v3ndor.io

SOC 2 Readiness Checker

Free tool

SOC 2 Readiness Checker.

Answer eight questions about how your program actually runs today and see where you stand against the SOC 2 Security common criteria — with your largest gaps named, not just a number.

Runs entirely in your browser — nothing you enter is stored or sent anywhere. No account required.

This is a self-assessment, not an audit. A SOC 2 report is an attestation issued by a licensed CPA firm; use this to find the work worth doing before you engage one.

1. Policies & governance · 15%CC1 — Control environmentDo you have written security policies that someone owns, approves, and reviews?
2. Risk assessment · 10%CC3 — Risk assessmentDo you run a documented risk assessment, and act on what it finds?
3. Access control · 20%CC6 — Logical & physical accessHow do you control who has access to production systems and customer data?
4. Change management · 10%CC8 — Change managementHow do changes reach production?
5. Monitoring & logging · 15%CC4 / CC7 — Monitoring and operationsWhat visibility do you have into what happens in production?
6. Incident response · 10%CC7 — System operationsWhat happens when something goes wrong?
7. Vendor & third-party risk · 10%CC9 — Risk mitigationHow do you assess and monitor the vendors that touch your data?
8. Evidence readiness · 10%Audit preparationIf an auditor asked for six months of control evidence tomorrow, what would happen?

Answer all eight questions to see your readiness — 8 remaining. The score, stage, biggest gaps, and a next step appear here instantly.

How the score is calculated

Eight control areas mapped to the SOC 2 Security common criteria, each weighted — policies & governance 15%, risk assessment 10%, access control 20%, change management 10%, monitoring & logging 15%, incident response 10%, vendor & third-party risk 10%, evidence readiness 10%. Your answer sets how fully each area is in place; the weighted sum is the 0-100 readiness score, mapped to 0-24 Not started, 25-49 Foundational, 50-74 Approaching, and 75-100 Audit-ready. Access control carries the most weight because it is the most heavily sampled area in a Security engagement. Model version public-soc2-readiness-1.0.

Scope note: this covers the Security criteria, which every SOC 2 engagement includes. The optional categories — Availability, Confidentiality, Processing Integrity and Privacy — are selected per engagement, so they are deliberately left out rather than folded into a number you would read as "my SOC 2".

Readiness Is Earned Over a Window, Not a Weekend.

A Type II report observes your controls over months. The platform keeps the evidence — access reviews, vendor assessments, and attestations — collected as the controls run, so the window is a record rather than a scramble.