How This Works

Answer 24 questions across eight control areas — scope, governance and risk, access, change management, vendors, monitoring and incident response, availability, and evidence. Each takes 10–20 seconds. At the end you'll get a weighted readiness score, a band on the six-rung Readiness Ladder, a breakdown by area, and a recommended set of priority actions. Answer for the practice that is actually running today — not the policy that describes it. The questions reflect widely recognised SOC 2 practice; which recommendations fit your scope is your call.

Part 1 — Scope & the Report You Need

SOC 2 covers five criteria: Security (always), Availability, Confidentiality, Processing Integrity, and Privacy. Choosing scope first is what keeps the audit — and its cost — from ballooning.

A Type I is a point-in-time snapshot; a Type II covers a window (commonly 3–12 months). Most buyers ultimately want Type II — deciding the target makes the calendar real.

The system description is Section III of the report: the people, systems, data, and vendors it covers. Scope decides effort more than anything else.

Part 2 — Governance & Risk

Auditors open here, under the Common Criteria. A stale or missing risk assessment is a costly first impression.

"Everyone" owning security means no one does. Each control needs a named owner who would have to produce its evidence.

A policy that says one thing while the practice does another fails an audit. Write policies people actually follow.

Part 3 — Access Control & Identity

Access control is the most-sampled area in a typical audit, and MFA is the first thing checked. One afternoon of work that outlasts every other fix.

Leftover access for ex-staff is a classic finding and a real breach path. Access should be granted on a documented basis and removed on departure.

For a Type II, the evidence that the review ran each period is the control, not the review itself. Save the dated result somewhere durable.

Part 4 — Change Management & Development

Auditors test that the process ran, not just that it exists on paper. The record is what they sample.

Segregation of duties is ideal; where a small team can't, a documented compensating control (peer review, logged approvals) is what the auditor looks for.

Ticket history or pull-request logs kept across the window are the evidence that change management operated all year.

Part 5 — Risk, Vendors & Sub-Processors

Vendor estates outgrow their registers quietly. The auditor will ask for this list — and which vendors touch customer data.

Collecting a vendor's SOC 2 (or equivalent) is the standard evidence. Tier the effort to the sensitivity of the data they hold.

An assessment with no contract terms cannot be enforced. The notification clause decides whether you hear of a vendor's breach from them or from the news.

Part 6 — Monitoring, Logging & Incident Response

These logs are the forensic record an auditor and an incident both rely on. Retention across your window is what makes them evidence.

An alert in an unwatched console is not detection. Someone has to read them the day they arrive.

A written plan beats an improvised one every time it is needed, and SOC 2 expects one. The first version can be a single page.

Part 7 — Availability, Backups & Continuity

Backups you have never restored are a hope, not a control. A periodic, dated restore test is the evidence that matters.

If Availability is in scope, track uptime against a service-level objective and alert on it. If it is not in scope, this won't be tested in your report.

A short plan for what happens if a key system or vendor goes down covers the resilience the Common Criteria expects, even of a small team.

Part 8 — Evidence & Continuous Operation

A Type II proves a control ran across the whole window. Capturing dated records, exports, and logs as you go is the difference between a clean opinion and a scramble.

One table — each control, its evidence, and exactly where that evidence lives (a folder, a ticket queue, a dashboard). It is the spine of audit prep.

Score each control on the Readiness Ladder, rank the gaps, and give each a one-step plan, an owner, and a date. This is the heart of getting audit-ready.

Answer all 24 questions to see your report.

Your SOC 2 Readiness Results

0 / 58
Scope & the report you need
0 / 10
Governance & risk
0 / 8
Access control & identity
0 / 8
Change management & development
0 / 6
Risk, vendors & sub-processors
0 / 6
Monitoring, logging & incident response
0 / 6
Availability, backups & continuity
0 / 6
Evidence & continuous operation
0 / 8

The book series scores a programme by its weakest control area, not its average. Whatever your overall band, your lowest bars above are the recommended place to start.

Your Recommended Priority Actions

Ready to Close These Gaps?

The free assessment shows where you stand. The paid editions add the working documents — the readiness checklist and ladder worksheets, the policy set, the evidence tracker and risk register, the vendor set, and the system-description & audit-prep kit — so you have the artefacts, not just the score.

See the Editions + Toolkit →