SOC 2 Audit-Readiness Assessment

A customer asked for your SOC 2. Get audit-ready before you spend $20,000.

A free self-assessment for the founder, operator, or first security hire who just got asked for a System and Organization Controls 2 (SOC 2) report. It scores you on the Readiness Ladder across eight control areas — scope, governance, access, change, vendors, monitoring, availability, and evidence — and shows the gaps to close first. With it comes a working toolkit: the readiness checklist and ladder worksheets, the policy set, the evidence tracker and risk register, and the audit-prep kit. The assessment runs in your browser. Your answers never leave your device.

Free first

Two free ways to see if the toolkit fits.

1. Take the free assessment

24 questions across the eight control areas our checklist covers on the way to a SOC 2 examination. About ten minutes. You get a weighted readiness score, a band on the six-rung Readiness Ladder — from "just getting started" to "audit-ready" — a breakdown by area, and the priority gaps to close first. Runs in your browser. No email required; nothing is sent anywhere.

Take the free assessment →

2. Read the free guide

"Your First SOC 2 Moves" walks through what SOC 2 actually requires, how to scope it, and the first moves that close the most common gaps — before you spend $20K on a platform, a consultant, and an audit. Plain English, and yours to keep.

Read the free guide →
Who this is for

This is for getting ready for a SOC 2 examination.

It closes the gaps across the eight control areas a System and Organization Controls 2 (SOC 2) audit tests, before you pay for the audit itself. If a customer simply sent you a security questionnaire to answer, TrustReady is the faster route; for a general security baseline, see the SMB Security Assessment.

Still deciding whether you need SOC 2 at all yet? That decision has its own essay — Do you actually need SOC 2 yet? — and if your buyers are European, so does the SOC 2 or ISO 27001 comparison. Read those first if the question is open; the toolkit is for after the answer is yes.

Pick a tier

Three editions: one to get started, one to run the programme, one for the consultant who does this for a living.

Solo
$49one-time
For the founder or first hire who just got asked for a SOC 2 and needs to know what's required and where they stand.
  • The SOC 2 Readiness Checklist — every control area, where you stand, and where the evidence lives
  • The Readiness Ladder Worksheets — score each control, rank the gaps, build a dated plan with owners
  • The SOC 2 Scoping Worksheet — which Trust Services Criteria apply, before you pay for more scope than you need (PDF and editable Excel)
  • The Type I or Type II Decision Guide — the choice your customers actually care about, in plain English
  • The Security Awareness Training Programme & Log — the recurring training control with a dated evidence log (PDF and editable Excel)
  • The Core Security Policy Starter Set — the policies an auditor expects to see first, ready to adapt

Enough if you're early and need to understand SOC 2 and see your gaps before committing budget.

Buy Solo — $49
Pro
$299one-time
For the fractional Chief Information Security Officer (CISO), consultant, or managed service provider (MSP) running readiness for one demanding programme, or several clients at once.
  • The System Description & Audit-Prep Kit — draft Section III and walk into fieldwork prepared
  • The Vendor & Sub-Processor Management Set — the tiered register, reviews, and contract terms
  • The SOC 2 ↔ ISO 27001 Crosswalk & Multi-Client Readiness Tracker — answer both frameworks once; track every client
  • Choosing a SOC 2 Auditor & The Readiness Conversation — shortlist and price audit firms, and start fieldwork without surprises
  • The Incident Response Evidence Pack — the incident records auditors sample against the criteria
  • Everything in Solo and Team

Step up here if you answer to an auditor and a board, run SOC 2 and ISO 27001 together, or carry several clients.

Buy Pro — $299

Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.

How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.

From Sylvan Press

The companion books: the plain-English SOC 2 set behind this toolkit.

The books teach the judgement; the toolkit does the work with you. SOC 2 in Plain English walks a small team from "a customer asked" to audit-ready; the Operator's Workbook carries the templates.

Plain-English readiness tools that never see your data.

The free SOC 2 readiness self-assessment scores you in the browser. We do not collect your answers, your score, or your gap list. We collect your email address only if you choose to enter it for the free guide. Nothing else.

Our website uses Cloudflare's server-side traffic counts for page totals — no scripts added to the page, no cookies, no data that identifies you.

From the blog

The situations this toolkit is built for, written up.

Do you actually need SOC 2 yet? — ~7 min read.

SOC 2 or ISO 27001 — which one does your customer actually want? — ~7 min read.