A SOC 2 gap assessment answers the question your auditor will not answer for free: how much of the report can you already evidence? Not what the Trust Services Criteria say, not what a vendor’s checklist thinks you need — where you actually stand against all 61 criteria, before you commit to an observation period.
This assessment scopes the report first, then scores every criterion: all 33 common criteria, plus availability, confidentiality, processing integrity and privacy if you take them. It is free, it saves as you go, and you can stop and come back to it.
What is a SOC 2 gap assessment?
A gap assessment compares what your organisation does today against the AICPA Trust Services Criteria, and records the distance. It is the step before you engage a CPA firm, and the step that decides whether your first audit produces a clean report or a list of exceptions.
The usual surprise is not a missing control. It is that scope was never decided — nobody wrote down which trust services categories the report covers, the system boundary was assumed rather than drawn, or the subservice organisations were carved out without anyone reading their reports. Those are scoping failures, and they cost more to fix once the observation period has started.
What this assessment covers
69 assessable items: 8 scoping decisions, then every criterion in the 2017 Trust Services Criteria with the 2022 revised points of focus.
| Domain | Items | What it asks about |
|---|---|---|
| Scope and report readiness | 8 | Categories, report type, system boundary and description, control mapping, subservice organisations, complementary user entity controls |
| CC1 Control environment | 5 | Code of conduct, board oversight, structures, competence, accountability |
| CC2 Communication and information | 3 | Asset inventory and classification, internal and external communication |
| CC3 Risk assessment | 4 | Objectives, risk identification, fraud, change |
| CC4 Monitoring activities | 2 | Ongoing and separate evaluations, deficiency reporting |
| CC5 Control activities | 3 | Control selection, technology general controls, policies |
| CC6 Logical and physical access | 8 | Identity, authorisation, removal, physical access, disposal, boundaries, transmission, malicious software |
| CC7 System operations | 5 | Vulnerability detection, monitoring, event evaluation, incident response, recovery |
| CC8 Change management | 1 | Authorisation, testing and approval of change |
| CC9 Risk mitigation | 2 | Business disruption, vendor and business partner risk |
| Availability | 3 | Capacity, backup and recovery infrastructure, recovery testing |
| Confidentiality | 2 | Identifying confidential information, disposing of it |
| Processing integrity | 5 | Specifications, inputs, processing, outputs, storage |
| Privacy | 18 | Notice, choice and consent, collection, use and retention, access, disclosure, quality, monitoring |
Choose your categories before you score anything
Security is mandatory. The other four are not, and every one you add is more control work, a longer audit and a larger bill. Most buyers ask for Security alone, or Security plus Availability. Confidentiality is common in enterprise software; Processing Integrity matters if you compute something your customer relies on; Privacy is the heaviest of the four and is usually driven by a specific contract.
The assessment asks you to decide this first, then only scores the categories you selected. If you are not sure, score the common criteria and leave the rest — you can come back.
Type 1 or Type 2
A Type 1 report says your controls were suitably designed at a point in time. A Type 2 says they operated effectively across a period, usually three to twelve months. A Type 1 buys you a few months of credibility with a buyer who is waiting; a Type 2 is what most enterprise procurement teams eventually insist on.
The expensive mistake is deciding late. If you start the observation period before the controls are actually running, the exceptions are already in the report by the time anyone notices.
How the scoring works
Each item is scored on the same six-point scale, weighted so that evidence counts for more than intention:
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records an auditor can sample |
| Not applicable | — | A justified exclusion, removed from the score |
The gap between “implemented” and “evidenced” is the one that matters for SOC 2. A Type 2 audit samples records across the period. A control that works but leaves no trace produces an exception exactly as surely as a control that does not work.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and adds the detail you need to actually run the remediation: every criterion with your status and notes, the score broken down by domain, a prioritised gap list, and the specific Governance Docs documents that close each gap. It comes as both a PDF and a working Excel file.
How long does it take?
About 35 minutes if you know your environment, longer if you have to check things — and you should check things. Answers save as you go, so treating it as three sittings across a week is normal and produces a more honest score than one optimistic pass.
Gap assessment, readiness assessment, audit
Three different things, often confused:
- Gap assessment — you, scoring yourself against the criteria. Free, fast, and the right place to start.
- Readiness assessment — a CPA firm or consultant doing the same work with an outside eye, usually a few weeks and four figures. Worth it once your own score is high enough that the findings will be about nuance rather than absence.
- SOC 2 examination — the audit itself, performed by a licensed CPA firm, producing the report you hand to customers. Nothing else produces that report.
What to do with your score
Below 40% — you are at the scoping and policy stage. Settle categories, boundary and description before building anything.
40–70% — the common shape. Controls exist, evidence does not. Work the “implemented, not evidenced” list first; it is usually the cheapest movement available.
Above 70% — talk to a CPA firm about an observation period. Close the remaining gaps before it starts, not during it.
Frequently asked questions
Is this assessment really free?
Yes. Every criterion, your section breakdown and your overall score cost nothing. The $39 full report is optional and buys the per-criterion detail and the document mapping.
Do I need to finish it in one go?
No. Answers save as you go and you can return to where you stopped.
Which version of the criteria does it use?
The 2017 Trust Services Criteria with the 2022 revised points of focus, which is the current version. No criteria were added, removed or renumbered in 2022 — the changes were to the points of focus underneath them, mostly in the common criteria.
Is a high score the same as being SOC 2 compliant?
No, and be wary of anyone who says otherwise. There is no such thing as being “SOC 2 certified”. SOC 2 is an attestation: a licensed CPA firm examines your controls and issues a report. This assessment tells you how ready you are for that examination.
Can I use this for a client?
Yes. Consultants and vCISOs use it as a first-meeting structure. Run one assessment per client organisation.
Does it cover the privacy criteria?
All 18 of them, if you select Privacy as an in-scope category. If you do not, they are left out of your score entirely rather than counted as gaps.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.