SOC 2 readiness assessment

20 questions about the controls a SOC 2 auditor tests first, grouped by area. Answer yes, partly or no, and get a score out of 100, your gaps in priority order, what to do about each one, and a free policy template for every gap. About three minutes, no signup, nothing leaves your browser.

0 of 20 answered

Governance and risk

  1. Do you have written security policies that management approved in the last 12 months?

    Policies are the first section of every SOC 2 document request, and undated policies read as unapproved.

  2. Is one named person accountable for the security program?

    Auditors look for clear ownership and reporting lines before they test anything else.

  3. Have you completed a documented risk assessment, with a scored risk register, in the last 12 months?

    The whole CC3 series is about identifying and responding to risk; the register is the evidence.

  4. Do you check at least yearly that your controls are still working, and track the fixes?

    Monitoring activities (CC4) ask for evidence that someone looks at whether controls operate, not just that they exist.

People

  1. Does everyone acknowledge the security policies and complete security training at hire and every year?

    Signed acknowledgments and training records are the standard evidence that people know what is expected of them.

  2. Do you follow a written onboarding and offboarding checklist, including background checks where lawful?

    Auditors sample new hires and leavers and ask for the checklist and the screening record for each.

Access

  1. Is multi-factor authentication enforced for everyone on your identity provider, cloud console and source control?

    MFA is one of the first things tested under logical access, and an exception list is itself a finding.

  2. Is access granted through single sign-on groups or roles, following least privilege?

    Role-based access makes the population auditors sample small and explainable.

  3. Do you review who has access to production, source code and admin roles at least quarterly, and keep the record?

    Periodic access reviews are among the most commonly sampled controls, and a missed quarter is a visible exception.

  4. When someone leaves, is their access removed within a defined time you can prove?

    A terminated user who stayed active is one of the classic SOC 2 exceptions.

Change and development

  1. Does every production change go through a pull request with an independent review and passing checks?

    Change management (CC8.1) is tested by sampling production changes and looking for approval before deployment.

  2. Are production deployments done only through your CI/CD pipeline, not by hand?

    A pipeline gives a complete, dated record of what was deployed, by whom, from which commit.

Detection and response

  1. Do you scan code, dependencies and infrastructure for vulnerabilities and fix findings within set timelines?

    CC7.1 asks for detection of vulnerabilities; auditors compare fix dates against the timelines your policy sets.

  2. Are security-relevant logs collected centrally, retained, and alerted on?

    Monitoring for anomalies (CC7.2) needs logs you keep and alerts someone actually reviews.

  3. Do you have a written incident response plan that you tested (for example a tabletop) in the last 12 months?

    CC7.3 to CC7.5 cover evaluating, responding to and recovering from incidents; a tested plan is the evidence.

Vendors

  1. Do you keep a vendor inventory and review the SOC 2 reports of vendors that hold customer data?

    CC9.2 asks how you assess and monitor vendor risk; the inventory and the dated reviews are what gets sampled.

Resilience

  1. Are backups automated, and have you restored from one as a test in the last 12 months?

    An untested backup is not evidence of recoverability; auditors ask for the restore test record.

  2. Do you have a business continuity and disaster recovery plan with recovery time and recovery point objectives?

    Availability commitments and CC9.1 expect a plan for disruption, with objectives you can test against.

Devices and data

  1. Are laptops encrypted, screen-locked and kept up to date, and can you prove it (device management or attestation)?

    Endpoints hold credentials and data; auditors ask for evidence across the whole fleet, not a policy statement.

  2. Is customer data classified, encrypted in transit and at rest, and deleted on a defined schedule?

    Confidentiality criteria and CC6.7 cover how data is protected while you hold it and disposed of when you do not need it.

How the questions were chosen

Every question maps to one or more Trust Services Criteria (shown next to each gap) and covers a control that leaves evidence an auditor can sample: approvals, reviews, tickets, logs, test records. Questions that only check whether a document exists are left out on purpose; a policy with no evidence behind it is the most common reason a control fails testing. For the full picture of what each criterion asks, see the SOC 2 controls list, and for the order to write the documents in, the 22 policies a startup needs.

Frequently asked questions

Is this an official SOC 2 readiness assessment?
No. It is a self-assessment built on the Trust Services Criteria: each question maps to the criteria it evidences and to the policy that addresses it. A CPA firm or a readiness consultant looks at evidence, not answers. Use this to find your gaps and decide what to fix first.
What does the score mean?
Each question scores 1 for yes, 0.5 for partly and 0 for no, and the total is shown out of 100. It measures how many common SOC 2 controls you say are in place and evidenced. It does not predict an audit opinion, and a high score with no written policies still leaves the first document request unanswered.
Are my answers stored or sent anywhere?
No. The check runs in your browser. Your answers are kept in the page address after the # sign so you can bookmark or come back, and browsers do not send that part to servers. The share link carries only your score.
What should I fix first?
The gap list puts every missing control before every partial one. In practice most teams start with the policies, a risk assessment and multi-factor authentication everywhere, because many other controls reference those.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.