SOC 2 Readiness Assessment Guide
A readiness assessment is your dress rehearsal for the SOC 2 audit. Done well, it surfaces every gap with time to fix. Here is how to scope and execute one that adds real value.
Why Readiness Assessment Matters
A readiness assessment simulates the formal SOC 2 audit before the audit happens. The reviewer (often the same firm that will do your audit, or a separate consultant) runs through the Trust Services Criteria, samples your evidence, and tests your controls. The output is a gap list with severity ratings and remediation recommendations.
The value: every gap you fix during readiness becomes a finding you avoid during audit. For first-time SOC 2 programs, readiness typically surfaces 20-50 gaps, many of them controls you thought were operating but were not, or evidence you thought you had but did not.
The cost: $15K-$40K depending on scope. Worth it for first-year programs. Less essential for renewal cycles where you have a reliable evidence pipeline.
Use the readiness output to refine your SOC 2 framework alignment before fieldwork begins.
Scope and Timing
Run the readiness assessment 60-120 days before your formal audit fieldwork starts. This window gives you time to remediate findings, capture remediation evidence, and demonstrate the fixed controls operating before the audit period begins.
Scope considerations:
- Same TSC as the formal audit: Test the same Trust Service Criteria you plan to include. Adding criteria during the formal audit that were not tested in readiness leads to surprises.
- Same system boundary: The system description used in readiness should match what goes into the audit.
- Sampling depth: Readiness reviewers typically sample 1-2 instances per control vs. 25-40 in a formal audit. The goal is to find systemic gaps, not exhaustively test.
Some companies do a partial readiness focused only on the criteria where they expect issues (e.g., access reviews and change management). This costs less but misses gaps in other areas. Full-scope readiness is the safer choice for first-year programs.
What Readiness Typically Finds
The most common gap categories in first-year readiness assessments:
- Access reviews not completed or not documented: Quarterly reviews are committed to in policy but not consistently performed
- Change management without ticketing trail: Code merges happen but the approval and review evidence is not captured
- Vendor management gaps: Critical vendors have no risk assessment, no SOC 2 review, no contract clauses
- Onboarding and offboarding inconsistencies: Some hires have full provisioning, others are missing access controls
- Incident response without exercise: IR plan exists but has not been tabletop-tested
- Vulnerability management without remediation tracking: Scanning runs but findings are not closed in a tracked timeline
- Backup testing not performed: Backups happen but recovery has never been tested
If you can address these seven proactively before readiness, you save time and money in the assessment itself.
Remediation Planning
The readiness output is a gap report. Each gap needs a remediation plan with three elements:
- Immediate fix: Close the control gap technically. Implement the missing control, fix the broken process, capture the missing evidence.
- Backfill: Where possible, retroactively generate evidence for the audit period leading up to remediation. For some controls (access reviews, training), you can document the activity for past periods.
- Forward operation: Operate the control consistently from the remediation date through audit fieldwork and beyond.
Prioritize remediation by audit risk. Critical findings (gaps that would result in qualified opinions) come first. Significant findings come second. Minor observations can be addressed during fieldwork.
Set a target date for remediation completion at least 30 days before audit fieldwork starts. This gives you a buffer to capture evidence of remediated controls operating consistently.
From Readiness to Audit
The transition from readiness to formal audit should be smooth if remediation is on track. Track these signals as you approach audit fieldwork:
- All critical and significant findings closed: Verified with evidence
- Evidence pipeline operating: New evidence accumulating consistently
- Controls running on schedule: Quarterly reviews, monthly scans, and other periodic controls executing on time
- System description finalized: Updated to reflect any scope or boundary changes from readiness
- Audit team briefed: Internal owners know who is accountable for which control during fieldwork
If material findings remain unclosed at the start of fieldwork, talk to the auditor. They may agree to defer fieldwork by a few weeks if remediation is in progress, or to scope the audit period to start after remediation completion. Better to delay fieldwork by 30 days than to receive a qualified opinion.
Frequently Asked Questions
Related Articles
SOC 2 Compliance Checklist
A SOC 2 audit covers controls across the Trust Service Criteria you select. This checklist walks through every step from scoping to report issuance.
SOC 2 Type I vs Type II
Type I tests control design at a point in time. Type II tests operating effectiveness across an audit period. Here is what each one proves and which one matters to your customers.
SOC 2 Evidence Collection Best Practices
Audit speed and quality depend on evidence quality. These patterns let you collect evidence continuously, name it consistently, and produce it on demand during fieldwork.