SOC 2 Readiness Assessment
Free SOC 2 Type I & Type II Readiness Audit (AICPA TSC, CC1-CC9)
A SOC 2 Type I / II readiness assessment benchmarked against the AICPA TSC 2017 - Security (CC1-CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1). Complements Vanta, Drata, Secureframe, Sprinto, Thoropass, and Hyperproof with senior-compliance-engineer-verified gap analysis: subservice scoping, CUECs, evidence quality, observation-period planning, and the surprises auditors raise on day one. Read-only access - no customer data exposed.
- Covers AWS, Azure, and Google Cloud - with AICPA TSC 2017 mapping for Security (CC1-CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1-P8)
- Complements Vanta, Drata, Secureframe, Sprinto, Thoropass, and Hyperproof by adding the human-verified gap analysis automation platforms don't do well
- Senior compliance engineer verifies every finding - typical first audit surfaces 25-50 control gaps and 5-10 evidence gaps before the Type II observation window starts
- Read-only access only
- No customer data leaves your environment
- Senior compliance-engineer verified
- Live findings walkthrough included
Supported Platforms
What We Audit Against the AICPA Trust Services Criteria
Six areas covering every Trust Services Criterion your auditor will test - with the same AICPA TSC 2017 mapping, scoping language, and evidence forms used by Big Four and SOC-2-specialist firms.
Security (CC1-CC9 Common Criteria)
Reviews the nine Common Criteria - control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation - across IAM, MFA, encryption, vulnerability management, incident response, and SDLC change management.
Availability (A1) & Resilience
Assesses SLA commitments, uptime monitoring, capacity planning, backup and recovery, multi-AZ / multi-region posture, RTO and RPO targets, and DR testing - against A1.1, A1.2, and A1.3 with the evidence forms auditors actually accept.
Confidentiality, Privacy & Data Lifecycle
Evaluates data classification, retention and deletion procedures, encryption with customer-managed keys, privacy-notice alignment, GDPR / CCPA overlap, and data-subject-rights workflow - mapped to C1 and the seven P-series criteria where Privacy is in scope.
Vendor, Subservice Organisation & Third-Party Risk
Reviews your third-party vendor inventory, subservice organisation listing (carve-out vs inclusive), CUECs (complementary user entity controls), CSOC mapping, and supply-chain risk management - using AICPA-standard terminology your auditor expects.
Evidence Readiness & Observation Window
Identifies which controls already produce audit-quality evidence, which need process changes before the Type II observation window starts (3-12 months), and which need documentation. Includes evidence mapping for AWS Audit Manager, Config, Security Hub, Azure Defender for Cloud, Purview, GCP SCC, plus Vanta, Drata, Secureframe, Sprinto, and Hyperproof.
Readiness Score & Auditor Selection Brief
A SOC 2 Readiness Score (0-100) per Trust Services Criterion with a prioritised gap list, estimated effort per gap, and a written auditor-selection brief - recommended firm tier, scoping language, fee benchmarks, and timeline guidance for Type I vs Type II.
How It Works
Register & Scope Definition
Tell us which Trust Services Criteria you intend to scope (Security is always required), Type I vs Type II target, and your current state. We provide a ready-to-deploy read-only IAM Role, App Registration, or Service Account plus an evidence-request list - no customer data leaves your environment.
Automated Controls & Evidence Scan
We benchmark cloud configuration against AICPA TSC 2017 using AWS Audit Manager, Config, Security Hub, Azure Defender for Cloud, Purview Compliance Manager, and GCP SCC signals where you have them - plus a structured policy review and a check of whether Vanta, Drata, Secureframe, Sprinto, Thoropass, or Hyperproof is correctly mapped.
Senior Compliance Engineer Verification
A senior compliance engineer who has been through the auditor side reviews every finding, removes false positives, models audit risk including likely auditor exceptions and management-response language, scopes subservice organisations and CUECs, and rewrites recommendations into account-specific remediation steps.
Receive Report & Live Debrief
Get your SOC 2 Readiness Score per TSC, control-by-control pass / partial / fail report, evidence-gap list, observation-window plan, and auditor-selection brief - within 1-2 business days, plus a 45-minute live walkthrough.
What You Get
Your report will include the following deliverables.
Avoid the surprise findings on day one of your SOC 2 audit.
Get a senior-engineer-verified gap report with AICPA TSC mapping, observation-window plan, and auditor-selection brief - read-only access only, no customer data exposed, completely free.
Get My SOC 2 Gap ReportHow We Handle Your Cloud Configuration & Policies
A SOC 2 readiness audit must never become a SOC 2 incident. Here is exactly what we read - and what never leaves your environment.
Read-Only, Time-Limited Access
We use a read-only IAM Role (AWS), App Registration (Azure), or Service Account (GCP) scoped strictly to compliance-relevant configuration APIs and time-limited to the assessment window. We can never read customer data, modify resources, change IAM, or trigger any workflow.
No Customer Data or Sensitive Policies Exfiltrated
The audit reads cloud configuration metadata only - IAM, encryption settings, log coverage, network rules, automation-platform mappings. We never read database rows, object contents, or message payloads. Policy documents you share for review are kept in an isolated workspace and never used for training or distribution. NDA available on request.
Auto-Revoked & Destroyed After Audit
As soon as your gap report is delivered, every credential is revoked, the analysis sandbox is destroyed, and your configuration export and shared policy documents are deleted. Only aggregate, anonymised findings are retained for QA - never account, resource, or organisational identifiers.
Frequently Asked Questions
The most common questions we hear from teams running this assessment.
Should we go for SOC 2 Type I or Type II first?
Type I tests whether your controls are designed correctly at a single point in time and can be issued in 4-6 weeks; Type II tests whether those controls operated effectively across an observation window of typically 3-12 months and is what most enterprise customers actually want to see. The right answer depends on your sales cycle, current control maturity, and how soon enterprise prospects need a report. The assessment includes a Type I vs Type II decision matrix tailored to your timeline, and many teams use Type I as a 4-6 week bridge while the Type II observation window runs in parallel.
How is this different from Vanta, Drata, Secureframe, or Sprinto?
Compliance-automation platforms continuously collect evidence and tell you whether a control is connected - but they do not tell you whether your control design will actually pass an auditor's review, whether your subservice organisations are scoped correctly, whether your CUECs are complete, or what the auditor will raise as exceptions on day one. The assessment is explicitly designed to complement those platforms by adding the human-verified gap analysis they don't do well. If you already use Vanta, Drata, Secureframe, Sprinto, Thoropass, or Hyperproof, we sanity-check the mapping and identify where the platform is producing false confidence.
Do you align with the AICPA Trust Services Criteria your auditor will use?
Yes. The assessment maps every finding to the AICPA TSC 2017 - Security (CC1-CC9 Common Criteria), Availability (A1.1-A1.3), Confidentiality (C1.1-C1.2), Processing Integrity (PI1.1-PI1.5), and Privacy (P1-P8) - using the same scoping language, control IDs, and evidence forms that Big Four and SOC-2-specialist firms (BDO, Grant Thornton, A-LIGN, Schellman, Prescient Assurance, Insight Assurance, KirkpatrickPrice) use in their workpapers.
What is the Type II observation window and how do you help us plan for it?
Type II reports test that controls operated effectively across an observation window - typically 3, 6, 9, or 12 months. Once the window starts, every control gap during that period becomes an audit exception. The assessment includes an observation-window plan that tells you which gaps must be closed before the window starts, which can be remediated during the window without becoming exceptions, and which automation platform integrations need to be live before day one of the window.
How do you handle subservice organisations, CUECs, and CSOCs?
Every subservice organisation (your hosting provider, payment processor, email vendor) must be either carved out or included in your report. We list every subservice organisation we identify in your stack, recommend carve-out vs inclusive method per AICPA SSAE-18 guidance, draft Complementary User Entity Controls (CUECs) for your customers and Complementary Subservice Organisation Controls (CSOCs) you rely on from your subservices, and review their SOC 2 reports if available - so your final report has the right scoping language an auditor will accept.
Do you cover ISO 27001, HIPAA, GDPR, or PCI overlap?
Yes. Many teams pursuing SOC 2 also need ISO 27001 (often via cross-mapping), HIPAA (for healthcare), GDPR (for EU customers), or PCI-DSS (for cardholder data). The assessment flags every control that satisfies multiple frameworks, identifies framework-specific extras (e.g. ISO 27001 Annex A.5-A.8 vs SOC 2 CC, HIPAA §164.312 mapping to CC6, GDPR Article 32 alignment), and the report can be reused as input for a multi-framework programme.
Will the assessment affect production systems?
No. The assessment is fully read-only and runs against configuration APIs at a controlled rate. Nothing we do can modify resources, change IAM, restart workloads, or affect production. You can run the audit during normal business hours with zero risk to delivery.
How long until we receive the report?
Typical turnaround is 1-2 business days from the moment read-only access is granted, plus a 45-minute live findings walkthrough at a time that suits your security and engineering leads. Larger multi-account, multi-cloud, or multi-product estates can take a little longer; we confirm the timeline as soon as we see the scope.
Register for Your Free SOC 2 Readiness Assessment
Fill out the form below and our team will get back to you within 2 business days.
You Might Also Be Interested In
HIPAA Compliance Audit
Free read-only HIPAA gap audit for AWS, Azure, and Google Cloud - covering the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule, aligned with the HHS OCR Audit Protocol and HITRUST CSF, verified by a senior compliance engineer.
DevOps DORA Checklist
See where your delivery performance stands against Elite, High, Medium, and Low performers - automatically scored, expert-verified.
Pipeline Inspector
Find every weak link in your CI/CD - automated scanning across GitHub Actions, GitLab, Jenkins, Bitbucket, and Azure DevOps, verified by a senior platform engineer.