SOC2Prep

Free SOC 2 readiness tools

Nine tools, all free, none of which hide the answer behind an email address. Each one gives you the result on screen and asks for a way to reach you only if you want the written version.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Nine free tools, listed below with what each one answers and how long it takes. If you have just been asked for a report and do not know where you are in the process, start with the readiness quiz. If you are already working on it, start with the scorecard, because everything else sequences off what it finds.

9 Tools, one per stage of the work

$0 Cost, and no gate on the answer

1 to 10 min Range of time each one takes

The nine tools, what each answers, and how long it takes
Tool The question it answers Length Use it when
Am I ready for an auditor Is calling audit firms this week worth the call, or would the quote come back priced against work you have not done 6 questions, about a minute Week one, before you contact anybody
Readiness scorecard Which of the six control areas is actually the problem, and how long each gap takes to close 36 items over 8 screens Week three, once scope is written
Policy checklist Which policy documents you are required to have, including the ones Canadian law drives rather than SOC 2 4 questions Before you download a template pack
Evidence tracker Every evidence item, its cadence, the artifact that satisfies it, and which ones a platform would not cover 6 questions Once you have a window date in mind
Control owner mapper Which role owns each common criteria area, who is carrying too much, and which areas have nobody accountable 7 questions Before the window opens, once scope is written
Remediation prioritiser What order to close your open gaps in, and whether the window date you have in mind survives the arithmetic 6 screens Straight after a gap assessment
Access review planner Which systems get reviewed, how often, by whom, and what evidence each review has to leave behind 7 questions Before the first review, which sets the format for all of them
Vendor risk triage Which vendors need a full review, which need a questionnaire, which need a register row, and what the auditor asks about each tier 6 questions Early, because the register is rebuilt from expense records
Policy gap finder Which policies you are missing given what you already have, ranked by how early the auditor asks for them 6 questions Once some documents exist and you need to know what is left

How the gate works, and what it does not do

The result renders in full on the page. No score is blurred, no list is truncated, no address is required to see a number. Underneath each result is an offer to send the working version of the same answer, and that is the only thing that asks for an address.

What each tool shows for free and what the written version adds
ToolOn screen, no addressWhat the written version adds
Am I ready The verdict, every blocker named, and what each one takes The date arithmetic between today and the report you were asked for
Readiness scorecard A score per control area and every finding with its lead time The same gaps reordered by lead time, with the earliest date a window could honestly open
Policy checklist Your document list and what each document has to contain A drafting note per policy, clause level, including the commitments to avoid making
Evidence tracker Every item, its cadence, its artifact and the populations sampled from The same rows as a spreadsheet with owner, folder path, last collected and next due columns
Control owner mapper The full responsibility map, the load per role and every unowned area The same rows as a matrix, with a backup owner column and the evidence each role produces quarterly
Remediation prioritiser The ordered sequence, the effort arithmetic and whether your date works The same sequence with start weeks, owners and the earliest honest window open date
Access review planner The schedule, the reviewer per system and the evidence checklist A sign-off sheet per system and a calendar of review dates across the window
Vendor risk triage Every tier, what each needs and what the auditor asks about it The register itself, with the tier rules written out and a questionnaire for the middle tier
Policy gap finder Every missing document, when it is asked for and what it has to contain A drafting note per document at clause level, including the commitments to avoid making

Those written versions are produced by a person rather than generated, so allow a working day rather than an instant download. Nothing is passed to a consultant or a platform unless you separately ask us to find you quotes.

Readiness scorecard

Thirty-six items across the six control areas a first audit turns on: access control, change management, monitoring, incident response, vendor management and people. It scores each area separately rather than giving you one number, because readiness is uneven and an average hides the area that is the problem. Every gap comes back with the missing artifact named and its lead time attached, which is what decides the order the work goes in.

Use it in the third week of a program, once your scope is written and before you commit to an observation window date. Score your readiness. If it finds more than you expected, the gap analysis page covers what a paid version of the same exercise buys you.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Policy checklist

Pick the Trust Services Criteria in scope, say what data you hold and how you run the product, and it produces the list of policy topics you are actually required to cover, with what each document has to contain. It separates the documents SOC 2 drives from the ones Canadian law drives, which is the part American template packs leave out: the PIPEDA breach record, the accountability role, and the Law 25 requirements if Quebec personal information is in scope.

Build your policy list, then read the policy templates page for how to edit a downloaded set without committing yourself to somebody else's cadences.

Evidence tracker

Builds your evidence list from your criteria, your window length and the systems you run: every item, the cadence it has to be produced on, the artifact that satisfies it, and the populations an auditor will sample from. It also tells you which items a compliance platform would cover and which stay manual, which is the number people want before deciding whether to buy one.

Build your evidence list, and read evidence collection for what auditors accept and what they reject.

Am I ready for an auditor

Six questions and about a minute. It answers one thing: whether calling audit firms now is worth the call, or whether the quote you get back would be priced against work you have not done. If you are ready it sends you to the auditors. If you are not, it says what the next piece of work is and roughly how long it takes.

Take the quiz. The checklist is the tick-box version of the same ground if you would rather work through it yourself, and the scope and system description page covers the one decision none of these tools can make for you.

Control owner mapper

An auditor asks who owns a control before asking to see it. This maps the twenty common criteria areas to the roles you actually have, names the areas nobody owns, and flags the places one person holds two duties an auditor expects to see separated. It is the tool that turns a control list into something a person can be held to. Map your control owners.

Remediation prioritiser

A gap list comes out in the order the criteria were walked, which is rarely the order the work has to happen. This ranks your open gaps by audit risk against effort, pulls anything with a long calendar lead time to the front, and tells you whether the window date you have in mind survives the arithmetic at the capacity you described. Order your remediation, then read the remediation plan page for how to write it up.

Access review planner

The access review is the most commonly tested control in a first audit and the most likely to produce an exception. This designs one that passes: a cadence per system, the right reviewer for each, the number of cycles that have to fall inside your window, and the five evidence items every review has to leave behind. Plan your access reviews, and the access review evidence page covers what auditors reject.

Vendor risk triage

Most registers treat forty suppliers as forty equal problems. This sorts yours into three tiers by data access and criticality, so the review effort lands on the handful that could actually hurt you, and it names what an auditor asks about each tier. It also covers the Canadian privacy obligations that attach where personal information leaves your systems. Triage your vendors.

Policy gap finder

The policy checklist above builds the required set. This one starts from what you already have, treats an unapproved draft the way an auditor does, and ranks what is missing by how early in the audit the request arrives. Find your policy gaps.

If you would rather somebody else did this

These are built for a team doing the preparation itself, which is the right answer for most companies of ten to fifty people. If it is not yours, the guide to readiness consultants in Canada covers what an engagement includes and what it costs, with a page for each of twenty markets, and the directory is where those firms and the compliance platforms get listed as they are checked.

Get quotes against what the tools found

Any tool can hand its result straight into the quote form with your size, your timeline and SOC 2 already filled in. Or start here and describe the scope yourself.

Get matched

Common questions

Do these tools require an email address?

No. Every result renders in full on the page with nothing asked for. Each tool offers a written version afterwards, a remediation roadmap or a spreadsheet or a drafting note, and that is the only thing that asks for an address. If the on-screen answer is all you need, take it and leave.

Are these based on the actual Trust Services Criteria?

They are built around the security criterion, which is what a first SOC 2 is nearly always scoped to, with the other four criteria adding items where you select them. They are not a substitute for your auditor's control list, which will be mapped to the criteria in that firm's own format. Use them to get ready, then reconcile against the request list the firm sends.

Which tool should we start with?

If you have just been asked for a report, the readiness quiz, because it tells you which end of the process you are at. If you are already working on it, the readiness scorecard, because everything else sequences off what it finds. The evidence tracker matters once you have a window date in mind, and not much before.

Is anything we type into a tool stored?

Not unless you submit the form underneath the result. The questions are answered in your browser and the result is calculated there. If you do submit the form, we hold those answers alongside your address so that the written version is about your situation rather than a generic one.