Without a SOC 2 readiness assessment checklist, you might discover your readiness gaps during the audit and not before it. By that point, the CPA firm is on the clock, evidence requests are live and anything missing becomes a documented exception in the final report.
It is the stage where the most consequential decisions in your SOC 2 programme are made. This includes scoping, control mapping and gap prioritisation. Get that right and your audit runs cleanly. However, if you get them wrong, you will feel it when the report lands on your buyer’s desk.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment evaluates your current control environment against the Trust Services Criteria (TSC) in scope. It tells you where you stand before the formal audit begins, focused on what is working, what is missing and what needs to be fixed before the observation window opens.
What it covers and what it produces
A thorough readiness assessment covers your control documentation, the actual operation of those controls and the evidence produced. The output is a prioritised gap report-what needs to be addressed, in what order and by when.
How it differs from the formal audit
The readiness assessment is conducted before the audit by your implementation partner, not the CPA firm. It is not legally binding and does not appear in your final report. The auditor tests whether your controls held up over time. The readiness assessment tests whether they exist and are ready to run. For a deeper look at what the formal audit involves, see our SOC 2 audit guide.
What is a SOC 2 gap analysis?
A gap analysis maps your current controls against the TSC requirements and identifies what is missing, incomplete or inconsistent. It is the core output of the readiness assessment.
How gap analysis sits inside the readiness assessment
The gap analysis is not a separate exercise-it is what the readiness assessment produces. Map what exists against what is required and the delta is your gap list.
What a gap report should tell you
Here is where most self-conducted readiness assessments fall short. A gap report that only lists what is missing is not a gap report-it is an inventory. A useful gap report tells you:
Why this stage requires GRC, cybersecurity and governance expertise
This is the part most guides skip. A readiness assessment looks straightforward on paper which include mapping controls, finding gaps and fixing them. In practice, the decisions made at this stage require three distinct areas of expertise working together.
1. Scoping decisions that require expert judgement
Which Trust Services Criteria belong in scope? Which systems sit inside the audit boundary? How do you handle subservice organisations-cloud providers, payroll platforms, third-party tools-that process data on your behalf?
These are commercial and governance decisions with audit consequences. Include too little and your report does not satisfy your buyer. Include too much without supporting controls and you generate exceptions. Getting scope right requires someone who has seen how auditors interpret system descriptions.
2. Control mapping that requires cybersecurity depth
Your organisation almost certainly has controls already running such as access management processes, incident response procedures, logging configurations. The question is whether they satisfy the TSC requirements they are meant to address.
A control that looks sufficient on paper may not satisfy the Common Criteria if the review lacks documented approvals or evidence of action taken. Identifying that gap requires someone who understands both what the criterion requires and what auditors test.
3. Gap prioritisation that requires governance experience
Not all gaps are equal. Some must be closed before the observation window opens or they will generate exceptions in every sampled period. Others can run in parallel. Sequencing remediation correctly-so the window opens only when the control environment is genuinely ready-requires governance experience. Rushing the window open with unresolved gaps is one of the most common and costly mistakes in SOC 2 programmes.
SOC 2 readiness assessment checklist
Here is what a thorough readiness assessment covers across five core control areas.
Access management
- Access provisioning and de-provisioning process documented and followed
- Periodic access reviews conducted, evidenced and completed on schedule
- Privileged access restricted, monitored and reviewed separately
- Multi-factor authentication (MFA) enforced for all systems in scope
Incident response
- Incident response plan documented, approved and communicated to relevant staff
- Incident log maintained continuously, including low-severity events
- Response timelines defined and evidenced in past incidents
- Post-incident reviews documented for significant events
Change management
- Change management policy covering development, testing, approval and deployment
- All in-scope system changes tracked with approval evidence
- Emergency change process defined and separately logged
- Separation of duties between development and production environments
Vendor and third-party risk
- Inventory of subservice organisations maintained and current
- Vendor risk assessments conducted and documented for critical third parties
- Contracts with security requirements in place
- Ongoing monitoring process defined for high-risk vendors
Monitoring and logging
- Logging enabled across all in-scope systems with defined retention periods
- Alerting configured for security-relevant events
- Log reviews conducted on schedule with evidence of completion
- Logging gaps identified and remediated before the observation window opens
How to prioritise and close gaps
Gaps need to be sequenced and not just listed.
| Gap level | Definition | Action required |
| Critical | Will generate an exception in every sampled period if not closed | Must be closed before observation window opens |
| High | Likely to generate exceptions depending on sampling | Should be closed before observation window opens |
| Medium | May surface as a finding depending on auditor judgement | Close during the observation window with evidence of improvement |
| Low | Unlikely to affect audit outcome | Address in the next programme cycle |
Critical and high gaps must be resolved before your observation window begins. Opening the window with known critical gaps is a guaranteed exception. For guidance on managing controls through the observation window, see our SOC 2 observation period guide.
Conclusion
Every exception in your final audit report can be traced back to a decision made—or not made—during the readiness phase. Scope chosen too narrowly. A gap missed. Remediation sequenced in the wrong order.
CyberNX brings GRC, cybersecurity and governance expertise together at this stage. We map your existing controls accurately, identify gaps your team may not see, make scoping decisions that hold up under auditor scrutiny and sequence remediation so your observation window opens only when you are genuinely ready. Getting the readiness phase right does not just improve your audit outcome. It determines it.
Talk to our SOC 2 team of experts about where your SOC 2 programme stands today.
SOC 2 readiness assessment FAQs
How long does a SOC 2 readiness assessment take?
For most organisations, two to four weeks. Larger environments or limited existing documentation can extend this to six to eight weeks. The timeline depends on how quickly your team can produce evidence of current controls-not just policy documents, but proof they are running.
Can you do a SOC 2 readiness assessment yourself?
You can conduct an initial self-assessment using a checklist like the one above. However, it cannot catch gaps you do not know to look for, and it cannot make the scoping and prioritisation judgements that require audit experience. Most organisations use a self-assessment to get oriented, then engage an expert partner to validate it before committing to an observation window start date.
What happens after the readiness assessment is complete?
You receive a gap report. The remediation phase begins-closing critical and high gaps, assigning control owners and setting the observation window start date. The readiness assessment defines the work.




