top of page

SOC 2 Readiness Assessment.

An independent pre-audit review of your control environment against the AICPA Trust Services Criteria, identifying gaps and building a remediation path before your Type I or Type II examination begins.

SOC 2 Readiness Assessment.

Empty boardroom waiting for the work to start

What is SOC 2

a woman standing by a screen explaining what is SOC2 to a buddy

SOC 2 is the AICPA's assurance framework for service organisations. It evaluates the design and operating effectiveness of controls across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory for every report. The remaining four are selected based on the commitments each organisation makes to its clients.
A Type I report assesses control design at a point in time. A Type II report assesses design and operating effectiveness over a minimum observation period of three to twelve months. Regulated buyers, particularly in financial services, healthcare, and government procurement, increasingly require a current Type II report before onboarding a vendor or renewing a contract.
The examination itself is conducted by a licensed CPA firm. What happens before that examination determines whether it proceeds cleanly or produces findings, qualifications, and delays that erode buyer confidence.

Who This Is For

For vendors and service organisations

If you build or operate software, platforms, or managed services sold into regulated markets, a SOC 2 report is a commercial prerequisite. The readiness assessment identifies what is missing, what is undocumented, and what will not survive scrutiny before your auditor arrives. First-time examinations carry the highest failure risk. Organisations typically discover a 40 to 60 per cent gap rate on their first structured assessment against the Trust Services Criteria.

For enterprise buyers and procurement teams

If you receive vendor SOC 2 reports as part of third-party risk management, the question is whether those reports actually evidence what you need them to evidence. A readiness review on your side of the relationship assesses whether your vendor oversight controls, your evidence intake process, and your internal mapping of vendor commitments to your own regulatory obligations are fit for purpose.

What the Review Covers

01. Scope Definition and Criteria Selection

Establishing the system boundary: which services, infrastructure, data flows, and third-party dependencies fall within the SOC 2 scope. Mapping the Trust Services Criteria to actual commitments and contractual obligations rather than selecting criteria by convention or competitor mimicry. Misaligned scope is the single most common cause of avoidable findings.

02. Control Mapping and Evidence Assessment

A structured walk-through of existing controls against each applicable criterion within the Common Criteria series (CC1 through CC9) and any supplemental criteria selected. Policies, procedures, access controls, change management processes, incident response documentation, vendor management programmes, and business continuity arrangements are assessed for both design adequacy and evidence readiness. Where controls exist informally but lack documentation, the gap is classified and sized.

03. Gap Register and Remediation Roadmap

Every identified deficiency is logged, categorised (missing control, design gap, or operational gap), and risk-ranked by the likelihood and severity of an audit finding. The output is a prioritised remediation plan with named owners, target dates, and the specific evidence each control area will need to produce for the examination.

The independence process

What You Get

SOC 2 Readiness Report.

A structured assessment of your control environment against the applicable Trust Services Criteria, with a clear verdict on examination readiness.

Control Mapping Matrix.

Each applicable criterion mapped to your existing controls, with a status indicator (met, partially met, not met) and the evidence that supports or is missing from each.

Gap Register.

A prioritised register of every identified deficiency, classified by type and severity, with remediation ownership assigned.

Remediation Roadmap.

A sequenced plan for closing gaps before audit fieldwork begins, with target dates calibrated to your intended examination window.

Why Independent Review First

CPA firms that conduct SOC 2 examinations cannot also advise on remediation without compromising their independence under AICPA professional standards. This creates a structural gap: the firm that will judge your controls cannot help you fix them.
An independent readiness assessment sits in that gap. It provides the forensic scrutiny of a formal examination without the constraints of the audit relationship. Control weaknesses are identified, documented, and remediated before the examination begins, not surfaced as findings in the report your clients will read.
Organisations that proceed directly to examination without a readiness review routinely encounter qualified opinions, exceptions noted in testing, extended observation periods, and audit fees that exceed original estimates. The readiness assessment is a fraction of the cost of a failed or qualified report and the commercial consequences that follow from it.

SOC 2 independence show

Frequently Asked Questions

Is SITG-Consulting a licensed CPA firm?

No. SITG-Consulting is an independent advisory practice. We do not conduct SOC 2 examinations and we do not issue SOC 2 reports. We prepare organisations for examination and ensure the control environment, documentation, and evidence are examination-ready before the CPA firm arrives. Our independence from the audit relationship is what allows us to advise without constraint.

Do I need a Type I before a Type II?

Not necessarily. A Type I report confirms control design at a point in time and can serve as a stepping stone, but it is not a prerequisite for a Type II. If your control environment is mature enough, proceeding directly to a Type II is the faster route to the report most enterprise buyers require. The readiness assessment determines which path is appropriate.

The readiness assessment applies equally to remediation engagements. A qualified report identifies what went wrong. The readiness review maps the path to a clean report on the next examination cycle, with specific attention to the criteria and controls that produced the original findings.

What if we have already failed or received a qualified SOC 2 report?

How long does the readiness assessment take?

Typically four to six weeks, depending on the size of the control environment and the number of Trust Services Criteria in scope. Organisations targeting a specific audit window should allow a minimum remediation period between the readiness assessment and the start of examination fieldwork.

Inquiry Form

Current SOC 2 status
Target examination date
Day
Month
Year
bottom of page