Executive self-assessment

SOC 2 Readiness Assessment

Identify whether your SaaS or technology company has the governance and evidence foundation needed for a SOC 2 examination.

Result logic

What this tool evaluates

Evaluates SOC 2 scoping, control operation, evidence, access, change, incident, vendor, and assurance readiness.

Scope & criteria 18%
Control ownership 24%
Evidence 24%
Security operations 20%
Third parties 14%
0 / 10
0%
01 Is the SOC 2 system boundary and customer-facing service scope documented?
02 Have the applicable Trust Services Criteria been deliberately selected?
03 Does each key control have an accountable owner and operating frequency?
04 Can controls produce repeatable evidence for the entire intended observation period?
05 Are privileged access, joiner/mover/leaver, and periodic access reviews consistently evidenced?
06 Are production changes approved, tested, traceable, and separated appropriately?
07 Has incident response been tested and are lessons/actions tracked?
08 Are critical vendors/subservice organizations risk-reviewed and contractually governed?
09 Are security training, policy acknowledgement, vulnerability, backup, and monitoring records retained consistently?
10 Can customer security questionnaires be answered from the same control truth and evidence used for SOC 2?