Free SOC 2 Type II gap analysis wizard. Assess your readiness across all 5 Trust Service Criteria: Security (CC1-CC9), Availability, Processing Integrity, Confidentiality, and Privacy.
A SOC 2 audit evaluates how well your organization's controls meet the AICPA's Trust Service Criteria. This tool helps you gauge readiness before you engage an auditor: you rate your current controls, receive a maturity score, and get a prioritized roadmap of the gaps to close first. It is a self-assessment to focus your preparation, not the audit itself.
SOC 2 is built on five TSC. Security is mandatory; the other four are included only if relevant to your services and commitments:
A Type I report assesses control design at a single point in time; a Type II tests operating effectiveness over a period (commonly 3–12 months). Knowing your target shapes how much evidence and runtime you need before the audit window opens.
Rather than a pass/fail snapshot, scoring each control area shows where you are strong and where you are exposed, so remediation effort flows to the weakest, highest-risk controls first instead of being spread evenly.
Use the prioritized output to sequence remediation: define policies, implement the technical controls, then accumulate evidence over your observation period. Common early gaps are formal access reviews, change management, vendor risk, and logging/monitoring.
The assessment runs entirely in your browser — your control ratings and notes are never uploaded — so you can document sensitive weaknesses honestly. If your compliance program also touches Microsoft 365 tooling, the Microsoft Security Compliance Mapper shows which products map to SOC 2 controls.
SOC 2 Type II is an auditing standard that evaluates how well a service organization protects customer data over a period of time (typically 6-12 months). It covers five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The five Trust Service Criteria are: (1) Security (CC1-CC9), (2) Availability (A1), (3) Processing Integrity (PI1), (4) Confidentiality (C1), (5) Privacy (P1-P8). Security is required for all SOC 2 audits; the others are optional.
SOC 2 preparation typically takes 3-12 months depending on your current maturity level. Organizations at maturity level 1-2 may need 6-12 months. Type II requires a 6-12 month observation period after controls are implemented.
No, only Security (Common Criteria) is required. The other four criteria are optional and should be selected based on what is relevant to your services and customer commitments.
Type I assesses control design at a point in time. Type II evaluates both design AND operating effectiveness over 6-12 months. Type II is more rigorous and most enterprises require Type II reports from vendors.
Auditor fees typically range from $20,000-$100,000+ depending on scope and complexity. Implementation costs can add $50,000-$200,000 for organizations at lower maturity levels.