SOC2Prep

SOC 2 readiness assessment: what it covers

A readiness assessment answers one question: if an auditor started tomorrow, what would they find. Everything else in the deliverable is supporting detail.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

A SOC 2 readiness assessment is a structured review of your controls against the Trust Services Criteria, done before the audit, that tells you which controls would pass, which would fail, and what to fix first. Paid assessments from Canadian providers typically run $5,000 to $20,000 CAD and take two to three weeks. Doing an honest version yourself takes about a week and costs nothing but attention.

It is not the audit and it produces nothing you can send a customer. Its only job is to remove surprises before you are paying an audit firm by the hour.

What an assessment actually examines

A real assessment looks at four things, in this order. Anything that skips the last two is a document review dressed up as an assessment.

The four layers a readiness assessment should test
LayerThe questionHow it is tested
Scope Is the system description defensible and complete Interview plus review of the architecture and data flows
Design If this control worked as written, would it meet the criterion Policy and control description review
Implementation Does the control exist in the systems, right now Configuration inspection, not a conversation
Evidence Could you prove it operated for a full period Sample requests against a real population

That last row is the one that separates a useful assessment from a comfortable one. Most companies pass the design layer easily, because writing a policy is easy. They fail at evidence, because nobody kept the record. If your assessment did not ask you to produce three access reviews and two offboarding records with dates on them, it did not test the thing that will cost you.

What a good deliverable looks like

You should end up with a document you can hand to an engineer on Monday morning and have work start without a follow-up meeting. That means, at minimum:

  • A control-by-control status. Met, partially met, or not met, with a sentence of evidence for each judgement rather than a colour.
  • For every gap, the specific artifact that is missing, not a restatement of the criterion.
  • A named owner per gap, agreed with you rather than assigned by the assessor.
  • Lead time per gap, so you can sequence. A control needing a full quarterly cycle is a different problem from one needing an afternoon.
  • An earliest defensible observation window start date, derived from those lead times. This is the most valuable line in the document.
  • A view on scope, including anything you assumed was out that an auditor would pull in.
  • A draft or a critique of your system description.

What you do not need is a maturity score, a heat map, or a benchmark against unnamed peers. None of those change what happens on Monday.

Ask what happens after the report

The gap between a $6,000 CAD assessment and a $20,000 CAD one is usually not depth of testing. It is whether the provider stays involved: reviewing your remediation, re-testing the gaps, and sitting in on the first auditor call. Ask directly what is included after the document lands, because a report with no follow-up is easy to produce and easy to shelve.

Doing it yourself versus paying for it

A self-assessment is credible if you enforce one rule: nothing counts unless you can produce the artifact. Not "we do access reviews", but here are three of them with dates and names. Applied honestly, a self-assessment finds most of what a paid one finds. Applied loosely, it finds nothing, because the whole exercise becomes people confirming their own work.

Self-assessment versus paid assessment
FactorDo it yourselfPay for it
Cost$0, about a week of one person$5,000 to $20,000 CAD
Elapsed time1 to 2 weeks2 to 3 weeks
Knows what auditors acceptOnly if someone has been through itYes, and this is the main thing you buy
ObjectivityHard. You built the thing you are judgingStructurally better
Useful with the board or a customerLimitedAn external document carries weight
Teaches your team the programYes, and this is the main thing you getOnly if you stay in the room

Pay for it when a signed contract sets your date, when your environment involves more than one product or an acquisition, when regulated data such as health information under PHIPA is in scope, or when an earlier attempt already stalled. Do it yourself when the date is yours to set and you would rather spend the money on remediation, which is where it does more good.

How to run your own in a week

Block five days and treat it as a real piece of work rather than something squeezed between meetings.

Day one, scope. Write the system description. Draw the data flow. List every system holding customer data, every cloud account, every third party. Decide what is in and write down why anything is out.

Day two, controls on paper. Take the checklist and mark each item met, partial or missing, based only on what you believe today. This is your hypothesis, not your result.

Days three and four, test it. For every item you marked met, produce the artifact. Open the console and screenshot the configuration. Export the user list. Find the last access review. Pull three merged pull requests and check each had a reviewer. Pick two people who left and check when their access was actually removed. Expect a third of your met items to move to partial. That movement is the entire value of the exercise.

Day five, sequence it. Turn the surviving gaps into a list ordered by lead time rather than by severity. Assign an owner and a date to each. Then work backwards from the longest one to find the earliest date your observation window can honestly begin. The timeline page shows how to do that arithmetic.

When in the process to run one

Run it after remediation and before the observation window opens. Too early and it just reproduces your gap analysis. Too late and its findings land inside a window you have already started, which is the expensive case, because a control that was not operating in month one cannot be fixed retroactively.

Some companies also run a short second pass a few weeks into the window, checking only that evidence is accumulating as expected. That is cheap, quick, and catches the most common failure in a first audit.

A readiness assessment is distinct from a gap analysis, though vendors use the terms interchangeably. A gap analysis asks what you are missing at the start. A readiness assessment asks whether what you built would survive contact with an auditor at the end. Buying one when you needed the other is a common and avoidable waste.

Want an outside read on where you stand

Describe your environment and your target date and we will tell you whether a self-assessment is enough or whether this needs an external pair of eyes.

Get matched

Common questions

How much does a SOC 2 readiness assessment cost in Canada?

Roughly $5,000 to $20,000 CAD for an assessment and report from a Canadian consultancy, with the range driven by how many systems are in scope and whether remediation support is included. Bundled readiness programs where the provider also runs the remediation typically fall between $20,000 and $60,000 CAD.

Can our audit firm do the readiness assessment too?

Some firms offer it, and independence rules limit how far they can go. An auditor cannot design or implement the controls they will later examine, so a readiness engagement from your audit firm tends to be advisory and deliberately hands off. Many companies use a separate provider for readiness precisely to avoid the question, and doing so also gives you a second opinion.

How long does a readiness assessment take?

Two to three weeks for a paid engagement, of which perhaps three days are your team's time in interviews and evidence pulls. A self-assessment is about a week if someone works on it properly, and considerably longer if it is done in gaps between other work, which is usually when it stops being honest.

Do we need a readiness assessment if we use a compliance platform?

The platform tells you which automated checks are passing, which is a genuine part of the picture but not all of it. It does not judge whether your scope is defensible, whether your system description is accurate, whether a manual control is really operating, or whether your evidence would survive sampling. If your team has done this before, the platform plus your own honest review may be enough. If it is your first audit, an outside read is cheap insurance.

What happens if the assessment finds a lot of gaps?

That is a normal first-time result and a good outcome. Gaps found before the observation window cost remediation time. The same gaps found during fieldwork cost either an exception on the report or a restarted window. Sequence them by lead time, fix the long ones first, and move your window start date rather than starting on schedule with controls that are not running.