A Useful Homelab Security Audit: What SOC 2 Checklists Don’t Test
Alex Kowalski
September 18, 2026
SOC 2 is a vendor conversation. It asks whether a company can tell a story about access reviews, change tickets, and a SOC that is not a Slack channel. A homelab is a house. The useful audit is not a mapped control. It is a walk that finds the port you forwarded in 2023, the camera that still has admin/admin, and the Vaultwarden container that shares a Docker bridge with the thing you told yourself was “just for testing.”
I have written real assessments for companies that needed a letter. I have also unplugged a homelab WAN because a checklist would have passed and a stranger on Shodan would not have cared. This is the second walk. If you want a logo, hire someone. If you want the house to be boring from the internet, test what the letter never names.
What the letter actually measures
SOC 2 Type I or II, for the shops that buy it, is about whether controls exist and whether they ran for a period. It is evidence. Screenshots of Jira. A list of leavers. An MDR invoice. It is not a proof that your Ubiquiti guest network isolates IoT, or that your kid’s laptop can reach the NAS share you named “private.” Auditors do not sit in your living room with nmap. They sit in a sample.
Home operators borrow the language anyway. “We have MFA.” “We have backups.” “We have a firewall.” Those sentences can be true and still leave UPnP on, IPv6 wide open, and SSH on a default port because a tutorial from 2019 said it was fine behind a “good” router. The checklist smiles. The WAN does not.
A useful homelab audit starts from the threat that is real here: opportunistic scan, a leaked credential from a random site, a family member who installs an “optimizer,” a cloud camera that phones home, and you on a tired Sunday. Nation-states are not your design center. Neither is a 200-page policy.

The walk I actually do
From a laptop that is not on the trusted LAN — phone hotspot, a neighbor, a travel SIM — I look at my public surface. If I cannot name every open port, I fail before I open a spreadsheet. IPv4 and IPv6. CGNAT can hide IPv4 and still leave IPv6 as a front door. I have seen people celebrate “no inbound” on the ISP app and forget the AAAA.
Then I sit on the LAN as a guest. Guest Wi-Fi that can see printers, Chromecasts, and the admin UI is a living room, not a guest. I try the IoT VLAN the way a cheap bulb would: can it reach luci, Proxmox, or the SMB share? If yes, the VLAN is a color on a switch diagram.
Then I sit as a family laptop. Work VPN on, random browser extensions, the password manager unlocked. Can that machine become the office? Usually yes. That is acceptable if you chose it. It is not acceptable if you wrote “zero trust” in a note and then shared a map drive to everyone because Plex was annoying.
Credentials the checklist never tastes
Default passwords on printers, NVRs, a travel router in a drawer that still gets plugged in, a UPS card, a switch that never got a unique login. I keep a list of every management plane and I log in once a year on purpose. If I cannot, the device is either forgotten or it is a museum piece on the LAN. Forgotten is worse.
Password reuse across the router, the NAS, and a forum account is still how houses get owned. A SOC 2 access review will not catch that you used the same string. A leak will. I want unique admin secrets and a vault I can open when the NAS is dead. If the vault is only on the NAS, the audit already failed for availability, which is a security property when the alternative is you resetting everything to factory and leaving WPS on “just to get Wi-Fi back.”
Service accounts in compose files that are still “changeme” because you meant to rotate. Tokens in git. A Telegram bot token in a ntfy shim from a weekend. I grep. I am not proud of what I still find.
The management plane is the product
luci, Unifi, Proxmox, TrueNAS, Portainer, Home Assistant — if any of those listen on an address a guest or a bulb can hit, you built a single pane of glass for an attacker who is already inside. Inside is not a rare story. Inside is a smart TV, a visitor, a malware on a teenager’s laptop.
I do not expose those UIs to WAN. I do not expose them to IoT. I use a jump that is not the router if I can help it, or a mesh that is not “allow all on tailnet.” Tailscale default ACLs that treat every device as friends are convenient. They are also a SOC-shaped sentence — “we use a zero-trust overlay” — that does not describe your house. If a phone can reach Proxmox because it is on the tailnet, say that out loud. Then decide.
UPnP and “automatic port mapping” for games and cameras are how a checklist that says “default deny” becomes a suggestion. I turn UPnP off. I get complaints. I live with them or I forward one port I can name.

Backups and the quiet second copy
Encrypted backups with the key on the same disk are a compliance story about “encryption at rest” that does not survive theft of the chassis. Offline or off-site with a key that is not on the chassis is the test. A SOC 2 sample might accept a vendor checkbox. Your house needs a restore that does not require the stolen box to still be yours.
I also ask: if ransomware hits the Windows PC, can it see the backup share? If the share is writable from every LAN member, you have a synchronized deletion service. Snapshots help. A pull backup from a host that the laptops cannot write to helps more. The letter will not model your SMB permissions. You should.
Updates that are not a ticket queue
Homelabs do not have change advisory boards. They have a Saturday. Unpatched Home Assistant, an old WordPress you forgot, a plugin on a self-hosted git, a camera firmware from the year the model shipped — those are the CVEs that land. I keep a short inventory: hostname, role, how it updates, last time I touched it. If I cannot list the containers, I cannot patch them. Portainer with twenty stacks I do not recognize is not a platform. It is a attic.
ISP router OTA is a separate mood. If that box is your only firewall, the vendor’s image is in scope. Bridge it if you can. The audit question is not “is there a patch program.” It is “who can change the firewall while I sleep.”
Logs that do not page anyone
Companies collect logs because the letter asks for monitoring. Homelabs collect logs because a YouTube video said Loki. I have run Promtail into a disk that filled and then I had neither logs nor room for photos. A useful audit asks who gets woken, for what, and whether that path works when the NAS is the patient. ntfy on the same host as the firewall is a diary, not a page.
I want one alert that means “the WAN changed or SSH got a hit I did not expect,” and I want it on a phone that is not silenced. I do not want a dashboard of 400 series from a camera that I already know is chatty. Volume is how you learn to ignore the one line that mattered.
What I skip on purpose
I skip writing a 40-control matrix. I skip pretending I have 24/7 monitoring. I skip pentest theater with a Kali ISO and a blog post. I skip “we encrypt DNS” as a substitute for “the admin UI is not on guest.” Those are the cargo-cult imports from the letter. They make you feel assessed. They do not close the camera.
I also skip chasing every IoT CVE on a bulb I will replace next year, if that bulb cannot reach anything that matters. Isolation is cheaper than firmware archaeology. If I cannot isolate it, I do not buy it, or I accept it as a toy on a VLAN I treat as hostile.
A one-hour list that is actually useful
Do this on a calendar, not after a scare:
- Public ports, IPv4 and IPv6, named or closed.
- UPnP off. Residual mappings gone.
- Guest and IoT cannot hit management or file shares.
- Every admin password unique, vault recoverable offline.
- No default creds on anything with an IP.
- WAN management closed. Overlay ACLs not “all to all” unless you mean it.
- Backup pull path that laptops cannot encrypt-sync to death.
- Container and appliance inventory with a last-patched date.
- Forwarded ports still have an owner and a reason.
- A family member cannot factory-reset the router to WPS-on without you noticing — or you accept that risk in writing, on paper, in the house.
If an item fails, fix it or write why you will live with it. An exception you can say out loud is better than a green checkbox you borrowed from a SaaS blog.
The decision
SOC 2 checklists test whether an organization can produce evidence. A homelab security audit tests whether a stranger, a guest, or a tired you can become the office. Walk from outside, from guest, from family. Count ports. Taste passwords. Pull the backup from a place the malware cannot see. Leave the letter for companies that sell software. For the house, usefulness is a dark WAN and a VLAN that is not a rumor.