How ready are you for SOC 2?
A 20-question readiness assessment mapped to the SOC 2 Trust Services Criteria. Get an instant score, a category-by-category breakdown, and the top gaps to close before your Type 1 audit — no signup, nothing leaves your browser.
How ready are you for SOC 2?
Answer 19 yes/no questions mapped to the SOC 2 Trust Services Criteria. Get an instant readiness score, a category-by-category breakdown, and the gaps to close before your audit. Nothing leaves your browser.
- Governance & policies
- Risk assessment
- Access control
- Change management
- Monitoring & incident response
- Vendor management
- Data & resilience
~3 minutes. 19 questions across 7 categories.
100% client-side. Your answers never leave your browser.
Seven control areas, mapped to the Common Criteria.
Every question in the assessment is tagged with the specific SOC 2 Trust Services Criteria it covers, so you know exactly what each answer means.
Governance & policies
Leadership-approved security policy, a named security owner, and annual training records.
Risk assessment
A documented annual risk assessment and a living risk register reviewed quarterly.
Access control
SSO / MFA everywhere, quarterly access reviews, fast offboarding, least-privilege on production.
Change management
Peer-reviewed production changes with audit trails that tie PRs to deployments.
Monitoring & incident response
Centralised logs, alerting on auth events, and a tested incident response plan.
Vendor management
A customer-visible sub-processor list and annual collection of vendor SOC 2 / ISO reports.
Data & resilience
Encryption in transit and at rest, tested backups, and a documented data classification scheme.
What the number means.
Your control posture lines up with what auditors expect. Schedule your Type 1 audit within 90 days.
Foundations are in place but material gaps exist. Three to six months of focused work is a realistic timeline to Type 1.
Significant gaps in access control, logging, or risk assessment. Start there — they unblock the most other controls.
Frequently asked questions.
Is this an official SOC 2 audit?+
No — a readiness assessment is a self-serve gap analysis, not an audit. The output tells you which Trust Services Criteria you already meet and where the gaps are. Only a licensed CPA firm can issue an actual SOC 2 report.
Is my data stored?+
No. Every question, answer, and the resulting score is computed in your browser. Nothing is sent to a server, nothing is logged, and nothing leaves your device.
Which SOC 2 criteria does this cover?+
The 20 questions map to the Common Criteria (CC1-CC9) plus selected points from the Availability and Confidentiality categories — the controls a SaaS company needs for a Type 1 audit. They are not a substitute for a full readiness review by an auditor.
How does this relate to AppCheck?+
AppCheck is a semi-manual security audit that produces evidence auditors accept across the same control areas — TLS configuration, security headers, access control on admin endpoints, exposed services, and more. It issues a 0-100 score and a shareable certificate, and is a common companion to SOC 2 because it produces the technical evidence your auditor will sample.
How long does a real SOC 2 audit take?+
For a typical Series A SaaS, the readiness period is 3 to 6 months, followed by a 4 to 8 week audit window. The total time from this assessment to a clean Type 1 report is usually 4 to 9 months.
Now produce the evidence.
A readiness score shows where you stand. Auditors want evidence — the screenshots, scan outputs, and policy diffs that prove the controls are real. AppCheck is a flat €500 semi-manual audit that produces auditor-ready evidence across TLS, access control, monitoring, and the rest of the criteria you just assessed.