Assess SOC 2 Type II readiness across all 5 Trust Service Criteria: Security (CC1-CC9), Availability, Processing Integrity, Confidentiality, Privacy. Free.
This is a self-assessment. You answer 36 questions covering all five Trust Services Criteria, choosing for each one the statement that best describes what your organisation actually does today. The tool converts those answers into a maturity score per criteria category, flags the categories that fall short, and lays out a rough remediation sequence. It runs in your browser, and none of your answers are transmitted while you work through it.
Say plainly what it cannot do. A SOC 2 report is an attestation issued by an independent licensed CPA firm after an audit engagement. Nothing on this page is an audit, produces an attestation, or moves you closer to one on paper. What it does is give you a structured, honest look at where you stand before you spend money on a readiness engagement — so that the conversation with an auditor starts from a list of known gaps rather than a discovery exercise you are paying for by the hour.
The two report types answer different questions. A Type I report assesses whether your controls are suitably designed at a single point in time: on this date, do the controls you describe exist and are they capable of meeting the criteria? A Type II report assesses whether those controls operated effectively over a review period — commonly three to twelve months — which means the auditor tests evidence sampled across that window.
The practical consequence is about evidence, not policy. You can pass a Type I with a policy written last week. A Type II requires that the policy was being followed, and that you can prove it: access review records from each quarter, ticket history for change approvals, alert logs, onboarding and offboarding trails. That is why organisations that get a clean Type I sometimes struggle with the Type II that follows. This assessment is framed around Type II readiness, and its maturity scale reflects that — the higher levels are precisely the ones about consistency, documentation and measurement over time.
The questions are grouped by Trust Services Criteria category. Security is the only category every SOC 2 report includes; the other four are optional and are selected based on the commitments you make to customers. This assessment walks you through all five regardless, which means some sections may not apply to your intended scope — a company that makes no availability commitment can reasonably skip A1.
| Category | Criteria covered | Questions |
|---|---|---|
| Security (Common Criteria) | CC1 Control Environment, CC2 Communication and Information, CC3 Risk Assessment, CC4 Monitoring Activities, CC5 Control Activities, CC6 Logical and Physical Access, CC7 System Operations, CC8 Change Management, CC9 Risk Mitigation | 19 |
| Availability | A1 — SLAs, capacity planning, redundancy and failover | 3 |
| Processing Integrity | PI1 | 3 |
| Confidentiality | C1 | 3 |
| Privacy | P1 Notice, P2 Choice and Consent, P3 Collection, P4 Use/Retention/Disposal, P5 Access, P6 Disclosure and Notification, P7 Quality, P8 Monitoring and Enforcement | 8 |
Security carries more than half the questions, which reflects how the criteria themselves are weighted: the common criteria are the foundation every report rests on. Privacy has the widest spread of criteria but one question each, so it is a breadth check rather than a deep review.
Every question offers five answers, one per maturity level, and each is written as a concrete description rather than an abstract rating. For the question "How is access to production systems restricted?" the five options run: all IT staff have production access; limited access with shared credentials; role-based access with individual accounts; privileged access management with session recording; just-in-time access with automated approval and audit.
| Level | Name | What it means |
|---|---|---|
| 1 | Initial | Ad hoc and reactive, no formal documentation, consistency depends on individuals |
| 2 | Developing | Basic processes starting to be documented; controls exist but are applied inconsistently |
| 3 | Defined | Standardised, documented processes applied consistently, with staff trained on them |
| 4 | Managed | Processes are monitored and measured, with metrics collected and analysed |
| 5 | Optimizing | Continuous improvement driven by data and benchmarking |
Level 3 is the target the whole tool is calibrated against. That is a deliberate and defensible choice: consistent, documented, trained-on processes are what an auditor can test evidence against. Levels 4 and 5 describe organisations doing more than the criteria demand. Answer honestly rather than aspirationally — picking the option describing what you intend to build produces a score that flatters you and a gap list that omits the work.
Each category score is the plain arithmetic mean of the levels you selected within that category. The overall score is the mean across every question you answered, so it is weighted by question count rather than by category — the 19 Security questions dominate it. Readiness percentage is derived from the overall score by a straight linear map from level 1 to level 3, then capped:
So the readiness figure measures distance to "Defined", not distance to perfect, and it saturates. An organisation averaging 3.2 and one averaging 4.8 both read 100% readiness, while their category breakdowns will look very different. Read the per-category scores rather than the headline number.
The threshold that drives everything else is 3.0. Categories scoring below it are listed as priority improvement areas, sorted worst first, with the shortfall shown to one decimal place. Categories at 3.0 or above are listed as areas of strength. A worked example: if you answer the three availability questions at levels 2, 3 and 4, the category mean is exactly 3.0, which lands on the strength side of the line by the narrowest possible margin — a reminder that a category average can hide a level 2 control underneath it.
Unanswered questions are excluded from the averages entirely rather than counted as zero or as level 1. That is reasonable behaviour when a whole category genuinely falls outside your intended scope. It is also the easiest way to produce a misleadingly good result: answer the ten questions you feel confident about, skip the rest, and the tool reports a high maturity score computed from ten answers.
The results screen shows the answered count per category and the overall count out of 36, so the evidence of a partial run is visible — but the headline score does not warn you. If you deliberately skip a category, note why. If you skip individual questions inside a category you are claiming, you have not assessed that category.
The assessment moves one question at a time, grouped by category, with a progress bar and category pills across the top that let you jump between categories in any order and return to earlier answers. Each question carries a short guidance line naming the things to consider — for the encryption question, TLS versions, algorithms and key management — which is useful for deciding what "documented standards" actually has to mean before you claim level 3. The intro screen estimates 10 to 15 minutes.
Do not do it alone if you can avoid it. The questions cut across engineering, IT, HR and legal: control environment and communication questions belong to whoever owns policy and onboarding, CC6 and CC7 to infrastructure, CC8 to whoever owns the deployment pipeline, and the privacy criteria to whoever handles data subject requests and retention. A single person answering all 36 will guess at some of them, and the guesses are exactly where real gaps hide.
Set expectations on the roadmap: it is a fixed set of sequencing advice, not generated from your specific answers. The immediate phase says to document critical security policies, assign control ownership and address any level 1 areas; the short-term phase covers formal procedures, monitoring tooling and training; the medium-term phase covers automating control testing, internal audits and preparing for the audit engagement itself. That ordering is sound and it is the order most readiness projects follow, but the specificity you need comes from the category breakdown above it, not from the roadmap boxes.
Two of the three result actions behave differently from the assessment itself, and both are worth understanding.
Share results encodes your full set of answers into the URL as a base64 query parameter and copies that link to your clipboard. Opening the link reloads the answers and jumps straight to the results view. Nothing is stored on a server — the answers travel inside the link. The flip side is that the link contains your control posture. Anyone who receives it, or reads it out of a chat log, browser history or a mail scanner, can see how you rated production access, encryption and incident response. Treat the link the way you would treat the assessment itself.
Export PDF produces a multi-page report with an executive summary, a readiness banner colour-coded by score, a category score table, your lowest-scoring categories with target levels, and a set of recommended next steps. This action asks for an email address the first time you use it, and the address is recorded. The assessment and the on-screen results need no email; only the PDF export does.
There is no autosave. Reloading the page without a share link discards your answers, so generate the link or the PDF before you close the tab.
A gap list is not a plan until each item has an owner, an artefact and a date. For every category scoring below 3.0, name the person accountable, name the specific document or system change that moves it to "Defined", and name the evidence a Type II auditor would sample — because at level 3 the process exists, and the audit still asks you to prove it ran.
Two sequencing points that follow from how the scores work. First, fix Security before the optional categories: it is the only mandatory one and it dominates the overall score, so improvements there move both the report scope and the number. Second, level 1 answers are worth more attention than a low category average, since a single ad hoc control — shared production credentials, no incident response plan — is a finding regardless of how the category averages out.
If you want a broader view of your security programme rather than a criteria-by-criteria SOC 2 read, the cybersecurity maturity assessment covers wider ground. For SOC 2 specifically, the next real step after this is a readiness assessment with the firm you intend to engage.
SOC 2 Type II is an auditing standard that evaluates how well a service organization protects customer data over a period of time (typically 6-12 months). It covers five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
The five Trust Service Criteria are: (1) Security (CC1-CC9), (2) Availability (A1), (3) Processing Integrity (PI1), (4) Confidentiality (C1), (5) Privacy (P1-P8). Security is required for all SOC 2 audits; the others are optional.
SOC 2 preparation typically takes 3-12 months depending on your current maturity level. Organizations at maturity level 1-2 may need 6-12 months. Type II requires a 6-12 month observation period after controls are implemented.
No, only Security (Common Criteria) is required. The other four criteria are optional and should be selected based on what is relevant to your services and customer commitments.
Type I assesses control design at a point in time. Type II evaluates both design AND operating effectiveness over 6-12 months. Type II is more rigorous and most enterprises require Type II reports from vendors.
Auditor fees typically range from $20,000-$100,000+ depending on scope and complexity. Implementation costs can add $50,000-$200,000 for organizations at lower maturity levels.