SOC 2 readiness assessment
20 questions about the controls a SOC 2 auditor tests first, grouped by area. Answer yes, partly or no, and get a score out of 100, your gaps in priority order, what to do about each one, and a free policy template for every gap. About three minutes, no signup, nothing leaves your browser.
How the questions were chosen
Every question maps to one or more Trust Services Criteria (shown next to each gap) and covers a control that leaves evidence an auditor can sample: approvals, reviews, tickets, logs, test records. Questions that only check whether a document exists are left out on purpose; a policy with no evidence behind it is the most common reason a control fails testing. For the full picture of what each criterion asks, see the SOC 2 controls list, and for the order to write the documents in, the 22 policies a startup needs.
Frequently asked questions
- Is this an official SOC 2 readiness assessment?
- No. It is a self-assessment built on the Trust Services Criteria: each question maps to the criteria it evidences and to the policy that addresses it. A CPA firm or a readiness consultant looks at evidence, not answers. Use this to find your gaps and decide what to fix first.
- What does the score mean?
- Each question scores 1 for yes, 0.5 for partly and 0 for no, and the total is shown out of 100. It measures how many common SOC 2 controls you say are in place and evidenced. It does not predict an audit opinion, and a high score with no written policies still leaves the first document request unanswered.
- Are my answers stored or sent anywhere?
- No. The check runs in your browser. Your answers are kept in the page address after the # sign so you can bookmark or come back, and browsers do not send that part to servers. The share link carries only your score.
- What should I fix first?
- The gap list puts every missing control before every partial one. In practice most teams start with the policies, a risk assessment and multi-factor authentication everywhere, because many other controls reference those.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.