What a SOC 2 readiness assessment covers, what a firm charges for one, when a small team can run it alone, and a checklist mapped to the nine Common Criteria.
A SOC 2 readiness assessment is a gap check of your controls against the AICPA Trust Services Criteria, done before the real audit, so you find the problems while they are still cheap to fix. A SOC 2 readiness assessment produces an internal list of gaps, not a report you can give customers. A CPA or advisory firm typically charges US$10,000 to US$17,000 for one, according to figures Secureframe publishes. A team of 5 to 50 people with one capable owner can usually run a SOC 2 readiness assessment themselves in about a week, using the checklist below.
A SOC 2 readiness assessment is an optional review that compares how your organisation operates today with the SOC 2 Trust Services Criteria published by the AICPA (2017 Trust Services Criteria, revised points of focus 2022). Security is the mandatory category and is assessed through the 33 Common Criteria, CC1.1 to CC9.2. Availability, Confidentiality, Processing Integrity and Privacy are added only if you include them in scope.
The output of a SOC 2 readiness assessment is a gap list and a remediation plan for internal use. A SOC 2 readiness assessment carries no auditor's opinion, so it cannot replace a SOC 2 Type I or Type II report, and customers who ask for "your SOC 2" will not accept it. The value is that the gaps show up in a private document rather than as exceptions in a report your customers will read.
No. A SOC 2 readiness assessment is not required by the AICPA or by any auditor. You can go straight to a SOC 2 Type I or Type II examination. Most first-time organisations still do some form of SOC 2 readiness assessment, because a Type II report records every control failure found during the observation period, and those exceptions appear in the report your customers read.
The real question is not whether to do a SOC 2 readiness assessment but who does it: a paid firm, or your own team.
A firm-led SOC 2 readiness assessment typically costs US$10,000 to US$17,000, according to figures Secureframe publishes, with the price driven by organisation size and scope. Some CPA firms fold the readiness work into the audit fee for new clients: Linford & Co, for example, says it includes a readiness assessment for new clients at no additional charge. A self-run SOC 2 readiness assessment costs mainly staff time. The table below sets the readiness assessment against the rest of a first SOC 2 budget.
| Cost component | Typical range (USD) | Who charges it |
|---|---|---|
| Readiness assessment, firm-led | $10,000 to $17,000 (Secureframe's published range) | A CPA or advisory firm |
| Readiness assessment, self-run | Staff time, about 4 to 7 working days | Internal |
| Compliance platform | CertAssist: $225 per month or $2,475 per year (October 2026) | The software vendor |
| Independent auditor, Type II | $10,000 to $30,000+ | A licensed CPA firm |
| Penetration test, if your scope needs one | $4,000 to $12,000 | A security testing firm |
| Remediation of the gaps found | Engineering and management time | Internal |
Vanta and Drata do not publish list pricing, so their cost cannot be quoted here. The auditor and penetration test ranges match the full breakdown in how much SOC 2 costs. The self-run effort is a planning estimate for a single product and a team of 5 to 50 people, not a guarantee.
A SOC 2 readiness assessment checks three things for each criterion in scope: whether a control exists, whether it is written down, and whether there is evidence it actually operates. A firewall rule nobody can show, or a policy nobody follows, both count as gaps in a SOC 2 readiness assessment.
The SOC 2 readiness assessment also checks the scope itself. You need a clear system description: which product, which infrastructure, which people and which third parties are in the audit boundary. A vague scope is the most common reason a SOC 2 readiness assessment, and later the audit, runs long.
This SOC 2 readiness assessment checklist covers the Security category. Score each line as in place, partial or missing, and record the evidence you would hand an auditor.
| Series | Criteria | What to check | Evidence an auditor will ask for |
|---|---|---|---|
| CC1 Control environment | 5 | Security roles assigned, code of conduct, background checks, board or leadership oversight | Org chart, signed policy acknowledgements, background check records |
| CC2 Communication and information | 3 | Policies published to staff, security commitments communicated to customers | Policy library, terms of service, security page, onboarding records |
| CC3 Risk assessment | 4 | A documented risk assessment, including fraud risk and changes to the business | Risk register with owners and dates, last review date |
| CC4 Monitoring activities | 2 | Someone reviews whether controls work and fixes what does not | Internal review notes, tracked findings |
| CC5 Control activities | 3 | Controls chosen to address the risks, backed by written policies | Control list mapped to risks, approved policies |
| CC6 Logical and physical access | 8 | MFA, least privilege, joiner and leaver process, access reviews, encryption | Access review records, offboarding tickets, MFA settings screenshots |
| CC7 System operations | 5 | Logging, vulnerability management, incident response, recovery | Alert examples, scan reports, incident log, tested response plan |
| CC8 Change management | 1 | Changes are approved, tested and tracked before production | Pull requests with reviews, change tickets |
| CC9 Risk mitigation | 2 | Vendor risk management and business disruption planning | Vendor list with reviews, supplier SOC reports, continuity plan |
A gap in CC6 or CC8 usually takes the longest to close, because fixing it changes how engineers work every day. A gap in CC1 to CC5 is mostly writing and approving documents. The guide to what auditors look for in evidence shows what a good evidence item looks like.
A self-run SOC 2 readiness assessment works best with one owner who knows how the product is built and operated. For a team of 5 to 50 people, a realistic sequence is:
The finished remediation plan from a SOC 2 readiness assessment becomes the project plan up to your audit. If the plan is long, decide whether a Type I first makes sense; the guide to SOC 2 Type 1 vs Type 2 covers that choice.
A SOC 2 readiness assessment for a Type 1 report asks whether each control is designed properly and in place on one date. A SOC 2 readiness assessment for a Type 2 report asks a harder question: can the control run consistently, with evidence, for every week of an observation period of typically 3 to 12 months?
The practical difference shows up in recurring controls. Quarterly access reviews, monthly vulnerability scans and annual security training all need a repeatable process and a record each time. A SOC 2 readiness assessment aimed at Type 2 should test that each recurring control has run at least once, with evidence, before the window opens.
A paid SOC 2 readiness assessment is worth the money when nobody in-house has been through an audit before and the scope is complex: several products, regulated data, or many third parties. It is also worth paying when a large deal depends on a clean first report and you want an auditor's eyes on the design early.
Your service auditor can usually perform the readiness assessment as well as the examination, provided the firm does not take on management responsibilities such as designing or running your controls. Ask any firm how it handles independence before you sign. A paid SOC 2 readiness assessment does not replace the independent audit itself, and no tool or checklist removes the need for a licensed CPA firm to issue the report.
CertAssist lays out every SOC 2 Trust Services Criterion on one board, with editable policy and evidence templates and a documentation and evidence checklist per control, so a self-run SOC 2 readiness assessment has its structure ready. CertAssist costs US$225 per month or US$2,475 per year as a launch offer as of October 2026, normally US$375 per month. CertAssist does not connect to your systems, so it gains no access to your cloud or code.
The trade-off is real. CertAssist does not collect evidence automatically or monitor controls continuously. A company with hundreds of engineers and many cloud accounts may be better served by an integration-based platform, and should budget for it. For a team of 5 to 50 that needs a first SOC 2 report, CertAssist is usually the right amount of tool.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment is an optional gap check that compares your current controls with the AICPA Trust Services Criteria before the real audit. A SOC 2 readiness assessment covers the 33 Common Criteria for Security plus any other categories in scope, and produces an internal list of gaps and a remediation plan. A SOC 2 readiness assessment carries no auditor's opinion, so it does not replace a SOC 2 Type I or Type II report.
How much does a SOC 2 readiness assessment cost?
A firm-led SOC 2 readiness assessment typically costs US$10,000 to US$17,000, according to figures Secureframe publishes, depending on organisation size and scope. Some CPA firms include readiness work in the audit fee for new clients. A self-run SOC 2 readiness assessment costs mainly staff time, about four to seven working days for a team of 5 to 50 people.
Is there a SOC 2 readiness assessment checklist or template?
Yes. The simplest SOC 2 readiness assessment checklist has one row per Common Criteria series, CC1 to CC9, covering 33 criteria in total. For each row, record what to check, the evidence an auditor will ask for, a score of in place, partial or missing, an owner and a target date. The checklist table in this guide follows that structure.
What is the difference between a SOC 2 Type 1 and Type 2 readiness assessment?
A SOC 2 Type 1 readiness assessment checks whether controls are designed properly and in place on a single date. A SOC 2 Type 2 readiness assessment also checks that each control can operate consistently, with evidence, across an observation period of typically 3 to 12 months. Recurring controls such as access reviews and vulnerability scans matter far more for Type 2.
Is SOC 2 mandatory?
No. SOC 2 is not mandatory under any law. SOC 2 is a voluntary attestation framework from the AICPA. In practice, SOC 2 becomes necessary when customers, usually larger US companies, require a SOC 2 report in their security review or contract before they will buy. Many organisations pursue SOC 2 for that commercial reason alone.
CertAssist lays out every SOC 2 criterion with editable policy and evidence templates, and lets your auditor review it all in one place, for a flat $225 a month.
See pricing FrameworksFlat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.