What a SOC 2 readiness assessment covers, and what it costs

Firms sell this as a paid engagement. Try five real questions below, then see what the full version checks and returns.

A SOC 2 readiness assessment is a practice run. It compares what your company does today against the criteria an auditor will use, and it lists the gaps before anyone is paid to find them. Nothing about it is official. That is exactly why it costs little to get wrong here and expensive to get wrong later. Here are five questions from the real intake.

  1. Access control. MFA required for cloud console access?
  2. Offboarding. User access removed within 24 hours of termination?
  3. Data protection. Encryption at rest for databases and backups?
  4. Monitoring. Centralized log collection for app and infrastructure?
  5. Governance. Has management formally approved the security and compliance program in the last 12 months?

Answer all five and a direction appears here. Nothing is sent anywhere, and there is no email box on this page.

Those five were not written for this page. They come straight from the full intake, and they cover controls an auditor tends to ask about early. A No on any of them is useful information today. The same No in the middle of fieldwork is a finding with an invoice attached.

What firms charge for this engagement

Readiness is sold as a service. Consultants and audit firms scope it, interview your team, review documents and hand back a written report. The people who sell it publish what it costs. Both of these were opened and read on the date shown.

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

That fee buys the preparation only. The examination is a separate engagement with its own bill. For a company of ten people, paying for a gap list before closing a single gap is a hard way to start.

We give the assessment away. The reason is simple: it is how we learn whether we can take your company to an audit at our price, and charging you to qualify us would be backwards. The full version is free, takes about 15 minutes, and asks for no card.

What the assessment covers

The Trust Services Criteria are written as objectives rather than as a checklist of controls.1 An assessment turns those objectives into plain questions about how you work. The full intake groups them into these areas.

Access
Multi-factor authentication, single sign-on where it exists, who can reach production, and whether reviews of that access leave a record.
Change management
How code reaches production, who approves it, and where the trail lives.
Vendors
The services that touch customer data, whether each one was reviewed, and which ones your report will carve out.
Encryption and data
At rest and in transit, plus a classification that says what the controls are protecting.
Logging and monitoring
Central collection, retention long enough to cover an examination period, and alerts that reach a person.
Incident response
A written plan, named owners, and some proof the plan has been used.
People and governance
Screening, training, offboarding, approved policies, and a named owner for the whole program.

Security is the category every SOC 2 report contains,2 so it is what the assessment scores. If a contract asks for another category, that is a scoping decision for later.

What you get back

The result renders the moment you finish. No sales call stands between you and it. It shows your readiness score, every gap category counted with exact numbers, and your first findings written out in full.

  • A score out of 100 and a tier. Weighted by severity, with the number of controls scored and the number passing beside it.
  • Every gap category, counted. Worst first, each split into what has to be fixed and what only has to be evidenced.
  • Findings written in full. Two or three of them, in prose about your own answers.
  • The exact size of the rest. How many more findings remain, and across which categories.

There is no PDF. The result lives in your account and recomputes when your answers change, so it stays current instead of going stale in a folder.

Reading your score

Each answer maps to one or more criteria. An answer that leaves a criterion uncovered creates a gap, and each gap is weighted by how central its control is. The score is the weighted share of scored controls that pass. The zones compare you with the standard, not with other companies.

ScoreWhere you standWhat to spend time on
85 to 100Most controls existCollecting evidence and writing down what you already do. A date is realistic
60 to 84Real gaps remainConfiguration and policy work, in the order the gap list gives
Under 60Early controls are missingFoundations first. An audit booked now buys a costly copy of the same list

The score reflects your answers

The same answers always give the same number, because no model is judging you. Nothing is verified at this stage either. Round an answer up and the score rises while the real problem moves to the audit, where it costs more to fix. Answer the way your week actually runs.

After the assessment

Under your score there is an optional call. We walk through every finding, including the ones the free screen summarizes, and say what closing each one takes. It is also a sales conversation, and we will tell you on it if we are the wrong fit. If you already know what you want, there is a checkout link below the calendar.

The paid side is where the remediation work, thirteen policies drafted from your answers, the evidence binder and the report package live. The software is $199 a month, cancel any time, or $2,189 a year. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. The pricing page lays out every plan.

The part no software can do

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

The examination runs under the AICPA attestation standards,3 no matter who assembled the package. Yours is performed by an independent partner auditor, a licensed U.S. CPA firm.

Where to go from here

If you want the difference between this and a gap analysis, the gap analysis page lines up all four options. For the artifacts an auditor requests, see the evidence checklist. For dates, how long SOC 2 takes ties each phase to its cost. The free assessment page explains exactly what the free tier includes: readiness assessment, score, gap list and one AI sample policy.

Or just start. Take the free assessment. Free. No payment and no card. In about 15 minutes you will have your number.

Questions

What does a SOC 2 readiness assessment check?
How your current controls line up against the Trust Services Criteria. That means access, change management, vendors, encryption, logging, incident response, people and governance. Each gap it finds is tied to the criterion it falls under.
Do I have to hire a CPA firm for a readiness assessment?
No. The standard only requires a licensed CPA firm for the examination itself. Anyone can assess readiness, including you. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
What does a readiness assessment cost?
Firms that sell it as an engagement publish figures in the five figures. Ours costs nothing. There is no card and no payment screen in front of the result.
Is a readiness assessment required before an audit?
No. The attestation standards do not ask for one. It is preparation. Its value is finding what an auditor would write down while the fix is still quick.
What score counts as ready?
There is no industry scale. In our scoring, 85 or higher means the remaining work is mostly evidence, 60 to 84 means real control gaps are open, and under 60 means several controls an auditor checks early are missing.
Does the free assessment come with a PDF?
No. The result stays in your account and updates when your answers change. A file would be out of date within a week.
Is the assessment different for Type 1 and Type 2?
No. Both reports examine the same controls. Type 1 looks at design on one date and Type 2 looks at operation over a period, so the readiness work is the same.
Can I prepare for SOC 2 on my own?
Yes, all of the preparation. The examination is the one part you cannot do yourself, because the report is signed by an independent licensed CPA firm.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.