

Without an MDM, this isn't possible. With one, it's a button click.

6. Device Inventory Is Current and Accurate

You need to know exactly what devices exist in your company, who has them, and what state they're in. This sounds simple, but for fast-growing companies, it's surprisingly easy to lose track.

A good MDM gives you a live inventory: serial numbers, OS versions, enrollment status, last check-in. Auditors will ask for this list.

7. Offboarding Procedures Are Documented and Followed

When someone leaves your company, what happens to their device access? Their email? Their app logins?

SOC 2 requires a documented offboarding process that includes:

  • Revoking access to company systems
  • Removing the device from your MDM (or wiping it)
  • Retrieving company-owned equipment

This is one of the most common gaps we see in growing companies. It works fine with 10 people. By 40, it's a mess.

8. Software on Devices Is Monitored and Controlled

Are employees installing random apps on company laptops? Are they using unauthorized tools that could expose company data?

SOC 2 requires that you have visibility into what's installed and a policy around it. Your MDM should give you a software inventory and the ability to block or approve applications.

9. AI Tools Are Covered by Your Device and Data Policy

This one is newer, but auditors are starting to pay attention. If your employees are using AI tools like ChatGPT, Copilot, or Claude for work, you need a policy that addresses:

  • What data can be entered into these tools
  • Whether company or customer data is being used to train external models
  • Which tools are approved vs. unsanctioned

As AI becomes part of everyday work, device and data policies that don't address it are going to stick out in an audit.

Real Infrastructure Needs Protection.

SOC 2 compliance is a signal to your customers that you've built real infrastructure around protecting their data. Device management is one of the most concrete, visible parts of that.

If you have the right MDM in place and someone actively managing it, most of the items on this list are either automatic or easy to enforce. The hard part is doing it before your first audit, not scrambling through it afterward.

If you're not sure where your company stands, we offer a free MDM health check that gives you a clear picture of what's covered and what's not. Reach out if you're interested.


Phalanx Management helps growing tech companies manage their devices, stay secure, and stay compliant. Based in Colorado, we work with SaaS and tech teams who are ready to take IT seriously without hiring a full internal team.

Share this post