What a SOC 2 readiness assessment covers, and what it costs
Firms sell this as a paid engagement. Try five real questions below, then see what the full version checks and returns.
A SOC 2 readiness assessment is a practice run. It compares what your company does today against the criteria an auditor will use, and it lists the gaps before anyone is paid to find them. Nothing about it is official. That is exactly why it costs little to get wrong here and expensive to get wrong later. Here are five questions from the real intake.
- Access control. MFA required for cloud console access?
- Offboarding. User access removed within 24 hours of termination?
- Data protection. Encryption at rest for databases and backups?
- Monitoring. Centralized log collection for app and infrastructure?
- Governance. Has management formally approved the security and compliance program in the last 12 months?
Answer all five and a direction appears here. Nothing is sent anywhere, and there is no email box on this page.
Those five were not written for this page. They come straight from the full intake, and they cover controls an auditor tends to ask about early. A No on any of them is useful information today. The same No in the middle of fieldwork is a finding with an invoice attached.
What firms charge for this engagement
Readiness is sold as a service. Consultants and audit firms scope it, interview your team, review documents and hand back a written report. The people who sell it publish what it costs. Both of these were opened and read on the date shown.
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
That fee buys the preparation only. The examination is a separate engagement with its own bill. For a company of ten people, paying for a gap list before closing a single gap is a hard way to start.
We give the assessment away. The reason is simple: it is how we learn whether we can take your company to an audit at our price, and charging you to qualify us would be backwards. The full version is free, takes about 15 minutes, and asks for no card.
What the assessment covers
The Trust Services Criteria are written as objectives rather than as a checklist of controls.1 An assessment turns those objectives into plain questions about how you work. The full intake groups them into these areas.
- Access
- Multi-factor authentication, single sign-on where it exists, who can reach production, and whether reviews of that access leave a record.
- Change management
- How code reaches production, who approves it, and where the trail lives.
- Vendors
- The services that touch customer data, whether each one was reviewed, and which ones your report will carve out.
- Encryption and data
- At rest and in transit, plus a classification that says what the controls are protecting.
- Logging and monitoring
- Central collection, retention long enough to cover an examination period, and alerts that reach a person.
- Incident response
- A written plan, named owners, and some proof the plan has been used.
- People and governance
- Screening, training, offboarding, approved policies, and a named owner for the whole program.
Security is the category every SOC 2 report contains,2 so it is what the assessment scores. If a contract asks for another category, that is a scoping decision for later.
What you get back
The result renders the moment you finish. No sales call stands between you and it. It shows your readiness score, every gap category counted with exact numbers, and your first findings written out in full.
- A score out of 100 and a tier. Weighted by severity, with the number of controls scored and the number passing beside it.
- Every gap category, counted. Worst first, each split into what has to be fixed and what only has to be evidenced.
- Findings written in full. Two or three of them, in prose about your own answers.
- The exact size of the rest. How many more findings remain, and across which categories.
There is no PDF. The result lives in your account and recomputes when your answers change, so it stays current instead of going stale in a folder.
Reading your score
Each answer maps to one or more criteria. An answer that leaves a criterion uncovered creates a gap, and each gap is weighted by how central its control is. The score is the weighted share of scored controls that pass. The zones compare you with the standard, not with other companies.
| Score | Where you stand | What to spend time on |
|---|---|---|
| 85 to 100 | Most controls exist | Collecting evidence and writing down what you already do. A date is realistic |
| 60 to 84 | Real gaps remain | Configuration and policy work, in the order the gap list gives |
| Under 60 | Early controls are missing | Foundations first. An audit booked now buys a costly copy of the same list |
The score reflects your answers
The same answers always give the same number, because no model is judging you. Nothing is verified at this stage either. Round an answer up and the score rises while the real problem moves to the audit, where it costs more to fix. Answer the way your week actually runs.
After the assessment
Under your score there is an optional call. We walk through every finding, including the ones the free screen summarizes, and say what closing each one takes. It is also a sales conversation, and we will tell you on it if we are the wrong fit. If you already know what you want, there is a checkout link below the calendar.
The paid side is where the remediation work, thirteen policies drafted from your answers, the evidence binder and the report package live. The software is $199 a month, cancel any time, or $2,189 a year. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. The pricing page lays out every plan.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
The examination runs under the AICPA attestation standards,3 no matter who assembled the package. Yours is performed by an independent partner auditor, a licensed U.S. CPA firm.
Where to go from here
If you want the difference between this and a gap analysis, the gap analysis page lines up all four options. For the artifacts an auditor requests, see the evidence checklist. For dates, how long SOC 2 takes ties each phase to its cost. The free assessment page explains exactly what the free tier includes: readiness assessment, score, gap list and one AI sample policy.
Or just start. Take the free assessment. Free. No payment and no card. In about 15 minutes you will have your number.
Questions
What does a SOC 2 readiness assessment check?
Do I have to hire a CPA firm for a readiness assessment?
What does a readiness assessment cost?
Is a readiness assessment required before an audit?
What score counts as ready?
Does the free assessment come with a PDF?
Is the assessment different for Type 1 and Type 2?
Can I prepare for SOC 2 on my own?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.