Skip to content
Reference

SOC 2 Readiness Assessment, Explained

The short version

SOC 2 readiness is the state of a service organization's controls, documentation and evidence being prepared for a SOC 2 examination, and a readiness assessment is the structured review that gets it there. A SOC 2 report is an attestation report issued by a licensed CPA firm under the AICPA's attestation standards (AT-C sections 105 and 205), evaluating controls against the Trust Services Criteria. The readiness assessment scopes the system, drafts the system description, maps controls to the criteria, identifies gaps, tracks remediation and organizes evidence. It produces no report for outside users and is not an audit.

SOC 2 readiness is the condition in which a service organization's controls, system description and supporting evidence are prepared for examination by a CPA firm under the SOC 2 framework. A SOC 2 readiness assessment is the structured, pre-examination review that measures an organization's current controls against the applicable criteria, identifies gaps, and guides remediation before the examination period begins.

The readiness assessment is a preparation step. It does not result in a SOC 2 report and gives no assurance to customers. Its value lies in reducing the likelihood that the eventual examination will produce exceptions or a qualified opinion.

What a SOC 2 examination is

A SOC 2 examination is an attestation engagement defined by the American Institute of Certified Public Accountants (AICPA). It reports on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy. The examination is performed under the AICPA's attestation standards, principally AT-C section 105, "Concepts Common to All Attestation Engagements," and AT-C section 205, "Assertion-Based Examination Engagements," with further guidance in the AICPA Guide, SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy.

Three documents define what is examined:

Who may issue the report

Only a licensed CPA firm can perform a SOC 2 examination and issue the report, because the engagement is an attestation engagement under the AICPA's professional standards and state accountancy laws reserve attest services to licensed firms. The firm must be independent of the service organization. A readiness consultant, a compliance software provider or an internal team can prepare an organization, but none of them can issue a SOC 2 report, and a readiness assessment performed by the same CPA firm that later performs the examination raises independence questions that the firm must evaluate under the AICPA Code of Professional Conduct.

Type 1 and Type 2 reports

Type 1Type 2
What it coversThe fairness of the system description and the suitability of control design as of a specified date.The same, plus the operating effectiveness of controls throughout a specified period.
TestingDesign and implementation at a point in time.Tests of operation across the period, usually by sampling.
Evidence neededEvidence that controls exist and are in place on the report date.Evidence that each control operated as described across the whole period.
Typical useA first report, or a report needed before a period of operation has elapsed.The report customers commonly request in vendor due diligence.

The period covered by a Type 2 report is often called the observation period or review period. The standards do not fix its length; periods of three to twelve months are common, and customers frequently expect twelve months once an organization has an established reporting cycle. Controls must operate, and generate evidence, from the first day of the period, which is why readiness work is completed before the period starts.

The steps of a readiness assessment

A readiness assessment usually follows the sequence below. The same steps apply whether the work is done internally, by a consultant, or with the help of compliance software.

StepWhat is done
1. ScopeDefine the system in scope (the services, infrastructure, software, people, procedures and data), the Trust Services Categories to be covered, the report type, and any subservice organizations, such as cloud hosting providers, and whether they will be presented using the carve-out or inclusive method.
2. System descriptionDraft management's description against the description criteria: the services provided, principal service commitments and system requirements, system components, relevant aspects of the control environment and risk assessment, and complementary user entity controls.
3. Control mappingList the organization's existing controls and map each one to the criteria it addresses. One control often addresses several criteria, and each criterion usually needs more than one control.
4. Gap assessmentIdentify criteria with no control, controls that are not designed to meet the criterion, and controls that exist but leave no evidence. Each gap is recorded with a severity and an owner.
5. RemediationDesign and implement missing controls, write or revise policies, configure systems, and assign control owners. Remediation is tracked to completion before the examination date or period begins.
6. EvidenceEstablish how each control will produce evidence the CPA can test: tickets, logs, approvals, reviews, reports and screenshots, retained for the whole period. A trial walkthrough of a sample of controls often tests whether the evidence is sufficient.

Areas that commonly produce gaps

Gaps recur in similar places across organizations, because the common criteria reach governance and process as well as technology. Examples include a documented risk assessment process (common criteria CC3), vendor and subservice organization oversight, formal access provisioning, periodic access reviews and prompt deprovisioning, change management with approval and separation of duties, incident response procedures that have been exercised, security awareness training with completion records, and board or management oversight of security. Technical controls may be in place while the review, approval or record that the criteria require is not.

How readiness relates to the report reader

The eventual SOC 2 report is read by customers and their auditors, typically during vendor due diligence. Readers look at the scope, the period, the opinion, the list of exceptions in the tests of controls, the complementary user entity controls they are expected to operate, and the treatment of subservice organizations. A readiness assessment that anticipates these points produces a report that answers reader questions rather than raising them. The SOC 2 report review checklist describes the report from the reader's side.

Readiness and other frameworks

Organizations preparing for SOC 2 often face other security frameworks as well, such as ISO/IEC 27001 or PCI DSS. The AICPA publishes mapping documents between the 2017 Trust Services Criteria and other frameworks, and a single control set can often be mapped to several of them. The control library and framework mapping entry describes how such mappings are built and where they stop being reliable.

Primary sources

Common questions

What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment is a pre-examination review of a service organization's controls against the Trust Services Criteria. It scopes the system, drafts the system description, maps controls to the criteria, identifies gaps, tracks remediation and plans evidence. It does not produce a SOC 2 report.
Who can issue a SOC 2 report?
Only a licensed, independent CPA firm. A SOC 2 examination is an attestation engagement performed under the AICPA's attestation standards (AT-C sections 105 and 205). Consultants and software providers can help an organization prepare but cannot issue the report.
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report covers the system description and the suitability of control design as of a single date. A Type 2 report also covers whether controls operated effectively throughout a period, based on testing across that period.
How long is a SOC 2 observation period?
The standards do not set a fixed length. Type 2 periods of three to twelve months are common, and twelve months is frequently expected once an organization reports annually.
Which Trust Services Criteria are required?
The security criteria (the common criteria) are included in every SOC 2 examination. Availability, processing integrity, confidentiality and privacy are added when the organization chooses them or its customers require them.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.