Compliance

SOC 2 Readiness Assessment

Free SOC 2 Type I & Type II Readiness Audit (AICPA TSC, CC1-CC9)

A SOC 2 Type I / II readiness assessment benchmarked against the AICPA TSC 2017 - Security (CC1-CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1). Complements Vanta, Drata, Secureframe, Sprinto, Thoropass, and Hyperproof with senior-compliance-engineer-verified gap analysis: subservice scoping, CUECs, evidence quality, observation-period planning, and the surprises auditors raise on day one. Read-only access - no customer data exposed.

  • Covers AWS, Azure, and Google Cloud - with AICPA TSC 2017 mapping for Security (CC1-CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1-P8)
  • Complements Vanta, Drata, Secureframe, Sprinto, Thoropass, and Hyperproof by adding the human-verified gap analysis automation platforms don't do well
  • Senior compliance engineer verifies every finding - typical first audit surfaces 25-50 control gaps and 5-10 evidence gaps before the Type II observation window starts
  • Read-only access only
  • No customer data leaves your environment
  • Senior compliance-engineer verified
  • Live findings walkthrough included

Supported Platforms

Amazon AWS
Microsoft Azure
Google Cloud

What We Audit Against the AICPA Trust Services Criteria

Six areas covering every Trust Services Criterion your auditor will test - with the same AICPA TSC 2017 mapping, scoping language, and evidence forms used by Big Four and SOC-2-specialist firms.

Security (CC1-CC9 Common Criteria)

Reviews the nine Common Criteria - control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation - across IAM, MFA, encryption, vulnerability management, incident response, and SDLC change management.

Availability (A1) & Resilience

Assesses SLA commitments, uptime monitoring, capacity planning, backup and recovery, multi-AZ / multi-region posture, RTO and RPO targets, and DR testing - against A1.1, A1.2, and A1.3 with the evidence forms auditors actually accept.

Confidentiality, Privacy & Data Lifecycle

Evaluates data classification, retention and deletion procedures, encryption with customer-managed keys, privacy-notice alignment, GDPR / CCPA overlap, and data-subject-rights workflow - mapped to C1 and the seven P-series criteria where Privacy is in scope.

Vendor, Subservice Organisation & Third-Party Risk

Reviews your third-party vendor inventory, subservice organisation listing (carve-out vs inclusive), CUECs (complementary user entity controls), CSOC mapping, and supply-chain risk management - using AICPA-standard terminology your auditor expects.

Evidence Readiness & Observation Window

Identifies which controls already produce audit-quality evidence, which need process changes before the Type II observation window starts (3-12 months), and which need documentation. Includes evidence mapping for AWS Audit Manager, Config, Security Hub, Azure Defender for Cloud, Purview, GCP SCC, plus Vanta, Drata, Secureframe, Sprinto, and Hyperproof.

Readiness Score & Auditor Selection Brief

A SOC 2 Readiness Score (0-100) per Trust Services Criterion with a prioritised gap list, estimated effort per gap, and a written auditor-selection brief - recommended firm tier, scoping language, fee benchmarks, and timeline guidance for Type I vs Type II.

How It Works

1

Register & Scope Definition

Tell us which Trust Services Criteria you intend to scope (Security is always required), Type I vs Type II target, and your current state. We provide a ready-to-deploy read-only IAM Role, App Registration, or Service Account plus an evidence-request list - no customer data leaves your environment.

2

Automated Controls & Evidence Scan

We benchmark cloud configuration against AICPA TSC 2017 using AWS Audit Manager, Config, Security Hub, Azure Defender for Cloud, Purview Compliance Manager, and GCP SCC signals where you have them - plus a structured policy review and a check of whether Vanta, Drata, Secureframe, Sprinto, Thoropass, or Hyperproof is correctly mapped.

3

Senior Compliance Engineer Verification

A senior compliance engineer who has been through the auditor side reviews every finding, removes false positives, models audit risk including likely auditor exceptions and management-response language, scopes subservice organisations and CUECs, and rewrites recommendations into account-specific remediation steps.

4

Receive Report & Live Debrief

Get your SOC 2 Readiness Score per TSC, control-by-control pass / partial / fail report, evidence-gap list, observation-window plan, and auditor-selection brief - within 1-2 business days, plus a 45-minute live walkthrough.

What You Get

Your report will include the following deliverables.

SOC 2 Readiness Score per Trust Services Criterion (CC1-CC9, A1, C1, PI1, P1)
Control-by-control pass / partial / fail assessment with AICPA TSC 2017 mapping
Evidence gap list with documentation requirements and audit-quality criteria
Type I vs Type II decision matrix and observation-period plan
Subservice organisation scoping (carve-out vs inclusive) and CUEC list
Vendor and third-party risk management assessment
Compliance-automation platform sanity check (Vanta, Drata, Secureframe, Sprinto, Hyperproof)
Prioritised remediation roadmap with effort estimates
Auditor selection brief with firm-tier guidance, scoping language, fee benchmarks, and timeline
45-minute live findings walkthrough with your security and engineering leads

Avoid the surprise findings on day one of your SOC 2 audit.

Get a senior-engineer-verified gap report with AICPA TSC mapping, observation-window plan, and auditor-selection brief - read-only access only, no customer data exposed, completely free.

Get My SOC 2 Gap Report

How We Handle Your Cloud Configuration & Policies

A SOC 2 readiness audit must never become a SOC 2 incident. Here is exactly what we read - and what never leaves your environment.

Read-Only, Time-Limited Access

We use a read-only IAM Role (AWS), App Registration (Azure), or Service Account (GCP) scoped strictly to compliance-relevant configuration APIs and time-limited to the assessment window. We can never read customer data, modify resources, change IAM, or trigger any workflow.

No Customer Data or Sensitive Policies Exfiltrated

The audit reads cloud configuration metadata only - IAM, encryption settings, log coverage, network rules, automation-platform mappings. We never read database rows, object contents, or message payloads. Policy documents you share for review are kept in an isolated workspace and never used for training or distribution. NDA available on request.

Auto-Revoked & Destroyed After Audit

As soon as your gap report is delivered, every credential is revoked, the analysis sandbox is destroyed, and your configuration export and shared policy documents are deleted. Only aggregate, anonymised findings are retained for QA - never account, resource, or organisational identifiers.

Frequently Asked Questions

The most common questions we hear from teams running this assessment.

Should we go for SOC 2 Type I or Type II first?

Type I tests whether your controls are designed correctly at a single point in time and can be issued in 4-6 weeks; Type II tests whether those controls operated effectively across an observation window of typically 3-12 months and is what most enterprise customers actually want to see. The right answer depends on your sales cycle, current control maturity, and how soon enterprise prospects need a report. The assessment includes a Type I vs Type II decision matrix tailored to your timeline, and many teams use Type I as a 4-6 week bridge while the Type II observation window runs in parallel.

How is this different from Vanta, Drata, Secureframe, or Sprinto?

Compliance-automation platforms continuously collect evidence and tell you whether a control is connected - but they do not tell you whether your control design will actually pass an auditor's review, whether your subservice organisations are scoped correctly, whether your CUECs are complete, or what the auditor will raise as exceptions on day one. The assessment is explicitly designed to complement those platforms by adding the human-verified gap analysis they don't do well. If you already use Vanta, Drata, Secureframe, Sprinto, Thoropass, or Hyperproof, we sanity-check the mapping and identify where the platform is producing false confidence.

Do you align with the AICPA Trust Services Criteria your auditor will use?

Yes. The assessment maps every finding to the AICPA TSC 2017 - Security (CC1-CC9 Common Criteria), Availability (A1.1-A1.3), Confidentiality (C1.1-C1.2), Processing Integrity (PI1.1-PI1.5), and Privacy (P1-P8) - using the same scoping language, control IDs, and evidence forms that Big Four and SOC-2-specialist firms (BDO, Grant Thornton, A-LIGN, Schellman, Prescient Assurance, Insight Assurance, KirkpatrickPrice) use in their workpapers.

What is the Type II observation window and how do you help us plan for it?

Type II reports test that controls operated effectively across an observation window - typically 3, 6, 9, or 12 months. Once the window starts, every control gap during that period becomes an audit exception. The assessment includes an observation-window plan that tells you which gaps must be closed before the window starts, which can be remediated during the window without becoming exceptions, and which automation platform integrations need to be live before day one of the window.

How do you handle subservice organisations, CUECs, and CSOCs?

Every subservice organisation (your hosting provider, payment processor, email vendor) must be either carved out or included in your report. We list every subservice organisation we identify in your stack, recommend carve-out vs inclusive method per AICPA SSAE-18 guidance, draft Complementary User Entity Controls (CUECs) for your customers and Complementary Subservice Organisation Controls (CSOCs) you rely on from your subservices, and review their SOC 2 reports if available - so your final report has the right scoping language an auditor will accept.

Do you cover ISO 27001, HIPAA, GDPR, or PCI overlap?

Yes. Many teams pursuing SOC 2 also need ISO 27001 (often via cross-mapping), HIPAA (for healthcare), GDPR (for EU customers), or PCI-DSS (for cardholder data). The assessment flags every control that satisfies multiple frameworks, identifies framework-specific extras (e.g. ISO 27001 Annex A.5-A.8 vs SOC 2 CC, HIPAA §164.312 mapping to CC6, GDPR Article 32 alignment), and the report can be reused as input for a multi-framework programme.

Will the assessment affect production systems?

No. The assessment is fully read-only and runs against configuration APIs at a controlled rate. Nothing we do can modify resources, change IAM, restart workloads, or affect production. You can run the audit during normal business hours with zero risk to delivery.

How long until we receive the report?

Typical turnaround is 1-2 business days from the moment read-only access is granted, plus a 45-minute live findings walkthrough at a time that suits your security and engineering leads. Larger multi-account, multi-cloud, or multi-product estates can take a little longer; we confirm the timeline as soon as we see the scope.

Register for Your Free SOC 2 Readiness Assessment

Fill out the form below and our team will get back to you within 2 business days.

Your SOC 2 Footprint

These six answers help us scope the assessment, choose the right TSC criteria and automation-platform integrations, and tailor the gap report and auditor-selection brief to your specific timeline.

Your data is protected under our Non-Disclosure Agreement.By registering, you and OpsHero are bound by our NDA - guaranteeing your data is used solely to generate this report, runs in an isolated sandbox, and is permanently deleted once complete. We retain absolutely nothing.

By clicking "Register for Free Review" you agree to our Non-Disclosure Agreement and confirm your data may be processed solely for report generation.