← All postsHow-to

SOC 2 readiness assessment: finding the gaps before the auditor does

A readiness assessment is not part of the audit. It exists so that the audit does not become an expensive way of discovering you were not ready.

How-toS

A SOC 2 readiness assessment is a gap analysis performed before the audit itself: someone works through the trust services criteria you intend to be examined against, compares them to what your organisation actually does, and produces a list of what is missing. It is not an opinion, it is not filed anywhere, and it has no standing with a customer — its entire value is preventing the audit from finding those gaps instead.

Companies that skip it usually do so on the reasoning that the audit will identify the same issues. That is true and expensive. A Type 2 examination covers a period, so a control that was absent at the start of the window cannot be retroactively operated — and the answer to a failed period is to fix the control and observe a new period, which puts the report months later than the deal that needed it.

What a SOC 2 readiness assessment covers

  • Scope: which trust services criteria apply. Security is the common baseline; availability, confidentiality, processing integrity and privacy are added deliberately, not by default.
  • System boundary: which products, environments, and supporting infrastructure are in scope, and which are excluded.
  • Control mapping: for each criterion, the control that satisfies it and the evidence that would demonstrate it operating.
  • Policies: existence, approval, and evidence that people have read them.
  • Evidence generation: whether each control produces an artefact automatically, or whether somebody has to remember to screenshot something.
  • Subservice organisations: which providers you rely on, and whether their controls are carved out or included.
  • A remediation list with owners and dates, which is the actual deliverable.

Evidence is the constraint, not controls

Most organisations pursuing a first report already do the substantive things — access reviews happen, changes are reviewed, backups run. What is missing is evidence that the auditor can sample: a ticket showing the review occurred on a date, an approval recorded rather than given verbally, a log retained long enough to cover the period. Readiness work is therefore mostly about instrumenting existing practice so it leaves traces, which is a smaller and more tractable job than the phrase "implement controls" suggests.

Independence matters. Where the audit firm also performs the readiness work, there are limits on how much remediation they can do for you without impairing their independence for the examination. Ask how the firm handles it before engaging both from the same provider.

Choose the period deliberately

For a Type 2 the observation period is a decision, not a default. A shorter first period gets a report into customers’ hands sooner; a longer one is more credible with enterprise buyers and avoids an awkward gap at the next renewal. What matters more than the length is that every in-scope control is operating from day one of the window, because a control implemented halfway through produces an exception in the report regardless of how well it works afterwards.

Tracking the remediation

The output is a list with owners and dates, and it decays exactly like any other project list unless it is worked. Ettex Forms collects the assessment answers per criterion so the same structure is reusable at the next cycle, Ettex Board tracks remediation items to closure, and Ettex Records keeps the policies, evidence samples and the scope decisions per period — the file the security questionnaire draws on as well.

Being direct: this is forms and records, not compliance automation, and none of it is audit advice. The examination is performed by a CPA firm, readiness is usually done with a consultant or a compliance platform, and both are worth their cost when a deal depends on the report.

Frequently asked

What is a SOC 2 readiness assessment?

A pre-audit gap analysis comparing your controls and evidence against the trust services criteria in scope, producing a remediation list.

Is it part of the audit?

No. It has no standing with customers and produces no opinion. Its value is avoiding exceptions in the examination that follows.

Can our auditor do the readiness work?

Partly, with independence limits on how much remediation they can perform for you. Ask how the firm separates the two engagements.

What usually fails readiness?

Evidence rather than practice — controls that operate but leave no artefact an auditor can sample.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.