Skip to main content

The Art of CTO SOC 2 Readiness tool is a free readiness questionnaire covering 51 of the 61 Trust Services Criteria — all 33 Common Criteria, all of Availability, Confidentiality and Processing Integrity, and 8 of the 18 Privacy criteria. It produces a weighted readiness score per domain and a gap list by control, each one referenced to the AICPA 2017 criteria. It is a readiness check, not an audit.

Are we ready for a SOC 2 audit?

A score against 51 of the 61 Trust Services Criteria, the gaps by control, and what to fix first.

About 20 min · Assessment · Free

About this toolWhy it matters, common mistakes, FAQ

Are You Ready For A SOC 2 Audit, Or Ready To Start One?

SOC 2 is usually forced by a deal, which means the timeline is set by a customer rather than by you. Type II needs an observation window of several months, so the date you start collecting evidence sets the date you can close the contract.

Teams treat SOC 2 as a documentation project and write policies nobody follows. Auditors test whether the control operated, not whether it was described — an access review policy with no quarterly evidence is a finding, however well written.

Questions CTOs ask

What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment evaluates your organization's controls against the Trust Service Criteria (security, availability, processing integrity, confidentiality, and privacy) before a formal audit. It identifies gaps in policies, procedures, and technical controls so you can remediate them proactively rather than discovering issues during the audit itself.
How long does it take to become SOC 2 compliant?
Most organizations need 3 to 12 months to achieve SOC 2 compliance, depending on their starting maturity level. The timeline includes implementing required controls, documenting policies, training staff, and running the controls for an observation period. Companies with existing security programs can often accelerate this to 3-6 months.
What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I evaluates the design of your controls at a single point in time, confirming they are suitably designed to meet Trust Service Criteria. SOC 2 Type II goes further by testing the operating effectiveness of those controls over a minimum observation period of 3-12 months. Type II is considered the gold standard and is what most enterprise customers require.

Related Reading