A customer asked for your SOC 2. Get audit-ready before you spend $20,000.
A free self-assessment for the founder, operator, or first security hire who just got asked for a System and Organization Controls 2 (SOC 2) report. It scores you on the Readiness Ladder across eight control areas — scope, governance, access, change, vendors, monitoring, availability, and evidence — and shows the gaps to close first. With it comes a working toolkit: the readiness checklist and ladder worksheets, the policy set, the evidence tracker and risk register, and the audit-prep kit. The assessment runs in your browser. Your answers never leave your device.
Two free ways to see if the toolkit fits.
1. Take the free assessment
24 questions across the eight control areas our checklist covers on the way to a SOC 2 examination. About ten minutes. You get a weighted readiness score, a band on the six-rung Readiness Ladder — from "just getting started" to "audit-ready" — a breakdown by area, and the priority gaps to close first. Runs in your browser. No email required; nothing is sent anywhere.
Take the free assessment →2. Read the free guide
"Your First SOC 2 Moves" walks through what SOC 2 actually requires, how to scope it, and the first moves that close the most common gaps — before you spend $20K on a platform, a consultant, and an audit. Plain English, and yours to keep.
Read the free guide →This is for getting ready for a SOC 2 examination.
It closes the gaps across the eight control areas a System and Organization Controls 2 (SOC 2) audit tests, before you pay for the audit itself. If a customer simply sent you a security questionnaire to answer, TrustReady is the faster route; for a general security baseline, see the SMB Security Assessment.
Still deciding whether you need SOC 2 at all yet? That decision has its own essay — Do you actually need SOC 2 yet? — and if your buyers are European, so does the SOC 2 or ISO 27001 comparison. Read those first if the question is open; the toolkit is for after the answer is yes.
Three editions: one to get started, one to run the programme, one for the consultant who does this for a living.
- The SOC 2 Readiness Checklist — every control area, where you stand, and where the evidence lives
- The Readiness Ladder Worksheets — score each control, rank the gaps, build a dated plan with owners
- The SOC 2 Scoping Worksheet — which Trust Services Criteria apply, before you pay for more scope than you need (PDF and editable Excel)
- The Type I or Type II Decision Guide — the choice your customers actually care about, in plain English
- The Security Awareness Training Programme & Log — the recurring training control with a dated evidence log (PDF and editable Excel)
- The Core Security Policy Starter Set — the policies an auditor expects to see first, ready to adapt
Enough if you're early and need to understand SOC 2 and see your gaps before committing budget.
Buy Solo — $49- The Full Policy Template Set — the complete policy set, mapped to the Common Criteria
- The Evidence Tracker & Index — maps every control to the dated proof a Type II report rests on
- The Risk Assessment & Register Templates — the method and register auditors open with
- The Quarterly Access Review Runbook & Evidence Log — the recurring control most Type II exceptions trace back to (PDF and editable Excel)
- The Change-Management Evidence Guide — the lightweight record that satisfies the criteria without slowing shipping
- The Backup & Restore-Test Evidence Guide — the availability evidence a Type II report rests on
- The Onboarding & Offboarding Evidence Runbook — joiner and leaver records that hold up in fieldwork
- Everything in Solo
Choose this when you've scoped the work and need the documents to run the programme through your window.
Buy Team — $99- The System Description & Audit-Prep Kit — draft Section III and walk into fieldwork prepared
- The Vendor & Sub-Processor Management Set — the tiered register, reviews, and contract terms
- The SOC 2 ↔ ISO 27001 Crosswalk & Multi-Client Readiness Tracker — answer both frameworks once; track every client
- Choosing a SOC 2 Auditor & The Readiness Conversation — shortlist and price audit firms, and start fieldwork without surprises
- The Incident Response Evidence Pack — the incident records auditors sample against the criteria
- Everything in Solo and Team
Step up here if you answer to an auditor and a board, run SOC 2 and ISO 27001 together, or carry several clients.
Buy Pro — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the plain-English SOC 2 set behind this toolkit.
The books teach the judgement; the toolkit does the work with you. SOC 2 in Plain English walks a small team from "a customer asked" to audit-ready; the Operator's Workbook carries the templates.
If this is your situation, one of these usually is too
TrustReady — Security Questionnaire Response Kit
The same buyers who ask for your SOC 2 also send security questionnaires. TrustReady turns the evidence you build here into fast, consistent answers — the natural next step after readiness.
First 4 Hours — Incident Response
SOC 2 expects a written incident response plan that works. First 4 Hours is the plain-English playbook for the first hours of an incident — the operational depth behind that control.
The situations this toolkit is built for, written up.
Do you actually need SOC 2 yet? — ~7 min read.
SOC 2 or ISO 27001 — which one does your customer actually want? — ~7 min read.