Before you sit a SOC 2 audit, you sit a readiness assessment. It is the rehearsal that tells you whether you would pass the real thing and, more usefully, exactly what to fix first. Skipping it is how companies walk into fieldwork and collect a list of exceptions they pay to resolve later. This guide explains what a SOC 2 readiness assessment is, what happens in one, and what you walk away with.

What a SOC 2 readiness assessment is

A SOC 2 readiness assessment is a structured evaluation of your environment against the SOC 2 Trust Services Criteria and your existing security controls, performed before the formal audit. It identifies where your controls, policies, and evidence already meet the criteria and where the gaps are, so you can remediate before a licensed CPA firm examines you. Think of it as a gap assessment with a remediation plan attached, and a realistic timeline to audit as the output.

Readiness assessments are not the audit. The audit is performed by an independent licensed CPA firm that attests to your controls and issues the SOC 2 report. The AICPA sets the framework all SOC 2 audits use. A readiness assessment is performed by a readiness partner like Onyx, who helps you prepare for that audit.

SOC 2 compliance requires both that you have the right controls and that you can prove them. Readiness assessments assess both dimensions before the licensed CPA auditor does.

SOC 2 readiness assessment: the four steps from scoping through to remediation plan

What happens in one

A typical SOC 2 readiness assessment moves through four steps.

Scoping. You agree which Trust Services Criteria apply (Security always, plus any of Availability, Processing Integrity, Confidentiality, and Privacy your customers require) and which systems are in scope. Good scoping is the single biggest lever on cost and timeline.

Assessment. Your current security controls, policies, configurations, and evidence are reviewed against the criteria, usually through documentation review, interviews, and checking your systems.

Gap analysis. Every gap is identified and rated, so you know what stands between you and a clean audit. A thorough gap analysis surfaces every control weakness before it becomes an audit exception.

Remediation plan. A prioritized plan to close the gaps: controls to implement, policies to write, evidence to start collecting, and the order to do it in. This is the output that actually moves you toward a successful SOC 2 audit.

Want an instant read on your SOC 2 readiness?

Run the free 15-question self-assessment and get a readiness score before committing to a full assessment.

Start the assessment →

What you walk away with

A good readiness assessment leaves you with a clear picture of where you stand, a prioritized list of what to fix, and a realistic timeline to audit. It should tell you whether to pursue Type 1 or Type 2 first, what to scope, and what evidence you need to start collecting now, especially important for a Type 2 with a monitoring period. The output is not a pass or fail; it is a roadmap.

Readiness assessments also help you understand your Type 2 readiness: whether your controls are operating consistently enough to withstand a monitoring period review. Many companies discover through the assessment that a Type 1 is the right first step, with a Type 2 to follow once the remediation is complete.

Preparing for a SOC 2 audit: what to do before fieldwork

Preparing for a SOC 2 audit properly means completing your readiness assessment and acting on the remediation plan before you engage your CPA firm for fieldwork. The steps are:

  1. Complete the readiness assessment and receive your gap analysis.
  2. Work through the remediation plan in priority order: security controls first, then policies and procedures, then evidence collection.
  3. Run an internal review to confirm the gaps are closed.
  4. Engage your chosen CPA auditor for fieldwork once your controls are operating.

This preparation is what separates companies that pass cleanly from those that collect exceptions and pay to resolve them mid-audit.

Why it saves money

Fixing a gap before fieldwork is cheaper than having an auditor raise it as an exception and paying to resolve it mid-audit, or worse, failing and re-engaging. A readiness assessment front-loads the cheap, controllable work so the audit itself is a confirmation rather than a discovery. It also prevents the most common waste: scoping too broadly and paying to be audited against Trust Services Criteria you never needed.

SOC 2 Type 2 evidence spans the full monitoring period, and readiness assessments help you prepare by starting evidence collection early enough. Preparing this way typically reduces overall cost by preventing exception resolution fees and failed fieldwork.

What does a SOC 2 readiness assessment cost?

The cost varies with the size of your environment, the number of Trust Services Criteria in scope, and your starting maturity. A focused assessment of a single-product SaaS company costs considerably less than a multi-system enterprise engagement. The right question is not what the assessment costs in isolation but what it saves: a thorough readiness assessment typically costs a fraction of the remediation, re-engagement, or audit exception resolution it prevents.

How Onyx helps

Onyx provides SOC 2 readiness assessments: scoping the right Trust Services Criteria, reviewing your controls and evidence against the criteria, producing a rated gap analysis, and handing you a prioritized remediation plan with a realistic timeline to audit. We then support you through the remediation phase so that by the time you engage a licensed CPA firm for fieldwork, your first audit is a confirmation of work already done.

Ready to find out where your gaps are?

We scope a readiness assessment on a short call and tell you exactly what your path to SOC 2 looks like. No obligation.

Book a scope call →

See also: how to choose a SOC 2 consultant, SOC 2 audit cost, and SOC 2 Type 1 vs Type 2. Or try our free security self-assessment for an instant first read.

The bottom line

A SOC 2 readiness assessment is the rehearsal before the audit: it scopes the right Trust Services Criteria, assesses your current state, identifies and rates the gaps, and hands you a prioritized remediation plan and a realistic timeline. Run one before you book fieldwork, and the audit becomes a confirmation of work you have already done rather than a list of surprises.

FAQ

What is a SOC 2 readiness assessment?

A structured evaluation of your environment against the SOC 2 Trust Services Criteria, performed before the formal audit. It identifies where you meet the criteria and where the gaps are, and produces a prioritized remediation plan so you can fix issues before a licensed CPA firm examines you.

What happens during a SOC 2 readiness assessment?

Scoping the criteria and systems, assessing your current security controls, policies, and evidence through documentation review and interviews, identifying and rating the gaps in a gap analysis, and producing a prioritized remediation plan with a realistic timeline to audit.

Is a readiness assessment the same as the SOC 2 audit?

No. The readiness assessment is preparation; it tells you whether you would pass and what to fix. The audit is performed by an independent licensed CPA firm that examines your controls and issues the SOC 2 report. Readiness assessments are performed by readiness consultants; the audit is performed by a licensed CPA auditor.

Do I really need a readiness assessment?

It is strongly recommended. Fixing gaps before fieldwork is far cheaper than having an auditor raise exceptions during the audit or failing and re-engaging. A thorough readiness assessment also prevents over-scoping, gives you a realistic timeline, and prepares you for a Type 2 monitoring period if that is your target.

How long does a SOC 2 readiness assessment take?

It varies with the size and complexity of your environment and the scope of criteria, but it is a focused, time-boxed exercise. The output is a remediation plan you then work through before the actual SOC 2 audit. Most readiness assessments complete in weeks, significantly shorter than the Type 2 observation period that follows. The attestation from a licensed CPA comes after this readiness work is done.