SOC readiness assessment background

SOC Reporting

SOC 2 Readiness Assessment

A readiness assessment is the audit before the audit. We find what would fail, defined by your scope and controls, and hand you a roadmap to fix issues.

Connect with an Expert

A SOC 2 readiness assessment is a pre-audit review that maps your existing controls to the Trust Services Criteria, finds the gaps an auditor would flag, and hands you a prioritized roadmap for closing them before your audit period begins. Some people call it a gap assessment. It produces no opinion: it tells you what would fail while you still have time to fix it, and it is the common first step before any SOC 1 or SOC 2 engagement.

Want a first look before talking to anyone? Our free interactive SOC 2 checklist builds a gap assessment from 23 questions about your environment, our guide to preparing for a SOC 2 audit step by step walks through the same five stages, and the 10 gaps we find most often covers what usually comes back.

Gap Analysis

Map your current controls to SOC criteria and surface exactly where documentation, design, or operating effectiveness falls short.

Scope Definition

Define system boundaries and select the right Trust Services Criteria or control objectives before your audit period begins.

Remediation Roadmap

Receive a prioritized control listing with actionable remediation guidance, so your team knows exactly what to fix and in what order.

Audit-Ready Timeline

Set a realistic start date for your observation period with confidence, knowing your control environment is prepared for independent testing.

AICPA SOC for Service Organizations seal

Licensed AICPA CPA Firm
Readiness assessments conducted by the same partners who will perform your SOC 1 or SOC 2 audit

The Full Route

Readiness is stop one. Here is where the route leads.

Readiness is the first of three stops between where your controls are today and the report your largest customers will ask for.

  1. You Are Here

    Readiness Assessment

    4 to 8 weeks

    We assist with mapping your controls to the Trust Services Criteria, surface every gap, and hand you a ranked remediation list.

    Best if this is your first SOC 2, or you are not sure your controls would hold up under testing.

  2. Next Stop

    SOC 2 Type I

    1 to 2 months

    An independent opinion on whether your controls are suitably designed as of a single date.

    Best if a stalled deal needs something formal now and an observation window would take too long.

    See how our SOC 2 audits run →
  3. Final Stop

    SOC 2 Type II

    Typically 6 to 12 months

    Evidence that your controls operated across an observation window, with a first window typically seen at 6 months to 12 months.

    Best if you sell into larger organizations and want questionnaires answered before they are asked, year after year.

The report renews every year; the relationship runs straight through. Beyond issuance, the partner who signed your opinion is still the person you call in the off months with questions, whether the AICPA updates the SOC framework or you are considering updates with new services, so next year's audit starts smooth.

Why It Matters

Fix gaps on your schedule

Gaps cost time and money in fieldwork. Readiness finds them before the attestation engagement begins.

Honest Assessment Before Fieldwork

We evaluate your control environment the same way we would during an audit. You get a clear picture of where you stand.

Scoped to Your Actual Environment

We define boundaries and select criteria based on how your systems operate, not a generic template.

Feeds Directly into Your Audit

Our readiness assessments are designed to transition smoothly into the SOC 1 or SOC 2 engagement.

Start Here

SOC Readiness / GAP Assessments

A readiness assessment covers your system boundaries and scope, how your controls align to the Trust Services Criteria, and the policies, documentation, and evidence behind them.

A SOC readiness assessment is recommended for organizations going through their first audit or those that have made recent changes to their environment. This step helps identify what systems and services are in scope, how your internal controls align with the Trust Services Criteria, and where documentation or processes may need improvement. The readiness process sets the foundation for a smooth, efficient audit experience.

As part of a readiness assessment, Sage Audits will:

  • Review policies, procedures, and documentation related to your system and services.
  • Help define system boundaries and determine the appropriate scope for the engagement.
  • Align current control activities with the Trust Services Criteria (for SOC 2) or defined control objectives (for SOC 1).
  • Conduct interviews with control owners to understand how your environment is managed.
  • Identify gaps, weak spots, or missing evidence that could affect audit readiness.
  • Provide guidance on drafting the system description that will be included in your SOC Report.
  • Deliver a control listing with status indicators and practical remediation suggestions, so you know exactly where you stand.

This phase is collaborative and consultative, typically 4 to 8 weeks for the assessment itself. With remediation, plan on 1 to 6 months before your audit period begins, depending on how quickly gaps close. Either way you get a clear roadmap toward a successful audit. Learn more about our phased audit approach →

Our Process

What a Readiness Assessment Covers

Readiness assessments typically run 4 to 8 weeks, and with remediation most teams plan on 1 to 6 months before the audit period begins, depending on priority.

Not sure whether you need a SOC 1 or SOC 2 readiness assessment? The answer depends on your service and what your customers are asking for. Reach out and we'll point you in the right direction.

Before we can assess your control environment, we need to understand what you've documented where you are in the process. Many organizations have strong controls that are simply underdocumented, and others have documentation that doesn't fit.

  • Review of existing information security policies, access management procedures, and change management documentation.
  • Identification of documentation gaps that would need to be addressed before fieldwork begins.
  • Guidance on drafting a system description, a required component of every SOC 1 and SOC 2 Report.

The core of a readiness assessment is mapping what you have to what the auditor will test. For SOC 2, that means the Trust Services Criteria. For SOC 1, that means your defined control objectives.

  • Map existing controls to the applicable Trust Services Criteria (SOC 2) or control objectives (SOC 1).
  • Interview control owners to understand how controls operate in practice, not just on paper.
  • Identify controls that are missing, inadequately designed, or lacking sufficient evidence.
  • Flag areas where operating effectiveness may be difficult to demonstrate over an audit period.

Defining what's in and out of scope during readiness prevents rework and ensures your audit period covers the right systems and services from day one.

  • Define the system boundary: which infrastructure, applications, and processes are in scope.
  • Identify subservice organizations and assess whether carve-out or inclusive method is appropriate.
  • For SOC 2: confirm which Trust Services Criteria categories apply based on your service commitments.
  • For SOC 1: define the control objectives that will anchor the report and satisfy your clients' auditors.

The deliverable from a readiness assessment is a prioritized remediation roadmap that tells your team exactly where to focus.

  • Prioritized control gap listing with specific remediation guidance for each item.
  • Categorization by severity: items that must be addressed before audit, versus items that are lower risk.
  • Recommended timeline for when to start the audit observation period based on remediation progress.
  • Readout session with your team to walk through findings and answer questions.

After the remediation roadmap is delivered, we remain available to answer questions as your team works through the items, and there is more we can do to support your readiness than we list here. Ask us how we can help you get ready → When you're ready to begin the audit, we pick up where we left off. Learn more about our phased audit approach →

Two Ways to Start

Self-Assessment or Readiness Assessment?

Self-Assessment Free

You, 23 questions, and a personalized gap list built in your browser. No email, no call.

Try the interactive checklist →

CPA-Led Readiness Fixed Fee

The partners who will test your controls review your environment, make the scoping calls, and rank the remediation work.

Right once an audit is on the calendar.

Budget

What a Readiness Assessment Costs

Readiness is priced by the same four drivers as the audit itself:

Systems in scope. How many systems sit inside the audit boundary, and how complex the infrastructure and processes behind them are.

Controls in scope. More controls means more mapping, and more gaps worth finding before the audit does.

Trust Services Categories. Every SOC 2 starts from Security, the common criteria, and expands to Availability, Processing Integrity, Confidentiality, or Privacy when the areas being tested call for them. Our guide explains all five →

Evidence maturity. How much of what an auditor needs already exists in usable form.

Most teams package readiness with the Type 1 and Type 2 in one fixed fee, quoted before work begins. See how engagements are priced →

Readiness Frequently Asked Questions

What teams ask before they commit to a readiness assessment, answered plainly.

Talk to a Partner

A pre-audit review that maps your existing controls to the Trust Services Criteria, identifies the gaps an auditor would flag, and delivers a prioritized roadmap for closing them before your audit period begins.

It is not an audit and it produces no opinion. It tells you what would fail, and in what order to fix it, while you still have time to act.

In practice they describe the same engagement, and we use the terms interchangeably. A gap assessment names the output, which is the list of gaps between your controls today and what the audit will test. A readiness assessment names the purpose, which is getting you ready for the examination.

Either way the work covers scope definition, control mapping, evidence review and a remediation roadmap. If you want to see the kind of thing that comes back, we wrote up the 10 gaps we find most often.

The assessment itself typically runs 4 to 8 weeks.

Remediation is the variable part. Most teams plan on 1 to 6 months between the readiness readout and the start of their audit period, depending on how many gaps came back and how quickly the team can close them.

A prioritized control gap listing with specific remediation guidance for each item, categorized by severity so you know what has to be fixed before the audit and what is lower risk.

It also includes a recommended start date for your observation period and a readout session with your team to walk through the findings and answer questions.

It is not required. It is worth doing if this is your first SOC 2, if your environment has changed materially since the last one, or if you are not confident your controls would hold up under testing. If your controls are mature and already evidenced, you can go straight into the examination.

Gaps found during fieldwork cost far more time and money than gaps found before it, which is the whole argument for doing this first. Our step-by-step guide to preparing for a SOC 2 audit walks through what the work looks like if you want to attempt a first pass yourself.

Yes. The work is the same shape, but instead of mapping controls to the Trust Services Criteria we map them to the control objectives you define for the report, and scope centers on the processes that affect your customers' financial reporting.

If you are not sure whether your customers are asking for SOC 1 or SOC 2, that is worth a short conversation before scoping anything. Reach out and we'll point you in the right direction →

You can start with one, and it is free: our interactive SOC 2 checklist builds a personalized gap list from 23 questions about your environment.

A self-assessment tells you where you think you stand. A readiness assessment tells you where an auditor would say you stand, with the scoping decisions and remediation roadmap a checklist cannot make for you.

It depends on the size of your system boundary, the Trust Services Categories in scope, and how mature your evidence already is.

Most teams engage readiness packaged with the Type 1 and Type 2 examinations in one fixed fee quoted before work begins, rather than as a standalone line item. Our pricing page and its calculator show how the full engagement is scoped.

Transparent Pricing

Get Your 
Custom Quote

Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.

Why Sage Audits

Big Four Training, Boutique Attention


20+Years of combined IT audit experience
0Junior staff on your engagement

Sage Audits is a licensed Colorado CPA firm and AICPA member serving SaaS and B2B technology companies nationwide.

Get a Fixed-Fee Quote

People

Work With the Partner Who Signs

A partner runs your engagement from scoping through report delivery, and the person signing the opinion is the person you talk to.

Pricing

Know Your Fee Before Work Begins

One fixed fee, quoted before work begins, with no hourly meters.

Platform

Keep the Stack You Already Run

Vanta, Drata, Secureframe, or spreadsheets: we start from the evidence you already have and build from there.

Timeline

Get the Draft in Two Weeks

Draft report within 2 weeks of fieldwork completion and the final report within 5 to 7 weeks of period end.

Perspectives

Latest from Sage Audits

View All Posts

Find the Gaps Early. Before They Find You.

Book a Free 30 Minute Consultation