Free SOC 2 readiness assessment: what it tells you
What a free SOC 2 readiness assessment covers, how to read your score and gap list, what it cannot tell you, and what to do next.
A readiness assessment is the first real step toward SOC 2. It tells you how far you are from a report before you spend money on software, consultants or an audit. Firms charge for this, and some teams assume a free SOC 2 readiness assessment must be a sales form in disguise. This guide explains what a good one covers, how to read the results, what it cannot tell you, and what to do with the answers.
What a readiness assessment is
SOC 2 reports are measured against the AICPA's Trust Services Criteria. A readiness assessment compares how your company works today with those criteria and lists the gaps. It is a planning tool. It is not an audit, and it does not produce a report you can hand to a customer.
When a firm performs it, readiness is a paid engagement. IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months (IS Partners, checked September 1, 2026).
A paid assessment usually includes interviews and a review of your documents. A free one relies on your answers. That difference matters, and we come back to it below.
What our free SOC 2 readiness assessment covers
Our free readiness assessment is a structured questionnaire that takes about fifteen minutes. There is no payment and no card. You get:
- Your readiness score, an overall measure of how close you are.
- Every gap category counted with exact numbers, so you know how much work each area holds.
- Your first findings written out in full, each with what is missing and why it matters.
- One AI sample policy, written from your answers, so you can see what a policy tailored to your setup looks like.
The questions cover the areas an auditor will look at:
| Area | Example questions | |---|---| | Access control | Is MFA enforced? Who can reach production? Are access reviews recorded? | | Change management | Is every code change reviewed? Are production changes tracked? | | People | Do new hires acknowledge policies? Is there a written offboarding step? | | Risk | Is there a risk assessment, and when was it last updated? | | Vendors | Do you know which vendors hold customer data? Do you review them? | | Incident response | Is there a written plan? Has anyone practiced it? | | Operations | Are backups tested? Is logging in place for key systems? | | Governance | Who owns security? Which policies exist, and are they approved? |
How to read your score
Treat the score as a direction, not a verdict.
- A high score usually means you have most controls in place and your work is mostly writing things down and collecting evidence.
- A middle score usually means a handful of real controls are missing, often MFA coverage, access reviews or a vendor process.
- A low score means more building work, which is normal for a team that has never needed a security program before.
The gap counts matter more than the headline number. Ten gaps in policies are an afternoon of writing and approvals. Ten gaps in access control may mean changing how people log in.
What a free assessment cannot tell you
Be clear about the limits.
- It relies on your answers. If you answer optimistically, the gap list will be optimistic. The auditor will check evidence, not answers.
- It is not an audit opinion. Only an independent licensed CPA firm can examine your controls and issue a SOC 2 report.
- It does not replace a scoping decision. You still decide which systems and criteria are in scope.
- It is not something to show a buyer as proof of SOC 2. You can tell a buyer you have completed a readiness assessment and are working on the gaps.
Turning the results into a plan
Once you have your gap list, work through it in this order.
- Fix the free, fast gaps first. MFA, written offboarding steps, a vendor list, backup restore test.
- Decide scope. Security only, unless a customer needs more.
- Write and approve policies that describe what you actually do.
- Collect evidence for each control as you go, mapped to the criteria.
- Pick your report type. Type 1 for design at a date, Type 2 for operation over a period, usually three to twelve months. See the SOC 2 gap analysis guide for how to prioritize.
- Book the audit once evidence is complete.
What happens after the free assessment
Nothing, unless you want it to. The results are yours to keep and use with any tool or consultant.
If you want help closing the gaps, cybersoftware is one plan: $199 a month, cancel any time, or $2,189 a year, which is one month free. It covers SOC 2 Type 1 and Type 2. Audits come with access to our preferred pricing program: the best negotiated audit rates on the market, because we negotiate on your behalf. You see your audit price in the app before you book. The full list is on our pricing page. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Frequently asked questions
Is the free SOC 2 readiness assessment really free?
Yes. No payment, no card, and you keep the score, the gap list and the sample policy.
How long does it take?
About fifteen minutes, if you know how your systems are set up.
Can we share the results with a customer?
You can tell a customer you have completed a readiness assessment and have a plan. It is not a SOC 2 report and should not be presented as one.
How is this different from a paid readiness engagement?
A paid engagement usually includes interviews and document review by a firm. A free assessment relies on your answers, which makes it fast, and makes honest answers important.
Start with a free readiness assessment. It takes about fifteen minutes and needs no card.