The SOC2 Gap Assessment is a free tool that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022) used in SOC2 examinations. Assess all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy at the SOC2 Type I or SOC2 Type II level; generate a downloadable report that includes a remediation roadmap.
The SOC2 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), the control criteria a licensed CPA firm uses in a SOC2 examination.
You choose your level: SOC2 Type I assesses all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy as a point-in-time readiness review, and SOC2 Type II assesses the same criteria and adds an Evidence (12 Months) field to every criterion so you can insert links to evidence artifacts covering the last 12 months. You assess each criterion, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
SOC 2 (System and Organization Controls 2, often written SOC2) is an assurance framework from the American Institute of Certified Public Accountants (AICPA) in which a licensed CPA firm examines a service organization's controls against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A SOC2 Type I report covers how controls are designed at a point in time, while a SOC2 Type II report covers how those controls operated over a period, typically 6 to 12 months. SOC2 is an attestation report rather than a certification, and it has become the de facto security credential SaaS companies need to sell to enterprise customers.
The assessment is built for small and medium organizations, startups, and growing SaaS companies that face customer security questionnaires or enterprise procurement requirements and want to understand where they stand against the Trust Services Criteria before engaging a CPA firm.
The SOC2 Type I level is the right starting point for teams preparing for their first examination, while the SOC2 Type II level suits teams heading into an operating-effectiveness review period who need to start collecting and organizing 12 months of evidence.
Enter your company name, website, and a description of what the company does, choose the SOC2 Type I or SOC2 Type II assessment level, and add your logo for the report.
Work through all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy, mark each one compliant, partially compliant, non-compliant, or not applicable, rate the likelihood and impact of each gap, and at the Type II level insert links to evidence artifacts covering the last 12 months.
Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.
Not loading? Open the SOC2 Gap Assessment tool in a new tab.
This assessment is a self-serve working draft to support professional review and decision-making. It is not a SOC2 examination, attestation, certification or legal advice, and it is not affiliated with or endorsed by the AICPA. We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.
A SOC2 gap analysis, also called a gap assessment, is a structured comparison of your organization's current controls against the AICPA Trust Services Criteria, identifying which criteria you already meet, where you fall short, and what to fix first. It is the standard starting point for any SOC2 readiness project, run before you engage a CPA firm so the formal examination holds no surprises.
A good gap assessment, sometimes called a SOC2 readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which Trust Services Categories belong in your report scope, given what you commit to customers about security, availability, processing integrity, confidentiality, and privacy? Secondly, Conformance: for each criterion, do you have the control, the documentation, and the evidence an auditor would sample?
Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your compliance obligations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.
A SOC2 Type I report opines on whether your controls are suitably designed and implemented at a single point in time. A SOC2 Type II report goes further: it opines on whether those controls operated effectively over a review period, commonly 3 to 12 months, which is why Type II is what enterprise customers usually require. Both report types are examinations of the same Trust Services Criteria; the difference is the evidence. That is exactly how the tool on this page treats them: both levels assess all 61 criteria, and the Type II level adds an Evidence (12 Months) field to every criterion so you can capture links to the artifacts that prove each control operated over the last 12 months.
| SOC2 Type I | SOC2 Type II | |
|---|---|---|
| What the auditor opines on | The design and implementation of your controls at a single point in time. | The design, implementation, and operating effectiveness of your controls over a review period, commonly 3 to 12 months. |
| Evidence required | Evidence that each control exists and is suitably designed as of the review date, such as policies, configurations, and walkthroughs. | Evidence that each control operated throughout the period: access review records, change tickets, incident records, monitoring reports, and training logs sampled across the full window. |
| How this tool maps to it | The SOC2 Type I level assesses all 61 Trust Services Criteria as a point-in-time readiness review. | The SOC2 Type II level assesses the same 61 criteria and adds an Evidence (12 Months) field to every criterion, so you can capture links to the artifacts that prove each control operated over the last 12 months. |
| Typical timeline | Faster: readiness, remediation, then a point-in-time examination. | Longer: an observation period must elapse before the examination, so evidence collection discipline matters from day one. |
| Who usually asks for it | Early-stage customers and partners who need initial assurance quickly. | Enterprise customers and procurement teams, who usually expect a Type II report renewed annually. |
The 2017 Trust Services Criteria (with Revised Points of Focus, 2022) contain 61 criteria organized into five categories. Security, expressed as the 33 Common Criteria CC1 to CC9, is mandatory in every SOC2 examination; the other four categories are added to the report scope based on the commitments you make to customers. This assessment covers all five categories so nothing is missed when you decide your report scope.
| Category | Criteria series | Criteria | What it covers |
|---|---|---|---|
| Security | CC1 to CC9 | 33 | The Common Criteria, mandatory in every SOC2 examination: control environment, communication and information, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation. |
| Availability | A1 | 3 | Capacity management, environmental protections, data backup and recovery infrastructure, and recovery plan testing that keep the system available per your commitments and SLAs. |
| Processing Integrity | PI1 | 5 | Processing specifications plus controls over system inputs, processing, outputs, and stored items so processing is complete, valid, accurate, timely, and authorized. |
| Confidentiality | C1 | 2 | Identifying, protecting, retaining, and verifiably disposing of confidential information in line with your confidentiality commitments. |
| Privacy | P1 to P8 | 18 | Notice, choice and consent, collection, use, retention and disposal, data subject access, disclosure and breach notification, data quality, and privacy dispute handling and compliance monitoring for personal information. |
The single biggest cause of SOC2 Type II findings is not missing controls, it is missing evidence: the control operated, but nobody can produce the access review, the change ticket, or the test result from eight months ago. At the Type II level, this tool adds an Evidence (12 Months) field to every criterion where you type or insert links to the artifacts that demonstrate operation over the last 12 months, for example policy documents, ticketing queries, monitoring reports, or folders in SharePoint, Google Drive, or your GRC platform.
Your evidence links are included against each criterion in the Detailed Findings section of the downloadable report, giving you a working evidence index you can hand to your auditor at the start of fieldwork, and an immediate view of which controls are operating without a paper trail. Criteria with no evidence link are your earliest warning of a Type II exception.
The table below summarizes each criteria series in the 2017 Trust Services Criteria and the evidence auditors typically expect to see. The summaries are condensed guidance prepared by IRM Consulting & Advisory, not verbatim AICPA criteria text; the assessment tool above walks you through all 61 criteria at either level.
| Series | Area | Summary | Evidence auditors expect |
|---|---|---|---|
| CC1 | Control Environment | Demonstrate integrity and ethical values, board oversight, defined structures and reporting lines, commitment to competence, and individual accountability for internal control. | Code of conduct, org chart, board minutes, job descriptions, training and performance records. |
| CC2 | Communication and Information | Generate and use quality information for internal control, communicate objectives and responsibilities internally, and communicate commitments and incidents to external parties. | System description, policy portal, security awareness communications, customer notifications, whistleblower channel. |
| CC3 | Risk Assessment | Specify clear objectives, identify and analyse risks including fraud risk, and assess changes that could significantly impact internal control. | Risk assessment procedure, risk register, fraud risk analysis, change impact assessments. |
| CC4 | Monitoring Activities | Perform ongoing and separate evaluations of internal control and communicate deficiencies to those responsible for corrective action. | Vulnerability scans, penetration test reports, internal audit reports, deficiency tracking. |
| CC5 | Control Activities | Select and develop control activities including general controls over technology, and deploy them through policies and procedures. | Control matrix, approved policies and procedures with owners and review dates. |
| CC6 | Logical and Physical Access Controls | Restrict logical and physical access to protected information assets: identity management, authentication, least privilege, access reviews, physical security, secure disposal, boundary protection, encryption, and anti-malware. | Access control policy, MFA configuration, joiner-mover-leaver tickets, access review records, badge logs, disposal certificates, encryption settings. |
| CC7 | System Operations | Detect configuration changes and vulnerabilities, monitor for anomalies and security events, evaluate and respond to incidents, and recover from them. | Monitoring and alerting configuration, SIEM reports, incident response plan, incident records and post-mortems, response test results. |
| CC8 | Change Management | Authorize, design, test, approve, and implement changes to infrastructure, data, software, and procedures. | Change management policy, change tickets with approvals and test evidence, emergency change reviews. |
| CC9 | Risk Mitigation | Develop risk mitigation activities for business disruptions and manage risks associated with vendors and business partners. | Business continuity plan, insurance review, vendor inventory, vendor due diligence and periodic review records. |
| A1 | Availability | Manage processing capacity, implement environmental protections, backups and recovery infrastructure, and test recovery plans. | Capacity monitoring dashboards, backup configuration and restoration tests, BC/DR test results. |
| PI1 | Processing Integrity | Define processing specifications and control system inputs, processing, outputs, and stored items for complete, accurate, timely, authorized processing. | Data definitions, input validation rules, processing error and reconciliation reports, output delivery controls. |
| C1 | Confidentiality | Identify and maintain confidential information, and dispose of it in a manner that prevents recovery when no longer needed. | Data classification policy, retention schedule, destruction and erasure records. |
| P1 to P8 | Privacy | Provide notice, obtain consent, limit collection and use, retain and dispose securely, grant data subject access and correction, control disclosures with breach notification, maintain data quality, and handle privacy inquiries, complaints and disputes. | Privacy notice, consent records, retention schedule, DSAR process records, disclosure logs, breach notification procedure, complaint register. |
Closing the gaps is where most organizations want help. IRM's Virtual CISO services take teams from gap assessment through certification readiness for SOC2, ISO 27001, ISO 42001 and CMMC, and our Governance, Risk & Compliance services build the policies, evidence habits and vendor management programs a clean Type II report depends on.
Yes. The SOC 2 Gap Assessment is a free, self-serve tool. You capture your company profile, choose the SOC 2 Type I or SOC 2 Type II assessment level, assess each AICPA Trust Services Criterion, and download a professional report with a remediation roadmap at no cost.
The Trust Services Criteria are the control criteria a licensed CPA firm uses in a SOC 2 examination, published by the AICPA. The current version is the 2017 Trust Services Criteria with Revised Points of Focus (2022). It contains 61 criteria in five categories: Security (the 33 Common Criteria, CC1 to CC9, mandatory in every SOC 2 report), Availability, Processing Integrity, Confidentiality, and Privacy.
Both levels assess all 61 Trust Services Criteria across the five categories. The SOC 2 Type I level is a point-in-time readiness review of how your controls stand today. The SOC 2 Type II level adds an Evidence (12 Months) field to every criterion, where you type or insert links to evidence artifacts covering the last 12 months, because a Type II examination tests that controls operated effectively over a review period, not just that they exist.
Each criterion is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).
The report includes an executive summary with your compliance score and top risks, detailed findings for every assessed Trust Services Criterion, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. At the SOC 2 Type II level your Evidence (12 Months) links are included in the detailed findings. It downloads in PDF or Word format with your company logo.
No. The tool runs entirely in your browser. Your answers and evidence links are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.
No. The assessment is a self-serve readiness working draft to support professional review and decision-making. A SOC 2 report can only be issued by a licensed CPA firm following an examination, and this independent tool is not affiliated with or endorsed by the AICPA. We recommend you seek advice from a Virtual CISO to validate findings, close the gaps, and prepare for the examination.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


