A SOC 2 readiness assessment is a structured comparison between the trust services criteria that apply to you and what your organization actually does today. The deliverable is a gap list: here are the criteria, here is what you have, here is what is missing, here is roughly what it takes to close it. It is not an audit, it produces no opinion, and you cannot show it to a customer as evidence of anything.

For most companies doing a first SOC 2, it is worth the money. For a specific minority, it is a fee you did not need to pay. The distinction is less about company size than about whether anyone in the building has done this before.

What a readiness assessment actually includes

Practice varies between firms, but a substantive readiness assessment generally covers the following.

Scope confirmation. Which system, which environments, which criteria categories beyond Security, which subservice organizations get carved out, and which of your customer-facing commitments will end up in the system description. Getting this wrong is more expensive than any individual control gap.

Criteria mapping. Walking the applicable trust services criteria and identifying, for each, whether you have a control, whether it is documented, and whether it operates. Common criteria alone cover a lot of ground: control environment, communication, risk assessment, monitoring, and then logical access, change management, operations and risk mitigation.

Documentation review. Reading your policies against what your systems and people actually do. The classic finding here is a policy that promises something the organization does not do — an access review policy saying monthly when the team runs it twice a year is worse than having no policy, because now there is a written standard you are failing.

Walkthroughs. Sitting with the people who run onboarding, deploy code, respond to alerts and manage vendors, and tracing an actual instance end to end. This is where undocumented reality surfaces.

Evidence feasibility. Can you produce a complete population of production changes for a period? A complete list of terminations? Scan results with dates? Plenty of organizations have good controls and no way to prove they ran, and that is a distinct problem worth finding early.

A remediation plan. Gaps, ranked, with owners and rough effort. The ranking matters more than the list — most gap lists are long, and not everything on them blocks a report.

What you get at the end

Typically a written report, a gap register you can work from, and a working session to walk through it. Some firms include a suggested observation window start date and a control matrix you can carry into the examination.

What you do not get is any form of attestation. There is no such thing as being “readiness certified”, and nothing from this phase goes to your customers. If a buyer asks for your SOC 2 and you send a readiness report, you have told them you do not have one.

The independence question — ask it early

This is the part that trips people up. If a CPA firm designs your controls, writes your policies and then examines those same controls, its independence is impaired for that engagement. Professional standards constrain how much a firm can do on both sides of the line.

Firms handle this differently, and the boundary is not identical everywhere. Some perform a readiness assessment that identifies gaps and describes what a remediated control would look like, then perform the examination — treating identification as acceptable and hands-on implementation as not. Others decline to do both entirely and will refer readiness work elsewhere.

Ask the question directly before you engage anyone: “If you do our readiness assessment, can you still perform the examination, and where is your line on remediation help?” A firm that cannot answer that clearly is a firm to be careful with.

When a readiness assessment earns its fee

You have never done a SOC 2 and no one on the team has either. This is the ordinary case. You do not know which of the criteria apply to you, what evidence they need, or which of your existing practices already satisfy them. Discovering that during fieldwork means discovering it as an exception.

Your scope is genuinely unclear. Multiple products, a recent acquisition, a hybrid of cloud and on-premise, or an unusual subservice arrangement. Scoping errors are the most expensive mistakes in a first SOC 2, and readiness is where you catch them cheaply.

You need to budget and plan. A gap list converts “we should do SOC 2” into a project with a duration and a headcount cost. That is often what the readiness assessment is really being bought for, and it is a legitimate reason.

You are worried about specific areas. Change management with a fast-moving engineering team, or access management after two years of rapid hiring, are the two that most often need a real look before an auditor sees them.

When to skip it

You have run a SOC 2 before, at this company or somewhere else. If your security lead has been through fieldwork, they can map the criteria themselves. Buy their time instead.

You are on your second report and scope has not changed. Your prior report is your gap analysis. Read the exceptions and management responses and work from those.

You already have a mature ISO 27001 ISMS in scope for the same system. A lot of the ground overlaps — risk assessment, access control, supplier management, incident management. A targeted mapping exercise focused on the criteria ISO does not cover is usually more useful than a full readiness assessment.

Your budget is genuinely fixed and small. If you can only afford one engagement, buy the examination and do the gap work yourself against the criteria. It is harder and slower, but a readiness report you cannot afford to act on helps nobody.

The middle option most people miss

You do not have to choose between a full readiness assessment and nothing. A scoping and criteria-selection conversation — a few hours, sometimes bundled into the audit engagement — resolves the most expensive category of mistake without the cost of a full walkthrough exercise.

Similarly, a targeted review of two or three areas you are uncertain about is often better value than a wall-to-wall assessment. If you know your logical access controls are solid and your change management is improvised, pay for a hard look at change management.

Ask the firm what they can scale down to. Most can.

What to do next

Before you decide, run a cheap self-test. Pick three criteria you know apply to you — user access is provisioned based on role and approval, changes are authorized and tested before deployment, and vendors are assessed before onboarding — and try to produce, today, a complete population and a piece of dated evidence for each.

If you can, you probably do not need a full readiness assessment. If you cannot produce the population, or the evidence has no date or approver on it, that is precisely the gap a readiness assessment exists to find, and it is cheaper to find it now than during fieldwork.

Assurion is a licensed CPA firm; we are happy to tell you which of these two situations you are in before you commit to either engagement.