Skip to main content
TOOLS

SOC 2 Readiness Check

Ten operating questions drawn from the Trust Services Criteria auditors test — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

SOC 2 is an attestation under the AICPA Trust Services Criteria, issued by a CPA firm — not law, not certification. Security is mandatory in every report; availability, confidentiality, processing integrity and privacy are added by scope.

0/10
  1. 1.Commitment: are security policies approved, with accountability for the control environment assigned to named people?

    CC1 — control environment

  2. 2.Scope: is the system description defined — what is in the audit boundary and which TSC categories beyond security are in scope?

    TSC — system description and scope

  3. 3.Risk: are threats and vulnerabilities identified and assessed, and are responses selected and on record?

    CC3 — risk assessment

  4. 4.Access: is logical access controlled through the whole lifecycle — provisioning, MFA, least privilege, prompt deprovisioning, periodic reviews?

    CC6.1–6.3 — logical access

  5. 5.Physical access: are facilities and hardware in scope protected — badges, visitors, environment (where physical scope exists)?

    CC6.4–6.5 — physical access

  6. 6.Change: are system changes authorized, tested and approved before release — with emergency changes on record?

    CC8 — change management

  7. 7.Vulnerabilities: are systems scanned, patched and hardened against known vulnerabilities on a schedule?

    CC7.1 — vulnerability detection and configuration

  8. 8.Incidents: is anomalous activity monitored, with a documented and tested incident-response process — including customer notification duties?

    CC7.2–7.5 — monitoring and incident response

  9. 9.Vendors and continuity: are critical vendors assessed, and are backups with tested restoration in place for the systems in scope?

    CC9 + A1 — risk mitigation, backup and recovery

  10. 10.Evidence: can you show each control operated over the whole audit window — continuously, not assembled at the end?

    CC4 + Type II — monitoring over the period

0%

SOC 2 readiness

Answer to score

What the score means

80–100% · Low risk

Controls exist and can mostly be shown. Next step: continuous evidence — Type II is won or lost on controls operating over the whole window, not on audit-day heroics.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with the system description, access lifecycle and change management — the SOC 2 framework page maps the criteria to operating controls.

The SOC 2 framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel. TruSecure is not a certification body and does not issue ISO, SOC 2, or CMMC certifications.

Frequently Asked Questions

What is the difference between SOC 2 Type I and Type II?
Type I says your controls were suitably designed at a point in time. Type II says they operated effectively over a period — usually six to twelve months. Buyers and enterprise procurement increasingly ask for Type II, and the evidence discipline the check scores under the last question is what it takes.
Who can issue a SOC 2 report?
A licensed CPA firm — a public accountant — performing the examination against the AICPA Trust Services Criteria. A software platform cannot issue SOC 2; it can only prepare the evidence.
Which categories should be in scope?
Security is mandatory in every SOC 2 report. Availability, confidentiality, processing integrity and privacy are added to match what your customers actually rely on — each adds criteria to the audit. The choice is made in the system description.
Is the score a SOC 2 audit?
No. It is an indicative maturity score from ten questions drawn from the Trust Services Criteria — not an examination and not a report. Only a CPA firm issues a SOC 2 opinion; the check tells you how far the control environment is from being examinable.