SOC 2 gap analysis: pay to close gaps, not to find them

A gap list is worth having and rarely worth buying. Here is what a good one holds and how to get it without a fee.

A SOC 2 gap analysis is a list. Each line names a place where your controls fall short of the Trust Services Criteria and what it takes to close it. It carries no opinion, nobody signs it, and no buyer will take it in place of a report. It still matters, because it turns a vague project into a finite one.

Pay to close gaps, not to find them. Finding them is mapping your answers onto published criteria. Closing them is the real work, and it is where your money should go.

What a useful gap list contains

A gap list is only as good as its lines, and a control name next to a red dot tells you nothing you can act on. Each finding on a list worth having answers five questions.

  1. Which criterion? The objective in the Trust Services Criteria the gap sits under,1 so you can read what is actually required.
  2. What is missing? Stated about your company and your systems, not in the general terms a checklist uses.
  3. Design gap or evidence gap? Either the control does not exist, or it runs and nothing proves it. These are very different amounts of work.
  4. What closes it? A setting, a document, a new process, or an infrastructure change.
  5. Who has to act? You, an engineer, or an outside party such as a vendor or a penetration tester.

The third question drives the plan. A design gap has to be built before anything can be evidenced, while an evidence gap only needs a record of something you already do. Mixing them in one flat list is how a three week project looks like a three month one.

Gap analysis next to the three things it gets confused with

Four activities get sold under overlapping names. Only one of them is independent, and that is the one your customer asked for. The column to read is the last one.

ActivityRun byOutputWill a buyer accept it?
Self assessmentYou, with a checklistYour view of your own controls, often a spreadsheetNo
Readiness assessmentYou with software, or a consultantA score plus the gap list. The exercise that produces the analysisNo
Gap analysisSoftware, a consultant, or a firm before fieldworkThe findings themselves, each tied to a criterionNo
SOC 2 examinationA licensed U.S. CPA firm, onlyA report containing the auditor’s opinionYes

The middle two rows describe one piece of work from two angles. If a quote lists a readiness assessment and a gap analysis as separate fees, ask what the second one adds. Then ask for it in writing.

What a firm charges for it

When a consultant or audit firm runs the exercise, it is billed as an engagement. These published figures describe that preparation, not the examination, and were read on the dates shown.

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

The audit is a separate fee on top. One vendor that quotes it puts it here:

  • Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.

Our version is free, and the reason is mechanical. Findings come from mapping your answers onto the criteria and reporting what is left uncovered. That is deterministic work that costs us almost nothing to run, so we see no reason to bill you for it. The readiness assessment is where the list comes from.

Where first gaps tend to sit

The criteria are objectives, not a control list, which makes a first analysis feel endless. It helps to know where a request list opens. Security is in scope for every engagement,2 and these are the areas it reaches for first. Start here.

Access
Multi-factor authentication on the cloud console, role based production access, and a periodic review with a signature on it.
Offboarding
How long access outlives a departure, shown against real people who left rather than asserted in a policy. A day holds up. A week does not.
Change management
Review and approval before production, with the trail kept in the tooling.
Encryption and logging
Data encrypted at rest and in transit, logs collected centrally and kept long enough to cover the period, alerts that reach a person.
Vendors
An inventory, a review of each one, and a decision on which are carved out of your report.3
Governance and incidents
Named owners, policies approved within the last year, and an incident plan that has been exercised at least once.

Two gaps are not technical at all. Does the evidence cover the whole period? Does the policy describe what the system actually does? A control that runs but cannot be shown to have run fails the same way as a missing one. What an exception does to a report explains how that gets written up.

From list to plan

An unordered list is a worry, and an ordered one is a schedule you can put dates against. Work it in this order, because each step unblocks the next and the costly mistakes come from doing them out of sequence.

  1. Build the missing controls. A control that does not exist cannot be evidenced, and a Type 2 window cannot start without it.
  2. Collect the evidence. The evidence checklist names each artifact, and the PBC list shows how the auditor’s request arrives.
  3. Pick the date. How long SOC 2 takes covers what remains once the gaps are closed.

Working the list yourself

A spreadsheet works for the first pass. It is free. It gets harder once things change, since a sheet is right on the day you fill it in. Software keeps the list live and holds the fixes in one place. Ours is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. When you need the report,Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. The pricing page has the detail.

What stays with the auditor

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

The examination is performed by an independent partner auditor, a licensed U.S. CPA firm. A company never signs its own report.

Get the list for free

You can have your own gap list today without a proposal or a kickoff call. Take the free assessment, answer the intake, and the findings render when you finish. It takes about 15 minutes. Spend your money on closing what it finds.

Questions

Is a gap analysis the same as a readiness assessment?
Close enough that you should never pay for both. The assessment is the exercise and the gap analysis is the list it produces. Some firms invoice them as two items, which is paying twice for one piece of work.
Who is allowed to perform a SOC 2 gap analysis?
Anyone. It carries no opinion and needs no independence, so you can run it yourself. Only the examination has to come from a licensed CPA firm. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Can I send a gap analysis to a customer instead of a report?
No. It is your own view of your own controls. A buyer wants a report signed by an independent licensed CPA firm, and nothing you write about yourself stands in for that.
How much does a gap analysis cost?
Firms that sell it as an engagement publish figures in the five figures. Run through our readiness assessment, it costs nothing.
How long does a gap analysis take?
A firm engagement can run from a few weeks to a few months because of interviews and document review. The self serve version takes about 15 minutes and returns the list when you finish.
Is a spreadsheet good enough for a first gap analysis?
It is a fair start. It gets hard in two places: grading yourself against criteria you have not read closely, and keeping the sheet current once things change.
Should every gap be closed before the audit starts?
Every missing control, yes. A missing piece of evidence for a control that really runs can sometimes be handled during fieldwork. A known design gap only buys you a finding you already knew about.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.