Free tool

How ready are you for SOC 2?

A 20-question readiness assessment mapped to the SOC 2 Trust Services Criteria. Get an instant score, a category-by-category breakdown, and the top gaps to close before your Type 1 audit — no signup, nothing leaves your browser.

How ready are you for SOC 2?

Answer 19 yes/no questions mapped to the SOC 2 Trust Services Criteria. Get an instant readiness score, a category-by-category breakdown, and the gaps to close before your audit. Nothing leaves your browser.

  • Governance & policies
  • Risk assessment
  • Access control
  • Change management
  • Monitoring & incident response
  • Vendor management
  • Data & resilience

~3 minutes. 19 questions across 7 categories.

100% client-side. Your answers never leave your browser.

What we assess

Seven control areas, mapped to the Common Criteria.

Every question in the assessment is tagged with the specific SOC 2 Trust Services Criteria it covers, so you know exactly what each answer means.

Governance & policies

Leadership-approved security policy, a named security owner, and annual training records.

Risk assessment

A documented annual risk assessment and a living risk register reviewed quarterly.

Access control

SSO / MFA everywhere, quarterly access reviews, fast offboarding, least-privilege on production.

Change management

Peer-reviewed production changes with audit trails that tie PRs to deployments.

Monitoring & incident response

Centralised logs, alerting on auth events, and a tested incident response plan.

Vendor management

A customer-visible sub-processor list and annual collection of vendor SOC 2 / ISO reports.

Data & resilience

Encryption in transit and at rest, tested backups, and a documented data classification scheme.

Reading your score

What the number means.

Ready · 75-100

Your control posture lines up with what auditors expect. Schedule your Type 1 audit within 90 days.

Partially ready · 50-74

Foundations are in place but material gaps exist. Three to six months of focused work is a realistic timeline to Type 1.

Not ready · 0-49

Significant gaps in access control, logging, or risk assessment. Start there — they unblock the most other controls.

FAQ

Frequently asked questions.

Is this an official SOC 2 audit?+

No — a readiness assessment is a self-serve gap analysis, not an audit. The output tells you which Trust Services Criteria you already meet and where the gaps are. Only a licensed CPA firm can issue an actual SOC 2 report.

Is my data stored?+

No. Every question, answer, and the resulting score is computed in your browser. Nothing is sent to a server, nothing is logged, and nothing leaves your device.

Which SOC 2 criteria does this cover?+

The 20 questions map to the Common Criteria (CC1-CC9) plus selected points from the Availability and Confidentiality categories — the controls a SaaS company needs for a Type 1 audit. They are not a substitute for a full readiness review by an auditor.

How does this relate to AppCheck?+

AppCheck is a semi-manual security audit that produces evidence auditors accept across the same control areas — TLS configuration, security headers, access control on admin endpoints, exposed services, and more. It issues a 0-100 score and a shareable certificate, and is a common companion to SOC 2 because it produces the technical evidence your auditor will sample.

How long does a real SOC 2 audit take?+

For a typical Series A SaaS, the readiness period is 3 to 6 months, followed by a 4 to 8 week audit window. The total time from this assessment to a clean Type 1 report is usually 4 to 9 months.

Now produce the evidence.

A readiness score shows where you stand. Auditors want evidence — the screenshots, scan outputs, and policy diffs that prove the controls are real. AppCheck is a flat €500 semi-manual audit that produces auditor-ready evidence across TLS, access control, monitoring, and the rest of the criteria you just assessed.