SOC 2

What is a SOC 2 readiness assessment?

A SOC 2 readiness assessment is a gap analysis you do before the formal audit: you compare your current controls and evidence against the Trust Services Criteria and identify what is missing or weak, so you can fix it before an auditor evaluates you. It is not the audit itself and produces no report customers can rely on; it is the preparation that makes the real audit go smoothly.

Step by step

  1. Set your scope. Decide which Trust Services Criteria apply (Security is required; add others that fit your commitments) and which systems are in scope.
  2. Map controls to the criteria. List your existing controls and map each to the criteria it satisfies, using a crosswalk so you can see coverage at a glance.
  3. Identify gaps. Find criteria with no control, controls with no evidence, and evidence that is stale. These are your remediation items.
  4. Remediate. Assign each gap an owner and a due date, implement the missing controls, and start collecting evidence.
  5. Confirm readiness. Re-check coverage and evidence, then engage an auditor for the formal Type I or Type II examination.

Why do it first

Going straight to an audit with unknown gaps wastes time and money. A readiness assessment surfaces the gaps while you can still fix them, so the formal audit is a confirmation rather than a surprise.

Readiness is not the audit

A readiness assessment can be done yourself or with help, but it is not an independent attestation. Only a licensed CPA firm performs the SOC 2 examination and issues the report.

FAQ

Can I do a readiness assessment myself?

Yes. Many teams run their own readiness assessment using a control-and-evidence platform that maps their posture to the Trust Services Criteria and flags gaps. You can also engage a firm to help.

How long does remediation take?

It depends on how many gaps you find. A program with controls already in place might need a few weeks; a team starting from scratch should plan for a few months before a Type II window.

Related

What is SOC 2? → How do I prepare for SOC 2? → Free readiness assessment tool →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free