SOC readiness assessment background

SOC Reporting

SOC 2 Readiness Assessment

A readiness assessment is the audit before the audit. We find what would fail, defined by your scope and controls, and hand you a roadmap to fix issues.

Connect with an Expert

A SOC 2 readiness assessment is a pre-audit review that maps your existing controls to the Trust Services Criteria, finds the gaps an auditor would flag, and hands you a prioritized roadmap for closing them before your audit period begins. Some people call it a gap assessment. It produces no opinion: it tells you what would fail while you still have time to fix it, and it is the common first step before any SOC 1 or SOC 2 engagement.

Want a first look before talking to anyone? Our free interactive SOC 2 checklist builds a gap assessment from 23 questions about your environment, our guide to preparing for a SOC 2 audit step by step walks through the same five stages, and the 10 gaps we find most often covers what usually comes back.

Gap Analysis

Map your current controls to SOC criteria and surface exactly where documentation, design, or operating effectiveness falls short.

Scope Definition

Define system boundaries and select the right Trust Services Criteria or control objectives before your audit period begins.

Remediation Roadmap

Receive a prioritized control listing with actionable remediation guidance, so your team knows exactly what to fix and in what order.

Audit-Ready Timeline

Set a realistic start date for your observation period with confidence, knowing your control environment is prepared for independent testing.

AICPA SOC for Service Organizations seal

Licensed AICPA CPA Firm
Readiness assessments conducted by the same partners who will perform your SOC 1 or SOC 2 audit

The Full Route

Readiness is stop one. Here is where the route leads.

Readiness is the first of three stops between where your controls are today and the report your largest customers will ask for.

  1. You Are Here

    Readiness Assessment

    4 to 8 weeks

    We assist with mapping your controls to the Trust Services Criteria, surface every gap, and hand you a ranked remediation list.

    Best if this is your first SOC 2, or you are not sure your controls would hold up under testing.

  2. Next Stop

    SOC 2 Type I

    1 to 2 months

    An independent opinion on whether your controls are suitably designed as of a single date.

    Best if a stalled deal needs something formal now and an observation window would take too long.

    See how our SOC 2 audits run →
  3. Final Stop

    SOC 2 Type II

    Typically 6 to 12 months

    Evidence that your controls operated across an observation window, with a first window typically seen at 6 months to 12 months.

    Best if you sell into larger organizations and want questionnaires answered before they are asked, year after year.

The report renews every year; the relationship runs straight through. Beyond issuance, the partner who signed your opinion is still the person you call in the off months with questions, whether the AICPA updates the SOC framework or you are considering updates with new services, so next year's audit starts smooth.

Why It Matters

Fix gaps on your schedule

Gaps cost time and money in fieldwork. Readiness finds them before the attestation engagement begins.

Honest Assessment Before Fieldwork

We evaluate your control environment the same way we would during an audit. You get a clear picture of where you stand.

Scoped to Your Actual Environment

We define boundaries and select criteria based on how your systems operate, not a generic template.

Feeds Directly into Your Audit

Our readiness assessments are designed to transition smoothly into the SOC 1 or SOC 2 engagement.

Start Here

SOC Readiness / GAP Assessments

A readiness assessment covers your system boundaries and scope, how your controls align to the Trust Services Criteria, and the policies, documentation, and evidence behind them.

A SOC readiness assessment is recommended for organizations going through their first audit or those that have made recent changes to their environment. This step helps identify what systems and services are in scope, how your internal controls align with the Trust Services Criteria, and where documentation or processes may need improvement. The readiness process sets the foundation for a smooth, efficient audit experience.

As part of a readiness assessment, Sage Audits will:

  • Review policies, procedures, and documentation related to your system and services.
  • Help define system boundaries and determine the appropriate scope for the engagement.
  • Align current control activities with the Trust Services Criteria (for SOC 2) or defined control objectives (for SOC 1).
  • Conduct interviews with control owners to understand how your environment is managed.
  • Identify gaps, weak spots, or missing evidence that could affect audit readiness.
  • Provide guidance on drafting the system description that will be included in your SOC Report.
  • Deliver a control listing with status indicators and practical remediation suggestions, so you know exactly where you stand.

This phase is collaborative and consultative, typically 4 to 8 weeks for the assessment itself. With remediation, plan on 1 to 6 months before your audit period begins, depending on how quickly gaps close. Either way you get a clear roadmap toward a successful audit. Learn more about our phased audit approach →

Our Process

What a Readiness Assessment Covers

Readiness assessments typically run 4 to 8 weeks, and with remediation most teams plan on 1 to 6 months before the audit period begins, depending on priority.

Not sure whether you need a SOC 1 or SOC 2 readiness assessment? The answer depends on your service and what your customers are asking for. Reach out and we'll point you in the right direction.

Before we can assess your control environment, we need to understand what you've documented where you are in the process. Many organizations have strong controls that are simply underdocumented, and others have documentation that doesn't fit.

  • Review of existing information security policies, access management procedures, and change management documentation.
  • Identification of documentation gaps that would need to be addressed before fieldwork begins.
  • Guidance on drafting a system description, a required component of every SOC 1 and SOC 2 Report.

The core of a readiness assessment is mapping what you have to what the auditor will test. For SOC 2, that means the Trust Services Criteria. For SOC 1, that means your defined control objectives.

  • Map existing controls to the applicable Trust Services Criteria (SOC 2) or control objectives (SOC 1).
  • Interview control owners to understand how controls operate in practice, not just on paper.
  • Identify controls that are missing, inadequately designed, or lacking sufficient evidence.
  • Flag areas where operating effectiveness may be difficult to demonstrate over an audit period.

Defining what's in and out of scope during readiness prevents rework and ensures your audit period covers the right systems and services from day one.

  • Define the system boundary: which infrastructure, applications, and processes are in scope.
  • Identify subservice organizations and assess whether carve-out or inclusive method is appropriate.
  • For SOC 2: confirm which Trust Services Criteria categories apply based on your service commitments.
  • For SOC 1: define the control objectives that will anchor the report and satisfy your clients' auditors.

The deliverable from a readiness assessment is a prioritized remediation roadmap that tells your team exactly where to focus.

  • Prioritized control gap listing with specific remediation guidance for each item.
  • Categorization by severity: items that must be addressed before audit, versus items that are lower risk.
  • Recommended timeline for when to start the audit observation period based on remediation progress.
  • Readout session with your team to walk through findings and answer questions.

After the remediation roadmap is delivered, we remain available to answer questions as your team works through the items, and there is more we can do to support your readiness than we list here. Ask us how we can help you get ready → When you're ready to begin the audit, we pick up where we left off. Learn more about our phased audit approach →

Step by Step

The SOC 2 Readiness Process

Six steps take a company from "we should probably do SOC 2" to a signed report. Readiness is the first two, remediation and evidence are where the work is, and the examination is the last. Each step has a deliverable you can hold in your hand.

  1. Scope the system

    Decide what the report is about before anyone maps a control: the product or service, the infrastructure and cloud accounts under it, the people and vendors who touch it, and which Trust Services Categories apply beyond Security.

    Deliverable: A written system boundary, a category selection, and an outline for the system description that becomes Section 3 of the report.

  2. Gap assessment

    Map the controls you already run to the Trust Services Criteria, read the policies and a sample of evidence behind each one, and interview the owners. This is the readiness assessment proper.

    Deliverable: A control gap listing ranked by severity: what must be fixed before the audit period, what should be, and what can wait.

  3. Remediation

    Write the missing policies, stand up the missing controls (access reviews, change approvals, vendor reviews, a documented risk assessment, an incident response plan, tested backups), and name an owner for each.

    Deliverable: A remediation tracker with every gap closed or accepted, and the first evidence that each new control actually operates.

  4. Evidence collection

    For every control, decide what evidence it produces and where that evidence lives: your compliance platform, your ticketing system, the cloud console, or a shared folder. Then capture it once, end to end.

    Deliverable: An evidence request list mapped to controls, populated once, so the audit is a refresh rather than a scramble.

  5. Observation window

    For a Type 2, the controls have to operate across a period. A first window can be as short as 3 months; we generally recommend 6 to 12. Keep the evidence flowing on its normal cadence and finish the system description.

    Deliverable: Dated evidence for each control across the whole period, and management's description ready to go into the report.

  6. The examination

    The attestation engagement itself: a licensed CPA firm tests design (Type 1) or design and operating effectiveness (Type 2), and issues an opinion. If readiness did its job, nothing in the findings is a surprise.

    Deliverable: Your SOC 2 report: the auditor's opinion, management's assertion, the system description, and the tests of controls.

Checklist

SOC 2 Readiness Checklist

What a first SOC 2 needs to have in place, grouped the way an auditor will ask about it. Security is the common criteria and applies to every report; the last group only matters when Availability or Confidentiality is in scope. Want it personalized? The interactive SOC 2 checklist builds a gap list from 23 questions about your environment, free and in your browser.

Governance and risk

  • Information security policies written, approved, and communicated to staff
  • A documented risk assessment, reviewed at least annually
  • Named control owners and a management review cadence
  • Security awareness training and background checks on record

Access control

  • MFA on the identity provider, cloud consoles, and code repositories
  • Role-based, least-privilege access with an approval trail
  • Quarterly access reviews with removals evidenced
  • Onboarding and offboarding checklists that close every account

Change management

  • Peer review on every production code change
  • CI/CD approvals and separation of duties between developer and deployer
  • Infrastructure changes ticketed, tested, and approved
  • Emergency change path defined and logged

Vendor and subservice management

  • A vendor inventory with data-access classification
  • Subservice organizations identified as carve-out or inclusive
  • SOC reports or equivalent assurance collected and reviewed annually
  • Security terms in vendor contracts

Monitoring and incident response

  • Centralized logging with alerting on the events that matter
  • Vulnerability scanning and patching on a defined cadence
  • An incident response plan that has been tested, plus an incident register
  • Annual penetration test if your customers expect one

Availability, data, and evidence

  • Backups configured and restore-tested; DR/BCP plan if Availability is in scope
  • Encryption in transit and at rest; data classification and retention rules
  • Evidence for every control stored where the auditor can sample it, dated and attributable

Two Ways to Start

Self-Assessment or Readiness Assessment?

Self-Assessment Free

You, 23 questions, and a personalized gap list built in your browser. No email, no call.

Try the interactive checklist →

CPA-Led Readiness Fixed Fee

The partners who will test your controls review your environment, make the scoping calls, and rank the remediation work.

Right once an audit is on the calendar.

Budget

What a Readiness Assessment Costs

Readiness is priced by the same four drivers as the audit itself:

Systems in scope. How many systems sit inside the audit boundary, and how complex the infrastructure and processes behind them are.

Controls in scope. More controls means more mapping, and more gaps worth finding before the audit does.

Trust Services Categories. Every SOC 2 starts from Security, the common criteria, and expands to Availability, Processing Integrity, Confidentiality, or Privacy when the areas being tested call for them. Our guide explains all five →

Evidence maturity. How much of what an auditor needs already exists in usable form.

Most teams package readiness with the Type 1 and Type 2 in one fixed fee, quoted before work begins. See how engagements are priced →

Readiness Frequently Asked Questions

What teams ask before they commit to a readiness assessment, answered plainly.

Talk to a Partner

A pre-audit review that maps your existing controls to the Trust Services Criteria, identifies the gaps an auditor would flag, and delivers a prioritized roadmap for closing them before your audit period begins.

It is not an audit and it produces no opinion. It tells you what would fail, and in what order to fix it, while you still have time to act.

In practice they describe the same engagement, and we use the terms interchangeably. A gap assessment names the output, which is the list of gaps between your controls today and what the audit will test. A readiness assessment names the purpose, which is getting you ready for the examination.

Either way the work covers scope definition, control mapping, evidence review and a remediation roadmap. If you want to see the kind of thing that comes back, we wrote up the 10 gaps we find most often.

The assessment itself typically runs 4 to 8 weeks.

Remediation is the variable part. Most teams plan on 1 to 6 months between the readiness readout and the start of their audit period, depending on how many gaps came back and how quickly the team can close them.

A prioritized control gap listing with specific remediation guidance for each item, categorized by severity so you know what has to be fixed before the audit and what is lower risk.

It also includes a recommended start date for your observation period and a readout session with your team to walk through the findings and answer questions.

It is not required. It is worth doing if this is your first SOC 2, if your environment has changed materially since the last one, or if you are not confident your controls would hold up under testing. If your controls are mature and already evidenced, you can go straight into the examination.

Gaps found during fieldwork cost far more time and money than gaps found before it, which is the whole argument for doing this first. Our step-by-step guide to preparing for a SOC 2 audit walks through what the work looks like if you want to attempt a first pass yourself.

Yes. The work is the same shape, but instead of mapping controls to the Trust Services Criteria we map them to the control objectives you define for the report, and scope centers on the processes that affect your customers' financial reporting.

If you are not sure whether your customers are asking for SOC 1 or SOC 2, that is worth a short conversation before scoping anything. Reach out and we'll point you in the right direction →

You can start with one, and it is free: our interactive SOC 2 checklist builds a personalized gap list from 23 questions about your environment.

A self-assessment tells you where you think you stand. A readiness assessment tells you where an auditor would say you stand, with the scoping decisions and remediation roadmap a checklist cannot make for you.

It depends on the size of your system boundary, the Trust Services Categories in scope, and how mature your evidence already is.

Most teams engage readiness packaged with the Type 1 and Type 2 examinations in one fixed fee quoted before work begins, rather than as a standalone line item. Our pricing page and its calculator show how the full engagement is scoped.

A SOC 2 assessment is a review of an organization's controls against the AICPA Trust Services Criteria. The term gets used two ways: a readiness assessment (or gap assessment) is the pre-audit review a company runs to find what would fail, and the SOC 2 examination is the attestation engagement in which a licensed CPA firm tests the controls and issues an opinion.

Only the examination produces a SOC 2 report. The readiness assessment tells you whether you are ready for it, and what to fix first.

How hard SOC 2 compliance is depends on how far your current practices sit from the criteria. Teams that already run MFA, peer-reviewed changes, vendor reviews, and a written risk assessment mostly need to document and evidence what they do; teams starting from scratch spend most of the effort building those routines.

Plan for a real time commitment from engineering and leadership during readiness (the readiness work alone typically takes at least 100 hours of your team's time), then a lighter steady state once evidence collection is routine. The framework is flexible about how you meet each criterion, which is what keeps it manageable: it asks whether your controls address the criteria, not whether you bought a specific tool.

A SOC 2 Type 2 compliance checklist is the list of controls, policies, and evidence a company needs to have operating across an observation period, not just designed at a point in time. It covers the same areas as a Type 1 checklist (governance, access, change management, risk and vendor management, monitoring, incident response, and any Availability, Confidentiality, Processing Integrity, or Privacy controls in scope) and adds the operating proof: dated access reviews, completed change tickets, tested backups, closed incidents, and training records collected throughout the period.

The checklist on this page covers the design side; the interactive SOC 2 checklist turns it into a personalized gap list.

Transparent Pricing

Get Your 
Custom Quote

Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.

Why Sage Audits

Big Four Training, Boutique Attention


20+Years of combined IT audit experience
0Junior staff on your engagement

Sage Audits is a licensed Colorado CPA firm and AICPA member serving SaaS and B2B technology companies nationwide.

Get a Fixed-Fee Quote

People

Work With the Partner Who Signs

A partner runs your engagement from scoping through report delivery, and the person signing the opinion is the person you talk to.

Pricing

Know Your Fee Before Work Begins

One fixed fee, quoted before work begins, with no hourly meters.

Platform

Keep the Stack You Already Run

Vanta, Drata, Secureframe, or spreadsheets: we start from the evidence you already have and build from there.

Timeline

Get the Draft in Two Weeks

Draft report within 2 weeks of fieldwork completion and the final report within 5 to 7 weeks of period end.

Perspectives

Latest from Sage Audits

Sage Audits Blog

Find the Gaps Early. Before They Find You.

Book a Free 30 Minute Consultation