A SOC 2 gap assessment answers the question your auditor will not answer for free: how much of the report can you already evidence? Not what the Trust Services Criteria say, not what a vendor’s checklist thinks you need — where you actually stand against all 61 criteria, before you commit to an observation period.

This assessment scopes the report first, then scores every criterion: all 33 common criteria, plus availability, confidentiality, processing integrity and privacy if you take them. It is free, it saves as you go, and you can stop and come back to it.

What is a SOC 2 gap assessment?

A gap assessment compares what your organisation does today against the AICPA Trust Services Criteria, and records the distance. It is the step before you engage a CPA firm, and the step that decides whether your first audit produces a clean report or a list of exceptions.

The usual surprise is not a missing control. It is that scope was never decided — nobody wrote down which trust services categories the report covers, the system boundary was assumed rather than drawn, or the subservice organisations were carved out without anyone reading their reports. Those are scoping failures, and they cost more to fix once the observation period has started.

What this assessment covers

69 assessable items: 8 scoping decisions, then every criterion in the 2017 Trust Services Criteria with the 2022 revised points of focus.

DomainItemsWhat it asks about
Scope and report readiness8Categories, report type, system boundary and description, control mapping, subservice organisations, complementary user entity controls
CC1 Control environment5Code of conduct, board oversight, structures, competence, accountability
CC2 Communication and information3Asset inventory and classification, internal and external communication
CC3 Risk assessment4Objectives, risk identification, fraud, change
CC4 Monitoring activities2Ongoing and separate evaluations, deficiency reporting
CC5 Control activities3Control selection, technology general controls, policies
CC6 Logical and physical access8Identity, authorisation, removal, physical access, disposal, boundaries, transmission, malicious software
CC7 System operations5Vulnerability detection, monitoring, event evaluation, incident response, recovery
CC8 Change management1Authorisation, testing and approval of change
CC9 Risk mitigation2Business disruption, vendor and business partner risk
Availability3Capacity, backup and recovery infrastructure, recovery testing
Confidentiality2Identifying confidential information, disposing of it
Processing integrity5Specifications, inputs, processing, outputs, storage
Privacy18Notice, choice and consent, collection, use and retention, access, disclosure, quality, monitoring

Choose your categories before you score anything

Security is mandatory. The other four are not, and every one you add is more control work, a longer audit and a larger bill. Most buyers ask for Security alone, or Security plus Availability. Confidentiality is common in enterprise software; Processing Integrity matters if you compute something your customer relies on; Privacy is the heaviest of the four and is usually driven by a specific contract.

The assessment asks you to decide this first, then only scores the categories you selected. If you are not sure, score the common criteria and leave the rest — you can come back.

Type 1 or Type 2

A Type 1 report says your controls were suitably designed at a point in time. A Type 2 says they operated effectively across a period, usually three to twelve months. A Type 1 buys you a few months of credibility with a buyer who is waiting; a Type 2 is what most enterprise procurement teams eventually insist on.

The expensive mistake is deciding late. If you start the observation period before the controls are actually running, the exceptions are already in the report by the time anyone notices.

How the scoring works

Each item is scored on the same six-point scale, weighted so that evidence counts for more than intention:

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records an auditor can sample
Not applicable—A justified exclusion, removed from the score

The gap between “implemented” and “evidenced” is the one that matters for SOC 2. A Type 2 audit samples records across the period. A control that works but leaves no trace produces an exception exactly as surely as a control that does not work.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and adds the detail you need to actually run the remediation: every criterion with your status and notes, the score broken down by domain, a prioritised gap list, and the specific Governance Docs documents that close each gap. It comes as both a PDF and a working Excel file.

How long does it take?

About 35 minutes if you know your environment, longer if you have to check things — and you should check things. Answers save as you go, so treating it as three sittings across a week is normal and produces a more honest score than one optimistic pass.

Gap assessment, readiness assessment, audit

Three different things, often confused:

  • Gap assessment — you, scoring yourself against the criteria. Free, fast, and the right place to start.
  • Readiness assessment — a CPA firm or consultant doing the same work with an outside eye, usually a few weeks and four figures. Worth it once your own score is high enough that the findings will be about nuance rather than absence.
  • SOC 2 examination — the audit itself, performed by a licensed CPA firm, producing the report you hand to customers. Nothing else produces that report.

What to do with your score

Below 40% — you are at the scoping and policy stage. Settle categories, boundary and description before building anything.

40–70% — the common shape. Controls exist, evidence does not. Work the “implemented, not evidenced” list first; it is usually the cheapest movement available.

Above 70% — talk to a CPA firm about an observation period. Close the remaining gaps before it starts, not during it.

Frequently asked questions

Is this assessment really free?

Yes. Every criterion, your section breakdown and your overall score cost nothing. The $39 full report is optional and buys the per-criterion detail and the document mapping.

Do I need to finish it in one go?

No. Answers save as you go and you can return to where you stopped.

Which version of the criteria does it use?

The 2017 Trust Services Criteria with the 2022 revised points of focus, which is the current version. No criteria were added, removed or renumbered in 2022 — the changes were to the points of focus underneath them, mostly in the common criteria.

Is a high score the same as being SOC 2 compliant?

No, and be wary of anyone who says otherwise. There is no such thing as being “SOC 2 certified”. SOC 2 is an attestation: a licensed CPA firm examines your controls and issues a report. This assessment tells you how ready you are for that examination.

Can I use this for a client?

Yes. Consultants and vCISOs use it as a first-meeting structure. Run one assessment per client organisation.

Does it cover the privacy criteria?

All 18 of them, if you select Privacy as an in-scope category. If you do not, they are left out of your score entirely rather than counted as gaps.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.