SOC 2

    SOC 2 Readiness Assessment: What It Covers, Cost, Timeline and Deliverables

    ICyberWave Editorial
    Sep 28, 2026
    SOC 2
    SOC 2 readiness dashboard showing controls being checked off along an audit timeline

    A SOC 2 readiness assessment is a pre-audit review that tells you, before a CPA firm does, whether your controls would pass. It is the cheapest way to avoid exceptions in your first SOC 2 report — and the step most first-time companies skip.

    What a SOC 2 readiness assessment is (and is not)

    A readiness assessment compares your current controls against the AICPA Trust Services Criteria (TSC) you plan to put in scope. It is not an attestation: no opinion is issued and the result cannot be shared with customers as a SOC 2 report. Its output is a gap list and a remediation plan.

    Readiness assessmentSOC 2 Type 1SOC 2 Type 2
    Performed byConsultant or CPA firmIndependent CPA firmIndependent CPA firm
    OutputGap report + roadmapOpinion on design at a point in timeOpinion on design and operating effectiveness over 3–12 months
    Shareable with customersNoYesYes
    Typical duration2–6 weeks4–8 weeksObservation window + 4–8 weeks

    What the assessor actually reviews

    1. Scope and system description Which products, environments, locations and subservice organizations (AWS, Azure, GCP, payroll providers) are in scope. A vague scope is the number one cause of rework later.

    2. Trust Services Criteria selection Security (Common Criteria CC1–CC9) is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional — add them only when customers ask for them.

    3. Control design walkthroughs For each criterion, the assessor asks: is there a control, who owns it, how often does it run, and what evidence does it leave behind?

    4. Evidence sampling A good readiness review pulls sample evidence the way an auditor would: access reviews, onboarding and offboarding tickets, change approvals, vulnerability scans, backup restore tests and vendor reviews.

    The gaps we find most often

    • Access reviews exist but are not documented or signed off
    • Offboarding takes longer than the policy says (often days, not hours)
    • Changes deployed without recorded peer review or approval
    • No formal risk assessment in the last 12 months
    • Vendor risk management limited to a spreadsheet with no reviews
    • Security awareness training not tracked per employee
    • Incident response plan never tested with a tabletop exercise
    • Policies written but not approved or acknowledged by staff

    Realistic timeline

    1. Weeks 1–2: scoping, TSC selection, interviews
    2. Weeks 2–4: control walkthroughs and evidence sampling
    3. Week 4–6: gap report and prioritized remediation plan
    4. Months 2–4: remediation and tool rollout
    5. Then: Type 1 audit, or start the Type 2 observation window (commonly 3–6 months for a first report)

    What drives cost

    Cost depends on company size, number of systems, criteria in scope, how much documentation already exists, and whether you use a compliance automation platform. A readiness assessment is usually a fraction of the audit fee — and it typically saves more than it costs by preventing exceptions and a repeat observation period.

    Deliverables you should insist on

    • Scope statement and draft system description outline
    • Control matrix mapped to each TSC point of focus
    • Gap register with owner, priority and target date
    • Evidence request list matching what your auditor will ask for
    • Remediation roadmap aligned to your audit date

    Readiness to report: how to avoid exceptions

    Start the observation window only after remediated controls have run at least once with evidence. Automate evidence collection where possible, keep a single owner per control, and run a mini internal review a month before fieldwork. See our SOC 2 compliance checklist for the full control and evidence list, and SOC 2 vs ISO 27001 if you are still choosing a framework.

    FAQs

    Is a SOC 2 readiness assessment mandatory? No, but it is strongly recommended for a first report. Auditors cannot help you design controls without impairing their independence, so readiness is where remediation advice happens.

    Can the same firm do readiness and the audit? A CPA firm can perform readiness, but it cannot design or implement your controls and then audit them. Many companies use a consultant for readiness and a separate CPA firm for the attestation.

    Should we go for Type 1 or Type 2 first? If a customer deal needs a report quickly, Type 1 is faster. If customers accept a short wait, going straight to a 3-month Type 2 avoids paying for two audits.

    Need help? ICyberWave provides SOC 2 readiness, implementation and audit support — talk to our team.

    Hi! I'm your AI Assistant 💬