SOC 2 Gap Analysis

Free SOC 2 Type II gap analysis wizard. Assess your readiness across all 5 Trust Service Criteria: Security (CC1-CC9), Availability, Processing Integrity, Confidentiality, and Privacy.

Advertisement

Assessing SOC 2 Readiness

A SOC 2 audit evaluates how well your organization's controls meet the AICPA's Trust Service Criteria. This tool helps you gauge readiness before you engage an auditor: you rate your current controls, receive a maturity score, and get a prioritized roadmap of the gaps to close first. It is a self-assessment to focus your preparation, not the audit itself.

The Five Trust Service Criteria

SOC 2 is built on five TSC. Security is mandatory; the other four are included only if relevant to your services and commitments:

  • Security (Common Criteria) — protection against unauthorized access, the required baseline for every report.
  • Availability — systems are available for operation as committed (uptime, monitoring, DR).
  • Processing Integrity — processing is complete, valid, accurate, and timely.
  • Confidentiality — information designated confidential is protected.
  • Privacy — personal information is collected, used, retained, and disposed of per your notice.

Type I vs. Type II

A Type I report assesses control design at a single point in time; a Type II tests operating effectiveness over a period (commonly 3–12 months). Knowing your target shapes how much evidence and runtime you need before the audit window opens.

How Maturity Scoring Helps

Rather than a pass/fail snapshot, scoring each control area shows where you are strong and where you are exposed, so remediation effort flows to the weakest, highest-risk controls first instead of being spread evenly.

Working the Roadmap

Use the prioritized output to sequence remediation: define policies, implement the technical controls, then accumulate evidence over your observation period. Common early gaps are formal access reviews, change management, vendor risk, and logging/monitoring.

Privacy

The assessment runs entirely in your browser — your control ratings and notes are never uploaded — so you can document sensitive weaknesses honestly. If your compliance program also touches Microsoft 365 tooling, the Microsoft Security Compliance Mapper shows which products map to SOC 2 controls.

Frequently Asked Questions

What is SOC 2 Type II certification?+

SOC 2 Type II is an auditing standard that evaluates how well a service organization protects customer data over a period of time (typically 6-12 months). It covers five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

What are the 5 Trust Service Criteria?+

The five Trust Service Criteria are: (1) Security (CC1-CC9), (2) Availability (A1), (3) Processing Integrity (PI1), (4) Confidentiality (C1), (5) Privacy (P1-P8). Security is required for all SOC 2 audits; the others are optional.

How long does it take to prepare for SOC 2?+

SOC 2 preparation typically takes 3-12 months depending on your current maturity level. Organizations at maturity level 1-2 may need 6-12 months. Type II requires a 6-12 month observation period after controls are implemented.

Do I need all 5 Trust Service Criteria for SOC 2?+

No, only Security (Common Criteria) is required. The other four criteria are optional and should be selected based on what is relevant to your services and customer commitments.

What is the difference between SOC 2 Type I and Type II?+

Type I assesses control design at a point in time. Type II evaluates both design AND operating effectiveness over 6-12 months. Type II is more rigorous and most enterprises require Type II reports from vendors.

How much does SOC 2 certification cost?+

Auditor fees typically range from $20,000-$100,000+ depending on scope and complexity. Implementation costs can add $50,000-$200,000 for organizations at lower maturity levels.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.