Twenty-four plain-English questions across the eight control areas our checklist covers on the way to a SOC 2 (System and Organization Controls 2) examination — scope, governance, access, change management, vendors and sub-processors, monitoring and incident response, availability, and evidence. You get a scored snapshot of where you sit on the Readiness Ladder, area by area. About ten minutes. No email required.
Plain-English readiness — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.
The eight control areas our checklist covers on the way to a SOC 2 examination. The assessment walks the same ground an auditor does: scope and the report you need (Type I versus Type II, and which Trust Services Criteria apply), governance and risk, access control and identity, change management and development, vendors and sub-processors, monitoring and incident response, availability, and evidence and continuous operation.
What you get. A weighted readiness score and your band on the six-rung Readiness Ladder — from just getting started to audit-ready — plus an area-by-area breakdown with plain-English next steps. One honest note from the books: the goal is a scope proportionate to your size and risk — a small team can be genuinely audit-ready without an enterprise control set.
What it isn't. This is general guidance. It is not a SOC 2 audit, not a readiness opinion from a licensed CPA (Certified Public Accountant) firm, and not legal advice. Every recommendation is optional. Following it can reduce common gaps but does not guarantee any audit outcome. Responsibility for your programme remains with you.
Everything behind this free assessment — the checklist, policy set, evidence tracker, and audit-prep kit that close the gaps before you spend $20,000. Three editions to fit how you work.
See the full toolkit & pricing →One-time purchase · files you own forever · 30-day money-back guarantee.