A SOC 2 readiness assessment is a pre-audit review that tells you, before a CPA firm does, whether your controls would pass. It is the cheapest way to avoid exceptions in your first SOC 2 report — and the step most first-time companies skip.
What a SOC 2 readiness assessment is (and is not)
A readiness assessment compares your current controls against the AICPA Trust Services Criteria (TSC) you plan to put in scope. It is not an attestation: no opinion is issued and the result cannot be shared with customers as a SOC 2 report. Its output is a gap list and a remediation plan.
| Readiness assessment | SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|---|
| Performed by | Consultant or CPA firm | Independent CPA firm | Independent CPA firm |
| Output | Gap report + roadmap | Opinion on design at a point in time | Opinion on design and operating effectiveness over 3–12 months |
| Shareable with customers | No | Yes | Yes |
| Typical duration | 2–6 weeks | 4–8 weeks | Observation window + 4–8 weeks |
What the assessor actually reviews
1. Scope and system description Which products, environments, locations and subservice organizations (AWS, Azure, GCP, payroll providers) are in scope. A vague scope is the number one cause of rework later.
2. Trust Services Criteria selection Security (Common Criteria CC1–CC9) is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional — add them only when customers ask for them.
3. Control design walkthroughs For each criterion, the assessor asks: is there a control, who owns it, how often does it run, and what evidence does it leave behind?
4. Evidence sampling A good readiness review pulls sample evidence the way an auditor would: access reviews, onboarding and offboarding tickets, change approvals, vulnerability scans, backup restore tests and vendor reviews.
The gaps we find most often
- Access reviews exist but are not documented or signed off
- Offboarding takes longer than the policy says (often days, not hours)
- Changes deployed without recorded peer review or approval
- No formal risk assessment in the last 12 months
- Vendor risk management limited to a spreadsheet with no reviews
- Security awareness training not tracked per employee
- Incident response plan never tested with a tabletop exercise
- Policies written but not approved or acknowledged by staff
Realistic timeline
- Weeks 1–2: scoping, TSC selection, interviews
- Weeks 2–4: control walkthroughs and evidence sampling
- Week 4–6: gap report and prioritized remediation plan
- Months 2–4: remediation and tool rollout
- Then: Type 1 audit, or start the Type 2 observation window (commonly 3–6 months for a first report)
What drives cost
Cost depends on company size, number of systems, criteria in scope, how much documentation already exists, and whether you use a compliance automation platform. A readiness assessment is usually a fraction of the audit fee — and it typically saves more than it costs by preventing exceptions and a repeat observation period.
Deliverables you should insist on
- Scope statement and draft system description outline
- Control matrix mapped to each TSC point of focus
- Gap register with owner, priority and target date
- Evidence request list matching what your auditor will ask for
- Remediation roadmap aligned to your audit date
Readiness to report: how to avoid exceptions
Start the observation window only after remediated controls have run at least once with evidence. Automate evidence collection where possible, keep a single owner per control, and run a mini internal review a month before fieldwork. See our SOC 2 compliance checklist for the full control and evidence list, and SOC 2 vs ISO 27001 if you are still choosing a framework.
FAQs
Is a SOC 2 readiness assessment mandatory? No, but it is strongly recommended for a first report. Auditors cannot help you design controls without impairing their independence, so readiness is where remediation advice happens.
Can the same firm do readiness and the audit? A CPA firm can perform readiness, but it cannot design or implement your controls and then audit them. Many companies use a consultant for readiness and a separate CPA firm for the attestation.
Should we go for Type 1 or Type 2 first? If a customer deal needs a report quickly, Type 1 is faster. If customers accept a short wait, going straight to a 3-month Type 2 avoids paying for two audits.
Need help? ICyberWave provides SOC 2 readiness, implementation and audit support — talk to our team.

