A SOC 2 gap analysis is the diagnostic step that tells you exactly where you stand before an auditor does. Find the gaps while they are still easy to fix.
TL;DR
A SOC 2 gap analysis measures the distance between the controls you have today and what the Trust Services Criteria require. It is the diagnostic you run first, so you find and fix problems while they are still private.
The process: define scope, map each criterion to your controls, mark every gap, score it by severity, assign an owner and deadline, then remediate. The output is a gap register that drives everything downstream.
On this page
What a SOC 2 gap analysis is
A SOC 2 gap analysis is a structured comparison: your current controls on one side, the SOC 2 Trust Services Criteria on the other, and a clear list of the differences in between.
Gap analysis vs readiness assessment
These terms get used loosely, so here is the clean distinction.
A gap is not an exception
This is the single most useful concept to hold onto, because it explains why the whole exercise is worth it.
How to run one, step by step
Run your SOC 2 gap analysis before you sign an engagement letter, ideally three to six months before you want your observation window to open. It is a cross-functional exercise, not a one-person spreadsheet.
Define scope
- Which systems and data are in scope
- Which criteria apply (Security is mandatory)
Map controls to criteria
- Go CC1 through CC9, plus any optional
- Note the control that satisfies each, if any
Flag every gap
- No control, undocumented, or no evidence
- Each of these counts as a gap
Score by severity
- How likely to cause an exception
- How much real risk it carries
Assign owners
- A named owner with authority and resources
- A realistic due date. Unowned gaps do not close
Remediate & verify
- Work the register, close each gap
- A short internal re-test confirms readiness
Building the gap register
The concrete deliverable is a gap register: a control mapping matrix that tracks each requirement, its status, and its path to closure.
| Column | What it captures |
|---|---|
| Criterion | The SOC 2 requirement (CC1 through CC9, plus optional) |
| Existing control | The control you have that satisfies it, if any |
| Gap status | Met, partial, or missing |
| Severity | How likely to cause an exception, and the risk it carries |
| Owner | The named person accountable for closing it |
| Due date | A realistic deadline for closure |
Scoring and prioritising gaps
Not every gap is equal, and you rarely have time to fix everything at once. Score each by how likely it is to produce an audit exception and how much real security risk it carries. That tells you what to fix first.
Closing the gaps faster
Here is the pattern a SOC 2 gap analysis almost always reveals. A thorough SOC 2 gap analysis almost always finds the biggest gaps clustered in the same three places.
Access & MFA
Access control and multi-factor authentication.
Monitoring
Monitoring and incident response.
Vendor risk
Third-party and vendor risk management.
These are not documentation gaps you can write your way out of. They are missing or partial security controls that have to be built, run, and evidenced. That is where closing speed is won or lost. When security is scattered across a patchwork of point tools, every high-severity gap means procuring, configuring, and wiring up another product before you can even collect evidence.
Turn a daunting gap register into a clean report.
Osto is a one-stop cybersecurity and compliance platform for growing companies. The controls behind your highest-severity gaps come built in, with the evidence collected from the same platform, so you can get SOC 2 ready in about 115 days. No security team required.
Frequently asked questions
What is a SOC 2 gap analysis?
A structured comparison between your current security controls and the requirements of the SOC 2 Trust Services Criteria. For each in-scope criterion, you check whether you have a control, whether it is documented, and whether you can produce evidence, then list every gap.
How is it different from a readiness assessment?
A gap analysis is the diagnostic core: mapping your controls to the criteria and listing what is missing. A readiness assessment is the broader phase that contains the gap analysis, plus remediation and a final self-check.
What is the difference between a gap and an exception?
A gap is a deficiency you find during your own readiness work, while there is still time to fix it privately. An exception is what the auditor documents when a control fails during formal testing, and it can appear in your final report.
When should I run a gap analysis?
Early, ideally three to six months before you want your observation window to open, and before you sign an engagement letter. Good triggers include an enterprise prospect asking for your report, or a mid-deal security questionnaire.
What is a gap register?
The concrete deliverable of a gap analysis: a control mapping matrix listing each criterion, your existing control, the gap status, its severity, the responsible owner, and a due date.

