Know your SOC 2 standing before you pay for the audit.
A buyer asked for SOC 2 and you need to know where you actually stand. SOC 2 is an attestation signed by a licensed CPA firm, so there is no self-attested version, but the readiness work is the part you can do for free. This tool grades you against the Security Trust Services Criteria, all 33 Common Criteria controls across CC1 to CC9, so you can close gaps first and hand your auditor a clean package. No signup, nothing stored.
Grade all 33 Security controls
Mark each control Met, Partial, or Gap. Your readiness score updates live. Met counts full, Partial counts half.
SOC 2 is an attestation report signed by a licensed CPA firm — there is no self-attested version. This tool grades you against the Security Trust Services Criteria (the Common Criteria, CC1–CC9) so you can close gaps before you commission the audit. If you already hold a NIST 800-171 or CMMC posture, the green and amber tags show how much of SOC 2 you have effectively already built. This is an unofficial readiness aid, not an assessment of record.
Email me my SOC 2 readiness summary + a gap-closure roadmap
We'll send a copy and, if you want, help you take the next step. No spam.
The nine Common Criteria, in plain English
SOC 2’s Security criterion is built from nine control families (CC1–CC9), drawn from the COSO framework. Here is what each one asks of a small firm.
Control Environment
Governance and ethics. A code of conduct, one accountable owner for security, and defined roles, even on a small team.
Communication & Information
Security duties are communicated to staff, and customers and vendors know their obligations, with a channel to report an issue.
Risk Assessment
A documented assessment that names your risks, weighs likelihood and impact, and considers fraud, not just outside threats.
Monitoring Activities
You periodically check that controls are actually working, and deficiencies are tracked to closure.
Control Activities
Controls are selected to meet the risks you found, backed by written policies people follow, and supported by technical controls.
Logical & Physical Access
The largest family. Identity and least privilege, provisioning and access reviews, physical access, secure disposal, encryption, and MFA.
System Operations
You detect and respond to what goes wrong: vulnerability scanning, monitoring, incident response, and recovery.
Change Management
Changes to systems are authorized, tested, reviewed, and approved before they ship. Often the main gap for a small shop.
Risk Mitigation
Business-disruption risk is mitigated through continuity and insurance, and vendors are assessed for the risk they introduce.
Readiness, not a report
The score is a readiness signal, not a SOC 2 opinion. Here is the honest read.
Audit-ready
With evidence behind each Met, “SOC 2 readiness complete, Type I in progress” is a claim you can defend to a buyer, and your CPA fee drops because the package is clean.
Start where you are strong
The eight CC6 access controls carry the most 800-171 overlap. If you hold a CMMC posture, this is where your score climbs fastest.
Partial means undocumented
A control you do informally but cannot show is Partial, not Met. SOC 2 is about evidence over time. If you cannot point to the proof, treat it as a gap.