ISO 27001 Maturity Assessment
Many organisations pursue both SOC 2 and ISO 27001, with significant control overlap.
Learn morePrepare for SOC 2 examination with a structured evaluation against the AICPA Common Criteria (CC1–CC9).
The SOC 2 Readiness Assessment provides a structured framework for evaluating your organisation's control environment against the AICPA Common Criteria (CC1–CC9) — the Security category of the Trust Services Criteria. With 119 questions across 9 control domains, this assessment helps service organisations prepare for Type I or Type II SOC 2 examinations.
Through structured evaluation criteria aligned to the Common Criteria (CC series), you will assess your organisation's security governance, logical and physical access controls, system operations, change management, and risk mitigation practices.
The assessment employs a maturity-based scoring model to help you understand your current readiness posture, identify control gaps that could result in examination exceptions, and develop a prioritised remediation roadmap.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment is structured around the nine Common Criteria (CC1–CC9), which make up the Security category within the AICPA's Trust Services Criteria:
Questions are tagged with Type I and Type II relevance to help you prioritise based on your examination timeline.
Board-ready overview with readiness scores by Common Criteria, exportable to Word format for executive and customer circulation.
Detailed findings mapped to specific CC criteria with Type I/II relevance, exportable to Excel for remediation tracking.
Charts showing maturity by control domain, suitable for management reporting and CPA firm preparation discussions.
Actionable recommendations ranked by examination significance and implementation effort.
Consistent methodology enables pre-examination readiness checks and ongoing monitoring between Type II examination periods.
Tell us a little about your organisation and we will walk you through what the SOC 2 assessment covers and how access works.
Enquire about accessCyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.
We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.
CyberAssure is not affiliated with, endorsed by, or accredited by the AICPA, any licensed CPA firm, or any accreditation or certification body.
Organisations frequently combine this assessment with complementary frameworks to address multiple governance requirements.
Many organisations pursue both SOC 2 and ISO 27001, with significant control overlap.
Learn moreExtend CC9 vendor management with a structured third-party risk assessment.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →