SOC 2 Readiness Check
Ten operating questions drawn from the Trust Services Criteria auditors test — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
SOC 2 is an attestation under the AICPA Trust Services Criteria, issued by a CPA firm — not law, not certification. Security is mandatory in every report; availability, confidentiality, processing integrity and privacy are added by scope.
1.Commitment: are security policies approved, with accountability for the control environment assigned to named people?
CC1 — control environment
2.Scope: is the system description defined — what is in the audit boundary and which TSC categories beyond security are in scope?
TSC — system description and scope
3.Risk: are threats and vulnerabilities identified and assessed, and are responses selected and on record?
CC3 — risk assessment
4.Access: is logical access controlled through the whole lifecycle — provisioning, MFA, least privilege, prompt deprovisioning, periodic reviews?
CC6.1–6.3 — logical access
5.Physical access: are facilities and hardware in scope protected — badges, visitors, environment (where physical scope exists)?
CC6.4–6.5 — physical access
6.Change: are system changes authorized, tested and approved before release — with emergency changes on record?
CC8 — change management
7.Vulnerabilities: are systems scanned, patched and hardened against known vulnerabilities on a schedule?
CC7.1 — vulnerability detection and configuration
8.Incidents: is anomalous activity monitored, with a documented and tested incident-response process — including customer notification duties?
CC7.2–7.5 — monitoring and incident response
9.Vendors and continuity: are critical vendors assessed, and are backups with tested restoration in place for the systems in scope?
CC9 + A1 — risk mitigation, backup and recovery
10.Evidence: can you show each control operated over the whole audit window — continuously, not assembled at the end?
CC4 + Type II — monitoring over the period
SOC 2 readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence — Type II is won or lost on controls operating over the whole window, not on audit-day heroics.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with the system description, access lifecycle and change management — the SOC 2 framework page maps the criteria to operating controls.
The SOC 2 frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel. TruSecure is not a certification body and does not issue ISO, SOC 2, or CMMC certifications.