SOC 2 gap analysis: pay to close gaps, not to find them
A gap list is worth having and rarely worth buying. Here is what a good one holds and how to get it without a fee.
A SOC 2 gap analysis is a list. Each line names a place where your controls fall short of the Trust Services Criteria and what it takes to close it. It carries no opinion, nobody signs it, and no buyer will take it in place of a report. It still matters, because it turns a vague project into a finite one.
Pay to close gaps, not to find them. Finding them is mapping your answers onto published criteria. Closing them is the real work, and it is where your money should go.
What a useful gap list contains
A gap list is only as good as its lines, and a control name next to a red dot tells you nothing you can act on. Each finding on a list worth having answers five questions.
- Which criterion? The objective in the Trust Services Criteria the gap sits under,1 so you can read what is actually required.
- What is missing? Stated about your company and your systems, not in the general terms a checklist uses.
- Design gap or evidence gap? Either the control does not exist, or it runs and nothing proves it. These are very different amounts of work.
- What closes it? A setting, a document, a new process, or an infrastructure change.
- Who has to act? You, an engineer, or an outside party such as a vendor or a penetration tester.
The third question drives the plan. A design gap has to be built before anything can be evidenced, while an evidence gap only needs a record of something you already do. Mixing them in one flat list is how a three week project looks like a three month one.
Gap analysis next to the three things it gets confused with
Four activities get sold under overlapping names. Only one of them is independent, and that is the one your customer asked for. The column to read is the last one.
| Activity | Run by | Output | Will a buyer accept it? |
|---|---|---|---|
| Self assessment | You, with a checklist | Your view of your own controls, often a spreadsheet | No |
| Readiness assessment | You with software, or a consultant | A score plus the gap list. The exercise that produces the analysis | No |
| Gap analysis | Software, a consultant, or a firm before fieldwork | The findings themselves, each tied to a criterion | No |
| SOC 2 examination | A licensed U.S. CPA firm, only | A report containing the auditor’s opinion | Yes |
The middle two rows describe one piece of work from two angles. If a quote lists a readiness assessment and a gap analysis as separate fees, ask what the second one adds. Then ask for it in writing.
What a firm charges for it
When a consultant or audit firm runs the exercise, it is billed as an engagement. These published figures describe that preparation, not the examination, and were read on the dates shown.
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
The audit is a separate fee on top. One vendor that quotes it puts it here:
- Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.
Our version is free, and the reason is mechanical. Findings come from mapping your answers onto the criteria and reporting what is left uncovered. That is deterministic work that costs us almost nothing to run, so we see no reason to bill you for it. The readiness assessment is where the list comes from.
Where first gaps tend to sit
The criteria are objectives, not a control list, which makes a first analysis feel endless. It helps to know where a request list opens. Security is in scope for every engagement,2 and these are the areas it reaches for first. Start here.
- Access
- Multi-factor authentication on the cloud console, role based production access, and a periodic review with a signature on it.
- Offboarding
- How long access outlives a departure, shown against real people who left rather than asserted in a policy. A day holds up. A week does not.
- Change management
- Review and approval before production, with the trail kept in the tooling.
- Encryption and logging
- Data encrypted at rest and in transit, logs collected centrally and kept long enough to cover the period, alerts that reach a person.
- Vendors
- An inventory, a review of each one, and a decision on which are carved out of your report.3
- Governance and incidents
- Named owners, policies approved within the last year, and an incident plan that has been exercised at least once.
Two gaps are not technical at all. Does the evidence cover the whole period? Does the policy describe what the system actually does? A control that runs but cannot be shown to have run fails the same way as a missing one. What an exception does to a report explains how that gets written up.
From list to plan
An unordered list is a worry, and an ordered one is a schedule you can put dates against. Work it in this order, because each step unblocks the next and the costly mistakes come from doing them out of sequence.
- Build the missing controls. A control that does not exist cannot be evidenced, and a Type 2 window cannot start without it.
- Collect the evidence. The evidence checklist names each artifact, and the PBC list shows how the auditor’s request arrives.
- Pick the date. How long SOC 2 takes covers what remains once the gaps are closed.
Working the list yourself
A spreadsheet works for the first pass. It is free. It gets harder once things change, since a sheet is right on the day you fill it in. Software keeps the list live and holds the fixes in one place. Ours is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. When you need the report,Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. The pricing page has the detail.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
The examination is performed by an independent partner auditor, a licensed U.S. CPA firm. A company never signs its own report.
Get the list for free
You can have your own gap list today without a proposal or a kickoff call. Take the free assessment, answer the intake, and the findings render when you finish. It takes about 15 minutes. Spend your money on closing what it finds.
Questions
Is a gap analysis the same as a readiness assessment?
Who is allowed to perform a SOC 2 gap analysis?
Can I send a gap analysis to a customer instead of a report?
How much does a gap analysis cost?
How long does a gap analysis take?
Is a spreadsheet good enough for a first gap analysis?
Should every gap be closed before the audit starts?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.