SOC2Prep

SOC 2 readiness scorecard

Thirty-six questions across the six areas a first SOC 2 audit turns on. Tick an item only if you could produce the artifact today, because that is the standard the auditor will hold you to.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

This is a self-assessment against the security criterion, which is what a first SOC 2 audit is nearly always scoped to. It scores six areas separately rather than giving you one number, because readiness is rarely even: most teams are strong on change management and weak on vendors and evidence, and an average hides that.

One rule makes the result worth having. Tick an item only if you could open a console or a folder right now and produce the artifact. Not "we do that", but here it is, with a date on it. Applied loosely this exercise tells you nothing, because it becomes people confirming their own work.

The score and the findings appear on this page. Nothing is emailed anywhere unless you ask for it at the end.

Access control

Tick what you could evidence today.

Change management
Monitoring and infrastructure
Incident response and resilience
Vendor management
People and onboarding
How many people work there?

When does a report have to exist by?

How the score is worked out

Each of the six sections has six items and each item is worth one point, so a section is scored out of six and the whole thing out of thirty-six. There is no weighting, and that is deliberate. Weighting implies we know which control your auditor will push on, and we do not. A section scoring two out of six has a structural problem rather than a tidy-up, and the section scores are what you should act on.

The bands are blunt on purpose. Below about twenty-four out of thirty-six you are not close enough to open an observation window, because at that level the gaps are usually periodic controls that need a full cycle to evidence. Between twenty-four and thirty-two you are in remediation, which is the normal place to be three months in. Above thirty-two the remaining work is generally evidence discipline rather than missing controls.

What this does not test

Three things this cannot judge and a real readiness assessment does. Whether your scope is defensible, which is a conversation about your architecture. Whether your system description matches what you actually run. And whether your evidence would survive sampling, which needs somebody to pick items from your population and ask you for each one. A high score here with an undefensible scope is still a stalled audit.

What to do with a low section

Order the gaps by lead time, not by how uncomfortable they are. Anything with a cycle inside the observation window is the long pole: access reviews, vendor reviews, training completion, and the penetration test with its remediation. Log retention belongs in the same group for a different reason, since retention cannot be applied backwards to logs that have already been deleted.

Point-in-time items such as a tabletop exercise, a restore test or a policy approval can be done late and still count, provided they fall inside the window. Fixing those first feels productive and moves your start date not at all. The timeline page shows how to work backwards from a report date, and the checklist is the full item-by-item version of what this tool samples.

Common questions

What is a good SOC 2 readiness score?

Above thirty-two out of thirty-six before you open an observation window, with no single section below four. An overall score in the high twenties with one section at one or two is a worse position than an even score in the mid twenties, because a whole control area missing is usually months of work rather than weeks.

Does a good score mean we will pass the audit?

No. This tests whether the controls exist and are evidenced today. A Type 2 audit tests whether they operated across a period, which is a different question that only calendar time answers. A company scoring thirty-six today and starting its window tomorrow still has three months at minimum before an auditor can begin fieldwork.

Should we answer for what we do or what our policy says?

What you do, and only where you could produce the artifact. Policies describing controls you do not operate are worse than having no policy on that topic, because every commitment in a policy becomes a control the auditor tests. If the two disagree, score what happens and then fix the policy to match.

Can we use this if we already have a compliance platform?

Yes, and the sections it scores worst are usually the ones the platform does not touch. Automated checks cover configuration state and user lists well. Vendor reviews, tabletops, training records, access review decisions and incident write-ups are manual, and they account for a large share of the items here.

Want an outside read on the same questions

Send your score and your target date and we will tell you whether this needs a paid readiness assessment or just a plan.

Get matched