SOC 2 readiness is the state of a service organization's controls, documentation and evidence being prepared for a SOC 2 examination, and a readiness assessment is the structured review that gets it there. A SOC 2 report is an attestation report issued by a licensed CPA firm under the AICPA's attestation standards (AT-C sections 105 and 205), evaluating controls against the Trust Services Criteria. The readiness assessment scopes the system, drafts the system description, maps controls to the criteria, identifies gaps, tracks remediation and organizes evidence. It produces no report for outside users and is not an audit.
SOC 2 readiness is the condition in which a service organization's controls, system description and supporting evidence are prepared for examination by a CPA firm under the SOC 2 framework. A SOC 2 readiness assessment is the structured, pre-examination review that measures an organization's current controls against the applicable criteria, identifies gaps, and guides remediation before the examination period begins.
The readiness assessment is a preparation step. It does not result in a SOC 2 report and gives no assurance to customers. Its value lies in reducing the likelihood that the eventual examination will produce exceptions or a qualified opinion.
What a SOC 2 examination is
A SOC 2 examination is an attestation engagement defined by the American Institute of Certified Public Accountants (AICPA). It reports on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy. The examination is performed under the AICPA's attestation standards, principally AT-C section 105, "Concepts Common to All Attestation Engagements," and AT-C section 205, "Assertion-Based Examination Engagements," with further guidance in the AICPA Guide, SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy.
Three documents define what is examined:
- The Trust Services Criteria. The AICPA's 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, with revised points of focus issued in 2022. The 2022 revision updated the points of focus, which are illustrative considerations, and did not change the criteria themselves. The security criteria, often called the common criteria, apply to every SOC 2 examination; the other four categories are included when the organization chooses them or its customers require them.
- The description criteria. The 2018 SOC 2 Description Criteria (DC section 200, with revised implementation guidance issued in 2022) govern what management's description of its system must contain.
- Management's assertion. Management asserts that the description is fairly presented and that controls were suitably designed (and, for Type 2, operated effectively). The CPA expresses an opinion on that assertion.
Who may issue the report
Only a licensed CPA firm can perform a SOC 2 examination and issue the report, because the engagement is an attestation engagement under the AICPA's professional standards and state accountancy laws reserve attest services to licensed firms. The firm must be independent of the service organization. A readiness consultant, a compliance software provider or an internal team can prepare an organization, but none of them can issue a SOC 2 report, and a readiness assessment performed by the same CPA firm that later performs the examination raises independence questions that the firm must evaluate under the AICPA Code of Professional Conduct.
Type 1 and Type 2 reports
| Type 1 | Type 2 | |
|---|---|---|
| What it covers | The fairness of the system description and the suitability of control design as of a specified date. | The same, plus the operating effectiveness of controls throughout a specified period. |
| Testing | Design and implementation at a point in time. | Tests of operation across the period, usually by sampling. |
| Evidence needed | Evidence that controls exist and are in place on the report date. | Evidence that each control operated as described across the whole period. |
| Typical use | A first report, or a report needed before a period of operation has elapsed. | The report customers commonly request in vendor due diligence. |
The period covered by a Type 2 report is often called the observation period or review period. The standards do not fix its length; periods of three to twelve months are common, and customers frequently expect twelve months once an organization has an established reporting cycle. Controls must operate, and generate evidence, from the first day of the period, which is why readiness work is completed before the period starts.
The steps of a readiness assessment
A readiness assessment usually follows the sequence below. The same steps apply whether the work is done internally, by a consultant, or with the help of compliance software.
| Step | What is done |
|---|---|
| 1. Scope | Define the system in scope (the services, infrastructure, software, people, procedures and data), the Trust Services Categories to be covered, the report type, and any subservice organizations, such as cloud hosting providers, and whether they will be presented using the carve-out or inclusive method. |
| 2. System description | Draft management's description against the description criteria: the services provided, principal service commitments and system requirements, system components, relevant aspects of the control environment and risk assessment, and complementary user entity controls. |
| 3. Control mapping | List the organization's existing controls and map each one to the criteria it addresses. One control often addresses several criteria, and each criterion usually needs more than one control. |
| 4. Gap assessment | Identify criteria with no control, controls that are not designed to meet the criterion, and controls that exist but leave no evidence. Each gap is recorded with a severity and an owner. |
| 5. Remediation | Design and implement missing controls, write or revise policies, configure systems, and assign control owners. Remediation is tracked to completion before the examination date or period begins. |
| 6. Evidence | Establish how each control will produce evidence the CPA can test: tickets, logs, approvals, reviews, reports and screenshots, retained for the whole period. A trial walkthrough of a sample of controls often tests whether the evidence is sufficient. |
Areas that commonly produce gaps
Gaps recur in similar places across organizations, because the common criteria reach governance and process as well as technology. Examples include a documented risk assessment process (common criteria CC3), vendor and subservice organization oversight, formal access provisioning, periodic access reviews and prompt deprovisioning, change management with approval and separation of duties, incident response procedures that have been exercised, security awareness training with completion records, and board or management oversight of security. Technical controls may be in place while the review, approval or record that the criteria require is not.
How readiness relates to the report reader
The eventual SOC 2 report is read by customers and their auditors, typically during vendor due diligence. Readers look at the scope, the period, the opinion, the list of exceptions in the tests of controls, the complementary user entity controls they are expected to operate, and the treatment of subservice organizations. A readiness assessment that anticipates these points produces a report that answers reader questions rather than raising them. The SOC 2 report review checklist describes the report from the reader's side.
Readiness and other frameworks
Organizations preparing for SOC 2 often face other security frameworks as well, such as ISO/IEC 27001 or PCI DSS. The AICPA publishes mapping documents between the 2017 Trust Services Criteria and other frameworks, and a single control set can often be mapped to several of them. The control library and framework mapping entry describes how such mappings are built and where they stop being reliable.
Primary sources
- AICPA, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022): The criteria a SOC 2 examination evaluates controls against.
- AICPA, 2018 SOC 2 Description Criteria, DC section 200 (With Revised Implementation Guidance, 2022): What management's system description must contain.
- AICPA Statements on Standards for Attestation Engagements (currently effective), AT-C sections 105 and 205: The attestation standards under which a SOC 2 examination is performed; AT-C 205 was retitled Assertion-Based Examination Engagements by SSAE No. 21.
- AICPA, SOC 2 (SOC for Service Organizations): The AICPA's overview of SOC 2 reports and the SOC 2 Guide.
- AICPA, Mapping: 2017 Trust Services Criteria to NIST CSF: An example of the AICPA's published mappings from the criteria to other frameworks.