SOC2Prep

SOC 2 gap analysis: how to run one

A gap analysis is the cheapest week you will spend on SOC 2. It turns an open-ended project into a finite list with owners and dates.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

A SOC 2 gap analysis compares the Trust Services Criteria against what your company does today and produces a ranked list of what is missing. You can run one yourself in about a week using the checklist as the control set. Paid gap analyses from Canadian consultancies run roughly $5,000 to $15,000 CAD and take two to three weeks.

It comes early, before remediation and long before you speak to an auditor. Its whole purpose is to convert "we need SOC 2" into a list somebody can start working on tomorrow.

Do not start without a scope

A gap analysis without a defined scope produces a list you cannot act on, because half the findings apply to systems you were never going to include. Before you begin, write down the product and environments in scope, the data involved, and which criteria you are pursuing. Security alone is the right answer for most first audits, and each additional criterion adds controls the analysis has to cover.

If you cannot write that page yet, that is your first gap, and the preparation guide covers how to write it.

Running one yourself, day by day

The method is simple and the discipline is the hard part: a control is a gap unless you can produce the artifact today.

Day one, build the control list. Take the checklist and turn it into rows in a spreadsheet: control, what it requires, the system it lives in, the evidence that would prove it, and an owner. Do not shorten the list to things you think you have.

Day two, interview the systems, not the people. Open the consoles. Look at the identity provider, cloud accounts, code repository, device management and ticketing system. Record what is configured rather than what anyone believes is configured. This single step reclassifies a large share of assumed controls.

Day three, test the human controls. Ask for the last access review, the last vendor review, the training completion export, the offboarding record for the two most recent departures, the last risk assessment, the incident log. Each one either exists with a date or it is a gap. There is no partial credit for intent.

Day four, classify. Mark each row met, partial or missing, and for the partials write the specific thing that is absent. "Access control partial" is useless. "Access control exists but no review has been performed and the policy commits to quarterly" is a work item.

Day five, sequence and cost it. Add a lead time and an owner to every gap, then sort by lead time descending. That order, not severity order, is your work plan, because the longest-lead item sets the date your observation window can start.

Rank by lead time, not by severity

Severity ranking feels right and produces a worse plan. A missing multi-factor policy is severe and takes a day. A quarterly access review is unremarkable and takes three months of calendar time before you have a cycle inside the window. The second one decides your schedule.

Common gaps by how long they take to close
GapLead timeWhy
No periodic access reviewOne full cycleA cycle must complete inside the observation window
Log retention shorter than the windowImmediate to change, then the window itselfRetention cannot be applied to deleted logs
No security awareness training2 to 6 weeksRollout plus chasing completion across everyone
No penetration test4 to 8 weeksScheduling, testing, remediation and retest
No background checksOnly forward-lookingEvidenced only by hires after you start
No vendor register or reviews2 to 6 weeksGetting subprocessor reports takes longer than expected
Change approvals not enforced1 to 2 weeksBranch protection is quick, culture takes a little longer
Policies missing1 to 3 weeksWriting is fast, approval and acknowledgement are not
No risk assessment1 weekPoint in time, feeds several other controls
No restore test1 dayPoint in time, though it may reveal a real problem

The gaps first-time companies almost always have

These recur so reliably that you can assume them until you prove otherwise. Nobody has ever run a formal access review. Offboarding happens but is not recorded, so there is no artifact. There is no vendor register, only an expenses report. Log retention is at whatever the default was. Policies either do not exist or were downloaded and describe a company with a change advisory board. There is no risk assessment in any form. Security training has never been delivered. Backups run but no restore has been tested. Incidents get handled in a chat channel and are never written up, so the incident log is empty in a way that looks like a control failure rather than a quiet year.

An empty log is not evidence of nothing happening

Auditors read an empty incident log as an absent process, not as a clean record. The same applies to change tickets and access requests. If the real answer is that these events go through a chat conversation, the gap is the record rather than the behaviour, and that is usually a one week fix that saves an awkward conversation later.

When to pay someone

A paid gap analysis costs $5,000 to $15,000 CAD in Canada and buys you two things: someone who knows what an auditor will accept, and an outside voice that is structurally able to say your controls are weaker than you think. Neither is available internally on a first audit.

Pay for it when the date is set by a contract and a wrong plan is expensive, when the environment involves more than one product or an acquisition, when regulated data is in scope, or when an internal attempt has already stalled for a quarter. Do it yourself when you control the date, your stack is one cloud and one product, and someone can genuinely give it a week.

If you pay, insist the deliverable names artifacts rather than criteria, and that it carries lead times. A report that restates the Trust Services Criteria back to you with red, amber and green is a document you have to translate before anyone can act on it, and translation is the work you were paying to avoid.

What happens after the gap analysis

Remediation, then a readiness assessment to confirm the gaps really closed, then the observation window. The gap analysis asks what you are missing at the start. The readiness assessment asks whether what you built would survive an auditor at the end. They are different exercises and vendors sell both under either name, so read the scope rather than the title.

Work the plan by lead time, keep the spreadsheet as your live status board rather than archiving the report, and set the window start date from the last gap to close rather than from the date you hoped for. When the window is running and evidence is accumulating, GetSOC2 covers choosing the audit firm.

Want your gap list reviewed

Send us what you found and we will tell you what is missing from the list and whether your window start date holds.

Get matched

Common questions

What is the difference between a gap analysis and a readiness assessment?

Timing and question. A gap analysis runs at the start and asks what controls you do not have. A readiness assessment runs after remediation and asks whether an auditor would accept the evidence you now hold. Vendors use the terms loosely, so compare the described work rather than the label.

How long does a SOC 2 gap analysis take?

About a week internally if someone works on it properly, or two to three weeks for a paid engagement of which a few days are your team's time. Doing it in spare moments across a month generally produces a list that reflects what people believe rather than what the systems show.

Can a compliance platform replace a gap analysis?

Partly. A platform gives you a control framework and flags failing automated checks, which is a real head start. It cannot tell you whether your scope is right, whether a manual control is genuinely operating, or how long each gap takes to close, and lead time is the output that actually drives your schedule.

How many gaps is normal for a first audit?

Most first-time companies find a substantial fraction of their control list is missing or partial, and that is the expected result rather than a bad sign. What matters is the shape: a long list of quick documentation fixes is a few weeks of work, while two or three long-lead items such as access review cycles and a penetration test are what set your date.

Should we do the gap analysis before or after picking an auditor?

Before. Nothing in it depends on the firm, and you will have a far better conversation with auditors once you can describe your scope, your control list and your intended window. Choosing a firm first tends to compress the preparation into whatever time is left before their booked dates.