San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active
WHY THIS MATTERS

Know your SOC 2 standing before you pay for the audit.

A buyer asked for SOC 2 and you need to know where you actually stand. SOC 2 is an attestation signed by a licensed CPA firm, so there is no self-attested version, but the readiness work is the part you can do for free. This tool grades you against the Security Trust Services Criteria, all 33 Common Criteria controls across CC1 to CC9, so you can close gaps first and hand your auditor a clean package. No signup, nothing stored.

THE SELF-ASSESSMENT

Grade all 33 Security controls

Mark each control Met, Partial, or Gap. Your readiness score updates live. Met counts full, Partial counts half.

0% ready
START THE ASSESSMENT
Met
0
Partial
0
Gap
33
Mark each control Met, Partial, or Gap. Readiness weights Met as full and Partial as half. Tags show where your NIST 800-171 / CMMC work likely already covers you.

SOC 2 is an attestation report signed by a licensed CPA firm — there is no self-attested version. This tool grades you against the Security Trust Services Criteria (the Common Criteria, CC1–CC9) so you can close gaps before you commission the audit. If you already hold a NIST 800-171 or CMMC posture, the green and amber tags show how much of SOC 2 you have effectively already built. This is an unofficial readiness aid, not an assessment of record.

Email me my SOC 2 readiness summary + a gap-closure roadmap

We'll send a copy and, if you want, help you take the next step. No spam.

WHAT SOC 2 SECURITY COVERS

The nine Common Criteria, in plain English

SOC 2’s Security criterion is built from nine control families (CC1–CC9), drawn from the COSO framework. Here is what each one asks of a small firm.

CC1

Control Environment

Governance and ethics. A code of conduct, one accountable owner for security, and defined roles, even on a small team.

CC2

Communication & Information

Security duties are communicated to staff, and customers and vendors know their obligations, with a channel to report an issue.

CC3

Risk Assessment

A documented assessment that names your risks, weighs likelihood and impact, and considers fraud, not just outside threats.

CC4

Monitoring Activities

You periodically check that controls are actually working, and deficiencies are tracked to closure.

CC5

Control Activities

Controls are selected to meet the risks you found, backed by written policies people follow, and supported by technical controls.

CC6

Logical & Physical Access

The largest family. Identity and least privilege, provisioning and access reviews, physical access, secure disposal, encryption, and MFA.

CC7

System Operations

You detect and respond to what goes wrong: vulnerability scanning, monitoring, incident response, and recovery.

CC8

Change Management

Changes to systems are authorized, tested, reviewed, and approved before they ship. Often the main gap for a small shop.

CC9

Risk Mitigation

Business-disruption risk is mitigated through continuity and insurance, and vendors are assessed for the risk they introduce.

HOW TO READ YOUR SCORE

Readiness, not a report

The score is a readiness signal, not a SOC 2 opinion. Here is the honest read.

90%+

Audit-ready

With evidence behind each Met, “SOC 2 readiness complete, Type I in progress” is a claim you can defend to a buyer, and your CPA fee drops because the package is clean.

CC6 FIRST

Start where you are strong

The eight CC6 access controls carry the most 800-171 overlap. If you hold a CMMC posture, this is where your score climbs fastest.

PARTIAL

Partial means undocumented

A control you do informally but cannot show is Partial, not Met. SOC 2 is about evidence over time. If you cannot point to the proof, treat it as a gap.

COMMON QUESTIONS

SOC 2, answered

Can I self-assess or self-certify SOC 2?
You can self-assess your readiness, but you cannot self-certify SOC 2. A SOC 2 report is an attestation issued by a licensed CPA firm under AICPA standards. What you do yourself is grade your controls against the same Trust Services Criteria the auditor uses, close the gaps, and gather evidence, so the paid audit is shorter and cheaper. That readiness work is exactly what this tool covers.
How many controls are in SOC 2 Security?
The Security criterion, also called the Common Criteria, is organized into nine families, CC1 through CC9, drawn from the COSO framework. This tool breaks them into 33 practical control points a small firm can grade itself against. Security is the baseline criterion that every SOC 2 report includes.
What is the difference between SOC 2 Type I and Type II?
Type I attests that your controls are designed appropriately at a single point in time. Type II attests that they operated effectively over a period, usually three to twelve months. Buyers generally want Type II, but a Type I plus an in-progress Type II observation window is a common and credible interim position.
If I already have NIST 800-171 or CMMC, how much SOC 2 is done?
A large share. SOC 2 Security and NIST 800-171 overlap heavily, especially across access control, identification and authentication, audit, incident response, and system integrity. Your biggest SOC 2-only additions tend to be governance and communication (CC1, CC2) and formal change management (CC8). Each control in the tool is tagged where the overlap is.
Does this tool store my answers or submit anything?
No. It runs entirely in your browser, stores nothing, and submits nothing. You can print or save your result. If you want a written summary and a gap-closure roadmap emailed to you, that is an optional step you choose.
FROM GAPS TO READY

Turn your gaps into a SOC 2 readiness plan

We map each open control to a concrete fix and the evidence your auditor will ask for, and where you already hold a NIST 800-171 or CMMC posture, we reuse it. Readiness preparation by a SAM-active firm that holds the line on its own systems.