SOC 2 readiness assessments for consultants
Updated
A SOC 2 readiness assessment checks whether a client’s controls are ready for a SOC 2 examination by a CPA firm. The consultant helps choose which Trust Services Criteria apply, tests the client’s controls against evidence, and fixes gaps before the audit period starts. The CPA firm then examines the controls and issues the report. Getting readiness right matters most for Type II, where gaps found late can cost the client a whole audit period.
Choosing the criteria
| Category | Included when |
|---|---|
| Security (common criteria) | Always |
| Availability | The client commits to uptime or recovery targets |
| Confidentiality | The client commits to protecting confidential customer information |
| Processing Integrity | Customers rely on the client’s processing being complete, accurate and timely |
| Privacy | The client collects or processes personal information on customers’ behalf |
Start from the client’s customer contracts and security questionnaires. The commitments made there decide which categories are worth the audit cost.
Type I or Type II
A Type I report covers control design at a point in time and suits a first report or a tight sales deadline. A Type II report adds operating effectiveness over a period and is what most enterprise customers ask for. For Type II readiness, test samples of recurring activity such as access reviews, onboarding and offboarding, change approvals and incident tickets, not only the current configuration.
Running the readiness engagement
- Describe the system. Services, infrastructure, software, people, data and the boundaries of the system in scope.
- Choose the criteria with the client, based on their commitments.
- Map the client’s controls to the criteria and test each one against evidence.
- Fix and retest before the Type II period starts.
- Hand over. Give the CPA firm a clear starting point: controls, evidence and known exceptions.
How Control+s supports SOC 2 readiness
- Scope the system and the selected Trust Services Criteria before assessing.
- Score each criterion from 0 to 5 with a rationale citing the evidence and the gaps that remain. Review and override any result.
- Share a SOC 2 readiness snapshot with the client, or invite their auditor to review evidence and rationale and raise challenges against specific scores.
- Reuse the same evidence for ISO 27001, which many SOC 2 clients pursue next.
Control+s does not perform SOC 2 examinations or issue reports. It prepares the readiness assessment you deliver to your client.
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
A Type I report covers the design of controls at a point in time. A Type II report also covers whether the controls operated effectively over a period, commonly several months to a year. Type II needs evidence from across the whole period, not a single snapshot.
Which Trust Services Criteria are required for SOC 2?
Security, covered by the common criteria, is included in every SOC 2 examination. Availability, Processing Integrity, Confidentiality and Privacy are optional and chosen based on the commitments the client makes to its customers.
Can a consultant issue a SOC 2 report?
No. Only a licensed CPA firm can perform the examination and issue a SOC 2 report. Consultants help with readiness. A CPA firm that performs the examination is subject to independence rules that limit readiness work for the same client.
Which version of the Trust Services Criteria applies?
As of September 2026, SOC 2 examinations use the 2017 Trust Services Criteria with the revised points of focus published in 2022.