Are you ready for a SOC 2 audit?
Eight questions, two minutes. Scored against the control areas auditors test first — access, logging, policies, vendors, and recovery.
What a SOC 2 readiness assessment actually includes
A readiness assessment is a pre-audit dry run: a CPA firm (or a separate readiness consultant) tests your controls against the Trust Services Criteria you've scoped, then hands you a gap list — the exact policies to write, access to fix, logs to stand up, and vendor reviews to formalize. It is not an audit and produces no report your customers can rely on; its product is a remediation list. Published sources put the price at $10,000–$17,000 (Eventus Security, 2026) — often the highest-ROI spend in the whole program, because it prevents a failed or qualified audit cycle.
Readiness assessment vs. the audit (why firms separate them)
The assessment prepares; the audit opines. Under AICPA independence rules, the firm that designs or implements your controls shouldn't be the one auditing them — which is why many buyers deliberately hire a readiness consultant to prepare and a separate CPA firm to attest. Some audit firms offer both services with documented team separation; if yours does, ask exactly how independence is preserved and get the answer in the engagement letter. The quiz below approximates what an assessment probes, in eight questions.
What readiness assessments cost (published ranges, labeled)
Eventus Security (2026) publishes $10,000–$17,000 for a readiness/gap engagement. Our cost estimator treats readiness as 40–60% of the audit fee if you're starting from scratch, or 15–30% with partial controls in place — see the cost guide for the formula and a worked example. Budget it as its own line item: folding it silently into the "audit cost" is how first-year budgets blow up.
The 2-minute quiz
1. Do you have written information-security policies that employees have acknowledged?
2. Do you review who has access to production systems and customer data?
3. Are security logs collected centrally and reviewed for incidents?
4. Do you run background checks and security training for new hires?
5. Is there a tested backup and disaster-recovery plan for critical systems?
6. Do you have an incident-response plan and know who runs it?
7. Do you assess the security of vendors that touch customer data?
8. Have you had a penetration test or vulnerability assessment in the last 12 months?
How scoring works
Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with a readiness assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready to engage auditors. This is a self-assessment aid, not an audit opinion.
Know your score? Get quotes
Auditors scope fees around readiness. Tell us where you stand and get matched.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.