Overview

The SOC 2 Readiness Assessment provides a structured framework for evaluating your organisation's control environment against the AICPA Common Criteria (CC1–CC9) — the Security category of the Trust Services Criteria. With 119 questions across 9 control domains, this assessment helps service organisations prepare for Type I or Type II SOC 2 examinations.

Through structured evaluation criteria aligned to the Common Criteria (CC series), you will assess your organisation's security governance, logical and physical access controls, system operations, change management, and risk mitigation practices.

The assessment employs a maturity-based scoring model to help you understand your current readiness posture, identify control gaps that could result in examination exceptions, and develop a prioritised remediation roadmap.

Who It's For

This assessment is designed for:

  • SaaS providers preparing for their first SOC 2 examination
  • Service organisations maintaining SOC 2 Type II attestation
  • Technology companies responding to enterprise customer security requirements
  • Security and compliance teams managing SOC 2 programmes
  • Organisations transitioning from SOC 1 to SOC 2
  • Companies evaluating readiness before engaging a CPA firm

Typical Outcomes

Organisations using this assessment typically gain:

  • Clear understanding of readiness for SOC 2 examination
  • Identification of control gaps likely to result in exceptions
  • Prioritised remediation plan for examination readiness
  • Documentation to support internal compliance reporting
  • Evidence of control maturity for customer security questionnaires
  • Structured preparation for CPA firm engagement

Assessment Coverage

The assessment is structured around the nine Common Criteria (CC1–CC9), which make up the Security category within the AICPA's Trust Services Criteria:

  • CC1: Control Environment — Management commitment, ethics, governance structure, personnel competence, and accountability
  • CC2: Communication & Information — Security objectives, policy communication, training, and incident notification
  • CC3: Risk Assessment — Risk identification, assessment methodology, fraud risk, and change-related risks
  • CC4: Monitoring Activities — Ongoing monitoring, logging, alerting, internal audit, and deficiency remediation
  • CC5: Control Activities — Segregation of duties, policy documentation, and exception management
  • CC6: Logical & Physical Access — Access provisioning, RBAC, MFA, termination, encryption, and physical security
  • CC7: System Operations — Vulnerability management, endpoint protection, network security, incident response, and hardening
  • CC8: Change Management — Change approval, testing, segregation of environments, and emergency changes
  • CC9: Risk Mitigation — Vendor management, business continuity, and disaster recovery

Questions are tagged with Type I and Type II relevance to help you prioritise based on your examination timeline.

What You Receive

Executive Summary Report

Board-ready overview with readiness scores by Common Criteria, exportable to Word format for executive and customer circulation.

Detailed Gap Register

Detailed findings mapped to specific CC criteria with Type I/II relevance, exportable to Excel for remediation tracking.

Readiness Visualisations

Charts showing maturity by control domain, suitable for management reporting and CPA firm preparation discussions.

Prioritised Remediation Roadmap

Actionable recommendations ranked by examination significance and implementation effort.

Consistent methodology enables pre-examination readiness checks and ongoing monitoring between Type II examination periods.

Ready to Assess Your SOC 2 Readiness?

Tell us a little about your organisation and we will walk you through what the SOC 2 assessment covers and how access works.

Enquire about access

What this is

CyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.

On coverage

We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.

CyberAssure is not affiliated with, endorsed by, or accredited by the AICPA, any licensed CPA firm, or any accreditation or certification body.

Often Used Alongside

Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.

Information Security

ISO 27001 Maturity Assessment

Many organisations pursue both SOC 2 and ISO 27001, with significant control overlap.

Learn more
Third-Party Risk

Supply Chain Security Assessment

Extend CC9 vendor management with a structured third-party risk assessment.

Learn more

Have questions about how our assessments work?

Read the Enterprise Assessment FAQ →