July 2, 2026
SOC 1 vs SOC 2: Which Report Does Your Company Need?SOC 1 covers financial reporting controls; SOC 2 covers security and trust. A Colorado CPA firm explains which report your clients are…
Read more →
SOC Reporting
A readiness assessment is the audit before the audit. We find what would fail, defined by your scope and controls, and hand you a roadmap to fix issues.
Connect with an ExpertA SOC 2 readiness assessment is a pre-audit review that maps your existing controls to the Trust Services Criteria, finds the gaps an auditor would flag, and hands you a prioritized roadmap for closing them before your audit period begins. Some people call it a gap assessment. It produces no opinion: it tells you what would fail while you still have time to fix it, and it is the common first step before any SOC 1 or SOC 2 engagement.
Want a first look before talking to anyone? Our free interactive SOC 2 checklist builds a gap assessment from 23 questions about your environment, our guide to preparing for a SOC 2 audit step by step walks through the same five stages, and the 10 gaps we find most often covers what usually comes back.
Map your current controls to SOC criteria and surface exactly where documentation, design, or operating effectiveness falls short.
Define system boundaries and select the right Trust Services Criteria or control objectives before your audit period begins.
Receive a prioritized control listing with actionable remediation guidance, so your team knows exactly what to fix and in what order.
Set a realistic start date for your observation period with confidence, knowing your control environment is prepared for independent testing.

Licensed AICPA CPA Firm
Readiness assessments conducted by the same partners who will perform your SOC 1 or SOC 2 audit
The Full Route
Readiness is the first of three stops between where your controls are today and the report your largest customers will ask for.
You Are Here
4 to 8 weeks
We assist with mapping your controls to the Trust Services Criteria, surface every gap, and hand you a ranked remediation list.
Best if this is your first SOC 2, or you are not sure your controls would hold up under testing.
Next Stop
1 to 2 months
An independent opinion on whether your controls are suitably designed as of a single date.
Best if a stalled deal needs something formal now and an observation window would take too long.
See how our SOC 2 audits run →Final Stop
Typically 6 to 12 months
Evidence that your controls operated across an observation window, with a first window typically seen at 6 months to 12 months.
Best if you sell into larger organizations and want questionnaires answered before they are asked, year after year.
The report renews every year; the relationship runs straight through. Beyond issuance, the partner who signed your opinion is still the person you call in the off months with questions, whether the AICPA updates the SOC framework or you are considering updates with new services, so next year's audit starts smooth.
Why It Matters
Gaps cost time and money in fieldwork. Readiness finds them before the attestation engagement begins.
Honest Assessment Before Fieldwork
We evaluate your control environment the same way we would during an audit. You get a clear picture of where you stand.
Scoped to Your Actual Environment
We define boundaries and select criteria based on how your systems operate, not a generic template.
Feeds Directly into Your Audit
Our readiness assessments are designed to transition smoothly into the SOC 1 or SOC 2 engagement.
Start Here
A readiness assessment covers your system boundaries and scope, how your controls align to the Trust Services Criteria, and the policies, documentation, and evidence behind them.
A SOC readiness assessment is recommended for organizations going through their first audit or those that have made recent changes to their environment. This step helps identify what systems and services are in scope, how your internal controls align with the Trust Services Criteria, and where documentation or processes may need improvement. The readiness process sets the foundation for a smooth, efficient audit experience.
As part of a readiness assessment, Sage Audits will:
This phase is collaborative and consultative, typically 4 to 8 weeks for the assessment itself. With remediation, plan on 1 to 6 months before your audit period begins, depending on how quickly gaps close. Either way you get a clear roadmap toward a successful audit. Learn more about our phased audit approach →
Our Process
Readiness assessments typically run 4 to 8 weeks, and with remediation most teams plan on 1 to 6 months before the audit period begins, depending on priority.
Before we can assess your control environment, we need to understand what you've documented where you are in the process. Many organizations have strong controls that are simply underdocumented, and others have documentation that doesn't fit.
The core of a readiness assessment is mapping what you have to what the auditor will test. For SOC 2, that means the Trust Services Criteria. For SOC 1, that means your defined control objectives.
Defining what's in and out of scope during readiness prevents rework and ensures your audit period covers the right systems and services from day one.
The deliverable from a readiness assessment is a prioritized remediation roadmap that tells your team exactly where to focus.
After the remediation roadmap is delivered, we remain available to answer questions as your team works through the items, and there is more we can do to support your readiness than we list here. Ask us how we can help you get ready → When you're ready to begin the audit, we pick up where we left off. Learn more about our phased audit approach →
Two Ways to Start
You, 23 questions, and a personalized gap list built in your browser. No email, no call.
Try the interactive checklist →The partners who will test your controls review your environment, make the scoping calls, and rank the remediation work.
Right once an audit is on the calendar.
Budget
Readiness is priced by the same four drivers as the audit itself:
Systems in scope. How many systems sit inside the audit boundary, and how complex the infrastructure and processes behind them are.
Controls in scope. More controls means more mapping, and more gaps worth finding before the audit does.
Trust Services Categories. Every SOC 2 starts from Security, the common criteria, and expands to Availability, Processing Integrity, Confidentiality, or Privacy when the areas being tested call for them. Our guide explains all five →
Evidence maturity. How much of what an auditor needs already exists in usable form.
Most teams package readiness with the Type 1 and Type 2 in one fixed fee, quoted before work begins. See how engagements are priced →
What teams ask before they commit to a readiness assessment, answered plainly.
Talk to a PartnerA pre-audit review that maps your existing controls to the Trust Services Criteria, identifies the gaps an auditor would flag, and delivers a prioritized roadmap for closing them before your audit period begins.
It is not an audit and it produces no opinion. It tells you what would fail, and in what order to fix it, while you still have time to act.
In practice they describe the same engagement, and we use the terms interchangeably. A gap assessment names the output, which is the list of gaps between your controls today and what the audit will test. A readiness assessment names the purpose, which is getting you ready for the examination.
Either way the work covers scope definition, control mapping, evidence review and a remediation roadmap. If you want to see the kind of thing that comes back, we wrote up the 10 gaps we find most often.
The assessment itself typically runs 4 to 8 weeks.
Remediation is the variable part. Most teams plan on 1 to 6 months between the readiness readout and the start of their audit period, depending on how many gaps came back and how quickly the team can close them.
A prioritized control gap listing with specific remediation guidance for each item, categorized by severity so you know what has to be fixed before the audit and what is lower risk.
It also includes a recommended start date for your observation period and a readout session with your team to walk through the findings and answer questions.
It is not required. It is worth doing if this is your first SOC 2, if your environment has changed materially since the last one, or if you are not confident your controls would hold up under testing. If your controls are mature and already evidenced, you can go straight into the examination.
Gaps found during fieldwork cost far more time and money than gaps found before it, which is the whole argument for doing this first. Our step-by-step guide to preparing for a SOC 2 audit walks through what the work looks like if you want to attempt a first pass yourself.
Yes. The work is the same shape, but instead of mapping controls to the Trust Services Criteria we map them to the control objectives you define for the report, and scope centers on the processes that affect your customers' financial reporting.
If you are not sure whether your customers are asking for SOC 1 or SOC 2, that is worth a short conversation before scoping anything. Reach out and we'll point you in the right direction →
You can start with one, and it is free: our interactive SOC 2 checklist builds a personalized gap list from 23 questions about your environment.
A self-assessment tells you where you think you stand. A readiness assessment tells you where an auditor would say you stand, with the scoping decisions and remediation roadmap a checklist cannot make for you.
It depends on the size of your system boundary, the Trust Services Categories in scope, and how mature your evidence already is.
Most teams engage readiness packaged with the Type 1 and Type 2 examinations in one fixed fee quoted before work begins, rather than as a standalone line item. Our pricing page and its calculator show how the full engagement is scoped.
Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.
Real numbers, a real conversation with a qualified CPA. No obligation.
Why Sage Audits
Sage Audits is a licensed Colorado CPA firm and AICPA member serving SaaS and B2B technology companies nationwide.
Get a Fixed-Fee QuotePeople
A partner runs your engagement from scoping through report delivery, and the person signing the opinion is the person you talk to.
Pricing
One fixed fee, quoted before work begins, with no hourly meters.
Platform
Vanta, Drata, Secureframe, or spreadsheets: we start from the evidence you already have and build from there.
Timeline
Draft report within 2 weeks of fieldwork completion and the final report within 5 to 7 weeks of period end.
Perspectives