Map your controls, close the gaps, and collect clean evidence before a CPA firm ever shows up.
TL;DR
A readiness assessment is the pre-audit dry run: check your controls against the framework, find the gaps, and fix them before a CPA firm looks at your evidence.
The startups that sail through have a clean evidence trail, every control has an owner, a policy, and proof it ran. This SOC 2 readiness checklist gives you the exact path to get there.
On this page
What a SOC 2 readiness assessment actually is
A SOC 2 readiness assessment is a pre-audit self-check. You map your controls against the SOC 2 Trust Services Criteria, flag every gap, and fix it before the formal audit begins.
The 7 steps to prepare
These are the moves that make up a solid SOC 2 readiness process, in the order that keeps you from redoing work.
Define scope & criteria
- Decide what systems and data the audit covers
- Security is mandatory; add others only if a buyer requires
Run a risk assessment
- Catalogue systems, score threats by likelihood and impact
- Document mitigations and get leadership sign-off
Do a gap analysis
- Map each criterion to the control that satisfies it
- Log every gap as a ticket with an owner and due date
Write & approve policies
- Draft the core policy suite, concise enough to actually follow
- Have leadership approve with a date and signature
Close the gaps
- Enforce MFA and role-based access, set up logging
- Give every control a named owner
Wire up evidence
- Point every control at a place its evidence lands
- Automate what you can so proof accumulates on its own
Final self-audit
- Confirm nothing is missing, fix what surfaces
- Appoint an auditor point of contact and schedule kickoff
Documents auditors expect
Unlike ISO 27001, SOC 2 has no fixed list of mandatory documents. Auditors expect a coherent policy suite, the evidence that those controls operate, and a few audit-specific artifacts.
- Information security
- Access control
- Change management
- Incident response
- Risk assessment
- Vendor management
- Business continuity & DR
- Data classification
- Access review sign-offs
- MFA configuration proof
- Change tickets
- Monitoring & alert logs
- Incident records
- Training completion logs
- Vendor assessments
- Backup test results
- Management assertion
- System description
- Control matrix
- Onboarding / offboarding
- Background checks
- Role-based access maps
- Acceptable use
The checklist, control area by control area
Work through these eight areas. For each item you want to say: the control exists, someone owns it, and there is evidence it operated. Anything you cannot tick is a gap to close before fieldwork.
Access & identity
- MFA enforced everywhere
- Role-based access, least privilege
- Access reviews with sign-off
Change management
- Changes reviewed and approved
- Change tickets with an audit trail
Monitoring & logging
- Logging on across systems
- Alerts reaching a human who acts
Incident response
- Current process, tested
- Incident records kept
Risk & vendors
- Risk assessment done and signed
- Critical vendors assessed on a schedule
Policies
- Core suite written and approved
- Policies match how you actually work
Data protection & people
- Encryption in transit and at rest
- Security training records filed
- Background checks on relevant hires
Evidence trail
- Every control points at where proof lands
- Collection automated where possible
How long it takes
Two clocks matter: how long readiness and remediation take, and how long the audit itself runs. Here is the realistic shape for a first-timer.
When SOC 2 is required
SOC 2 is not a law, so nothing legally forces it. In practice it becomes required the moment a customer or partner makes it a condition of doing business, and for a B2B SaaS startup that moment tends to arrive with the first serious enterprise deal.
- An enterprise or mid-market prospect asks for your report during a security review.
- You are selling into regulated industries like finance or healthcare, where their compliance flows down to you.
- A security questionnaire or vendor-risk assessment lands mid-deal.
- Investors ask about it during fundraising due diligence.
- You handle sensitive customer data and prospects keep asking how you protect it.
The SOC 2 readiness shortcut: controls and evidence in one place
Read back over this SOC 2 readiness checklist and one theme repeats on nearly every line. Every control needs three things:
A control
that actually does the job.
An owner
accountable for it operating.
Evidence
that proves it ran.
Readiness breaks down when those three live in different places, policies in a doc tool, controls across point products, evidence in screenshots gathered during audit week.
Walk into your audit with the evidence already organised.
Osto is a one-stop cybersecurity and compliance platform for growing companies. Deploy the controls SOC 2 checks for across web, cloud, endpoint, and access, collect the evidence from the same platform, and get audit-ready in about 115 days. No security team required.
Frequently asked questions
What is a SOC 2 readiness assessment?
A pre-audit self-check where you map your controls against the SOC 2 criteria, find gaps (a missing control, no owner, or no evidence), and fix them before the formal audit starts.
Can you fail a SOC 2 audit?
Not in a simple pass/fail sense. But you can receive a report full of exceptions, which reads badly to a buyer. A readiness assessment is how you avoid that.
What documents do auditors want?
SOC 2 has no fixed mandatory list. Auditors expect a coherent policy suite, evidence that those controls operate, and audit artifacts like a management assertion, system description, and control matrix.
How long does SOC 2 readiness take?
It depends mostly on your starting security. With real controls already running it can be weeks; from scratch it is months of foundational work before the observation window even starts.
When is SOC 2 actually required?
When a customer or partner makes it a condition of doing business, usually the first serious enterprise deal, a mid-deal security questionnaire, regulated-industry sales, or fundraising due diligence.

