Answer eight questions about how your program actually runs today and see where you stand against the SOC 2 Security common criteria — with your largest gaps named, not just a number.
Runs entirely in your browser — nothing you enter is stored or sent anywhere. No account required.
This is a self-assessment, not an audit. A SOC 2 report is an attestation issued by a licensed CPA firm; use this to find the work worth doing before you engage one.
Answer all eight questions to see your readiness — 8 remaining. The score, stage, biggest gaps, and a next step appear here instantly.
How the score is calculated
Eight control areas mapped to the SOC 2 Security common criteria, each weighted — policies & governance 15%, risk assessment 10%, access control 20%, change management 10%, monitoring & logging 15%, incident response 10%, vendor & third-party risk 10%, evidence readiness 10%. Your answer sets how fully each area is in place; the weighted sum is the 0-100 readiness score, mapped to 0-24 Not started, 25-49 Foundational, 50-74 Approaching, and 75-100 Audit-ready. Access control carries the most weight because it is the most heavily sampled area in a Security engagement. Model version public-soc2-readiness-1.0.
Scope note: this covers the Security criteria, which every SOC 2 engagement includes. The optional categories — Availability, Confidentiality, Processing Integrity and Privacy — are selected per engagement, so they are deliberately left out rather than folded into a number you would read as "my SOC 2".
Readiness Is Earned Over a Window, Not a Weekend.
A Type II report observes your controls over months. The platform keeps the evidence — access reviews, vendor assessments, and attestations — collected as the controls run, so the window is a record rather than a scramble.