SOC 2 readiness assessments for consultants

Updated

A SOC 2 readiness assessment checks whether a client’s controls are ready for a SOC 2 examination by a CPA firm. The consultant helps choose which Trust Services Criteria apply, tests the client’s controls against evidence, and fixes gaps before the audit period starts. The CPA firm then examines the controls and issues the report. Getting readiness right matters most for Type II, where gaps found late can cost the client a whole audit period.

Choosing the criteria

Category Included when
Security (common criteria) Always
Availability The client commits to uptime or recovery targets
Confidentiality The client commits to protecting confidential customer information
Processing Integrity Customers rely on the client’s processing being complete, accurate and timely
Privacy The client collects or processes personal information on customers’ behalf

Start from the client’s customer contracts and security questionnaires. The commitments made there decide which categories are worth the audit cost.

Type I or Type II

A Type I report covers control design at a point in time and suits a first report or a tight sales deadline. A Type II report adds operating effectiveness over a period and is what most enterprise customers ask for. For Type II readiness, test samples of recurring activity such as access reviews, onboarding and offboarding, change approvals and incident tickets, not only the current configuration.

Running the readiness engagement

  1. Describe the system. Services, infrastructure, software, people, data and the boundaries of the system in scope.
  2. Choose the criteria with the client, based on their commitments.
  3. Map the client’s controls to the criteria and test each one against evidence.
  4. Fix and retest before the Type II period starts.
  5. Hand over. Give the CPA firm a clear starting point: controls, evidence and known exceptions.

How Control+s supports SOC 2 readiness

  • Scope the system and the selected Trust Services Criteria before assessing.
  • Score each criterion from 0 to 5 with a rationale citing the evidence and the gaps that remain. Review and override any result.
  • Share a SOC 2 readiness snapshot with the client, or invite their auditor to review evidence and rationale and raise challenges against specific scores.
  • Reuse the same evidence for ISO 27001, which many SOC 2 clients pursue next.

Control+s does not perform SOC 2 examinations or issue reports. It prepares the readiness assessment you deliver to your client.

Frequently asked questions

What is the difference between SOC 2 Type I and Type II?

A Type I report covers the design of controls at a point in time. A Type II report also covers whether the controls operated effectively over a period, commonly several months to a year. Type II needs evidence from across the whole period, not a single snapshot.

Which Trust Services Criteria are required for SOC 2?

Security, covered by the common criteria, is included in every SOC 2 examination. Availability, Processing Integrity, Confidentiality and Privacy are optional and chosen based on the commitments the client makes to its customers.

Can a consultant issue a SOC 2 report?

No. Only a licensed CPA firm can perform the examination and issue a SOC 2 report. Consultants help with readiness. A CPA firm that performs the examination is subject to independence rules that limit readiness work for the same client.

Which version of the Trust Services Criteria applies?

As of September 2026, SOC 2 examinations use the 2017 Trust Services Criteria with the revised points of focus published in 2022.

Sources

  1. AICPA: 2017 Trust Services Criteria with revised points of focus (2022)
  2. AICPA: System and Organization Controls (SOC) suite of services

Bring your next assessment to Control+s.

Start free with two frameworks and five evidence files. Use your own material to inspect the mapping, reasoning, and results, and see how Control+s fits your engagements.

Help shape the product around real consulting work. We welcome teams who want to build their assessment workflow with us.

Running a larger program? .