SOC 2 Gap Analysis

Assess SOC 2 Type II readiness across all 5 Trust Service Criteria: Security (CC1-CC9), Availability, Processing Integrity, Confidentiality, Privacy. Free.

Advertisement

SOC 2 gap analysis: score your own controls against the Trust Services Criteria

This is a self-assessment. You answer 36 questions covering all five Trust Services Criteria, choosing for each one the statement that best describes what your organisation actually does today. The tool converts those answers into a maturity score per criteria category, flags the categories that fall short, and lays out a rough remediation sequence. It runs in your browser, and none of your answers are transmitted while you work through it.

Say plainly what it cannot do. A SOC 2 report is an attestation issued by an independent licensed CPA firm after an audit engagement. Nothing on this page is an audit, produces an attestation, or moves you closer to one on paper. What it does is give you a structured, honest look at where you stand before you spend money on a readiness engagement — so that the conversation with an auditor starts from a list of known gaps rather than a discovery exercise you are paying for by the hour.

Type I and Type II — which one you are preparing for

The two report types answer different questions. A Type I report assesses whether your controls are suitably designed at a single point in time: on this date, do the controls you describe exist and are they capable of meeting the criteria? A Type II report assesses whether those controls operated effectively over a review period — commonly three to twelve months — which means the auditor tests evidence sampled across that window.

The practical consequence is about evidence, not policy. You can pass a Type I with a policy written last week. A Type II requires that the policy was being followed, and that you can prove it: access review records from each quarter, ticket history for change approvals, alert logs, onboarding and offboarding trails. That is why organisations that get a clean Type I sometimes struggle with the Type II that follows. This assessment is framed around Type II readiness, and its maturity scale reflects that — the higher levels are precisely the ones about consistency, documentation and measurement over time.

What the 36 questions cover

The questions are grouped by Trust Services Criteria category. Security is the only category every SOC 2 report includes; the other four are optional and are selected based on the commitments you make to customers. This assessment walks you through all five regardless, which means some sections may not apply to your intended scope — a company that makes no availability commitment can reasonably skip A1.

CategoryCriteria coveredQuestions
Security (Common Criteria)CC1 Control Environment, CC2 Communication and Information, CC3 Risk Assessment, CC4 Monitoring Activities, CC5 Control Activities, CC6 Logical and Physical Access, CC7 System Operations, CC8 Change Management, CC9 Risk Mitigation19
AvailabilityA1 — SLAs, capacity planning, redundancy and failover3
Processing IntegrityPI13
ConfidentialityC13
PrivacyP1 Notice, P2 Choice and Consent, P3 Collection, P4 Use/Retention/Disposal, P5 Access, P6 Disclosure and Notification, P7 Quality, P8 Monitoring and Enforcement8

Security carries more than half the questions, which reflects how the criteria themselves are weighted: the common criteria are the foundation every report rests on. Privacy has the widest spread of criteria but one question each, so it is a breadth check rather than a deep review.

The maturity scale

Every question offers five answers, one per maturity level, and each is written as a concrete description rather than an abstract rating. For the question "How is access to production systems restricted?" the five options run: all IT staff have production access; limited access with shared credentials; role-based access with individual accounts; privileged access management with session recording; just-in-time access with automated approval and audit.

LevelNameWhat it means
1InitialAd hoc and reactive, no formal documentation, consistency depends on individuals
2DevelopingBasic processes starting to be documented; controls exist but are applied inconsistently
3DefinedStandardised, documented processes applied consistently, with staff trained on them
4ManagedProcesses are monitored and measured, with metrics collected and analysed
5OptimizingContinuous improvement driven by data and benchmarking

Level 3 is the target the whole tool is calibrated against. That is a deliberate and defensible choice: consistent, documented, trained-on processes are what an auditor can test evidence against. Levels 4 and 5 describe organisations doing more than the criteria demand. Answer honestly rather than aspirationally — picking the option describing what you intend to build produces a score that flatters you and a gap list that omits the work.

How the scores are calculated

Each category score is the plain arithmetic mean of the levels you selected within that category. The overall score is the mean across every question you answered, so it is weighted by question count rather than by category — the 19 Security questions dominate it. Readiness percentage is derived from the overall score by a straight linear map from level 1 to level 3, then capped:

  • An overall score of 1.0 gives 0% readiness
  • 2.0 gives 50%
  • 3.0 gives 100%
  • Anything above 3.0 also shows 100%, because the value is clamped

So the readiness figure measures distance to "Defined", not distance to perfect, and it saturates. An organisation averaging 3.2 and one averaging 4.8 both read 100% readiness, while their category breakdowns will look very different. Read the per-category scores rather than the headline number.

The threshold that drives everything else is 3.0. Categories scoring below it are listed as priority improvement areas, sorted worst first, with the shortfall shown to one decimal place. Categories at 3.0 or above are listed as areas of strength. A worked example: if you answer the three availability questions at levels 2, 3 and 4, the category mean is exactly 3.0, which lands on the strength side of the line by the narrowest possible margin — a reminder that a category average can hide a level 2 control underneath it.

The skipping trap

Unanswered questions are excluded from the averages entirely rather than counted as zero or as level 1. That is reasonable behaviour when a whole category genuinely falls outside your intended scope. It is also the easiest way to produce a misleadingly good result: answer the ten questions you feel confident about, skip the rest, and the tool reports a high maturity score computed from ten answers.

The results screen shows the answered count per category and the overall count out of 36, so the evidence of a partial run is visible — but the headline score does not warn you. If you deliberately skip a category, note why. If you skip individual questions inside a category you are claiming, you have not assessed that category.

Working through it

The assessment moves one question at a time, grouped by category, with a progress bar and category pills across the top that let you jump between categories in any order and return to earlier answers. Each question carries a short guidance line naming the things to consider — for the encryption question, TLS versions, algorithms and key management — which is useful for deciding what "documented standards" actually has to mean before you claim level 3. The intro screen estimates 10 to 15 minutes.

Do not do it alone if you can avoid it. The questions cut across engineering, IT, HR and legal: control environment and communication questions belong to whoever owns policy and onboarding, CC6 and CC7 to infrastructure, CC8 to whoever owns the deployment pipeline, and the privacy criteria to whoever handles data subject requests and retention. A single person answering all 36 will guess at some of them, and the guesses are exactly where real gaps hide.

What the results give you

  • An overall maturity score out of 5.0 with its level name, and a readiness percentage
  • A per-category breakdown with score, maturity level and how many questions you answered in each
  • Priority improvement areas — every category below 3.0, ordered worst first, with the size of the shortfall
  • Areas of strength — categories at 3.0 or above
  • A three-phase remediation roadmap: immediate (0–30 days), short-term (30–90 days) and medium-term (90+ days)
  • A shareable results link, and a PDF report

Set expectations on the roadmap: it is a fixed set of sequencing advice, not generated from your specific answers. The immediate phase says to document critical security policies, assign control ownership and address any level 1 areas; the short-term phase covers formal procedures, monitoring tooling and training; the medium-term phase covers automating control testing, internal audits and preparing for the audit engagement itself. That ordering is sound and it is the order most readiness projects follow, but the specificity you need comes from the category breakdown above it, not from the roadmap boxes.

Sharing and exporting — read this before you click

Two of the three result actions behave differently from the assessment itself, and both are worth understanding.

Share results encodes your full set of answers into the URL as a base64 query parameter and copies that link to your clipboard. Opening the link reloads the answers and jumps straight to the results view. Nothing is stored on a server — the answers travel inside the link. The flip side is that the link contains your control posture. Anyone who receives it, or reads it out of a chat log, browser history or a mail scanner, can see how you rated production access, encryption and incident response. Treat the link the way you would treat the assessment itself.

Export PDF produces a multi-page report with an executive summary, a readiness banner colour-coded by score, a category score table, your lowest-scoring categories with target levels, and a set of recommended next steps. This action asks for an email address the first time you use it, and the address is recorded. The assessment and the on-screen results need no email; only the PDF export does.

There is no autosave. Reloading the page without a share link discards your answers, so generate the link or the PDF before you close the tab.

Turning the output into an actual readiness plan

A gap list is not a plan until each item has an owner, an artefact and a date. For every category scoring below 3.0, name the person accountable, name the specific document or system change that moves it to "Defined", and name the evidence a Type II auditor would sample — because at level 3 the process exists, and the audit still asks you to prove it ran.

Two sequencing points that follow from how the scores work. First, fix Security before the optional categories: it is the only mandatory one and it dominates the overall score, so improvements there move both the report scope and the number. Second, level 1 answers are worth more attention than a low category average, since a single ad hoc control — shared production credentials, no incident response plan — is a finding regardless of how the category averages out.

If you want a broader view of your security programme rather than a criteria-by-criteria SOC 2 read, the cybersecurity maturity assessment covers wider ground. For SOC 2 specifically, the next real step after this is a readiness assessment with the firm you intend to engage.

Frequently Asked Questions

What is SOC 2 Type II certification?+

SOC 2 Type II is an auditing standard that evaluates how well a service organization protects customer data over a period of time (typically 6-12 months). It covers five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

What are the 5 Trust Service Criteria?+

The five Trust Service Criteria are: (1) Security (CC1-CC9), (2) Availability (A1), (3) Processing Integrity (PI1), (4) Confidentiality (C1), (5) Privacy (P1-P8). Security is required for all SOC 2 audits; the others are optional.

How long does it take to prepare for SOC 2?+

SOC 2 preparation typically takes 3-12 months depending on your current maturity level. Organizations at maturity level 1-2 may need 6-12 months. Type II requires a 6-12 month observation period after controls are implemented.

Do I need all 5 Trust Service Criteria for SOC 2?+

No, only Security (Common Criteria) is required. The other four criteria are optional and should be selected based on what is relevant to your services and customer commitments.

What is the difference between SOC 2 Type I and Type II?+

Type I assesses control design at a point in time. Type II evaluates both design AND operating effectiveness over 6-12 months. Type II is more rigorous and most enterprises require Type II reports from vendors.

How much does SOC 2 certification cost?+

Auditor fees typically range from $20,000-$100,000+ depending on scope and complexity. Implementation costs can add $50,000-$200,000 for organizations at lower maturity levels.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.