SOC2 Gap Assessment - IRM Consulting & Advisory
IRM Product

SOC2 Gap Assessment

The SOC2 Gap Assessment is a free tool that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022) used in SOC2 examinations. Assess all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy at the SOC2 Type I or SOC2 Type II level; generate a downloadable report that includes a remediation roadmap.

  • All 61 AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy)
  • Risk-ranked gaps & remediation roadmap
  • FREE, built by an AI-Native vCISO for SMBs

What is the SOC2 Gap Assessment?

The SOC2 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), the control criteria a licensed CPA firm uses in a SOC2 examination.

You choose your level: SOC2 Type I assesses all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy as a point-in-time readiness review, and SOC2 Type II assesses the same criteria and adds an Evidence (12 Months) field to every criterion so you can insert links to evidence artifacts covering the last 12 months. You assess each criterion, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.

What is SOC 2?

SOC 2 (System and Organization Controls 2, often written SOC2) is an assurance framework from the American Institute of Certified Public Accountants (AICPA) in which a licensed CPA firm examines a service organization's controls against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A SOC2 Type I report covers how controls are designed at a point in time, while a SOC2 Type II report covers how those controls operated over a period, typically 6 to 12 months. SOC2 is an attestation report rather than a certification, and it has become the de facto security credential SaaS companies need to sell to enterprise customers.

What you get

  • A Gap Assessment against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), the control criteria used in SOC2 examinations
  • Two assessment levels: SOC2 Type I and SOC2 Type II both cover all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy; Type II adds an Evidence (12 Months) field to every criterion for links to evidence artifacts covering the last 12 months
  • Likelihood and impact scoring for every gap on a 5x5 risk matrix
  • Gaps ranked Low, Medium, High, or Critical
  • An Executive Summary with your compliance score and top risks
  • A phased remediation roadmap across 30, 90, 180, and 365 day horizons, downloadable in PDF or Word format with your company logo

Who it is for

The assessment is built for small and medium organizations, startups, and growing SaaS companies that face customer security questionnaires or enterprise procurement requirements and want to understand where they stand against the Trust Services Criteria before engaging a CPA firm.

The SOC2 Type I level is the right starting point for teams preparing for their first examination, while the SOC2 Type II level suits teams heading into an operating-effectiveness review period who need to start collecting and organizing 12 months of evidence.

How it works

Step 1

Capture your Company Profile

Enter your company name, website, and a description of what the company does, choose the SOC2 Type I or SOC2 Type II assessment level, and add your logo for the report.

Step 2

Assess each Trust Services Criterion

Work through all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy, mark each one compliant, partially compliant, non-compliant, or not applicable, rate the likelihood and impact of each gap, and at the Type II level insert links to evidence artifacts covering the last 12 months.

Step 3

Download your Report and Remediation Roadmap

Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.

Not loading? Open the SOC2 Gap Assessment tool in a new tab.

This assessment is a self-serve working draft to support professional review and decision-making. It is not a SOC2 examination, attestation, certification or legal advice, and it is not affiliated with or endorsed by the AICPA. We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.

SOC2 Gap Analysis explained

A SOC2 gap analysis, also called a gap assessment, is a structured comparison of your organization's current controls against the AICPA Trust Services Criteria, identifying which criteria you already meet, where you fall short, and what to fix first. It is the standard starting point for any SOC2 readiness project, run before you engage a CPA firm so the formal examination holds no surprises.

A good gap assessment, sometimes called a SOC2 readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which Trust Services Categories belong in your report scope, given what you commit to customers about security, availability, processing integrity, confidentiality, and privacy? Secondly, Conformance: for each criterion, do you have the control, the documentation, and the evidence an auditor would sample?

Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your compliance obligations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.

SOC2 Type I vs SOC2 Type II

A SOC2 Type I report opines on whether your controls are suitably designed and implemented at a single point in time. A SOC2 Type II report goes further: it opines on whether those controls operated effectively over a review period, commonly 3 to 12 months, which is why Type II is what enterprise customers usually require. Both report types are examinations of the same Trust Services Criteria; the difference is the evidence. That is exactly how the tool on this page treats them: both levels assess all 61 criteria, and the Type II level adds an Evidence (12 Months) field to every criterion so you can capture links to the artifacts that prove each control operated over the last 12 months.

Comparison of SOC2 Type I and SOC2 Type II
SOC2 Type ISOC2 Type II
What the auditor opines onThe design and implementation of your controls at a single point in time.The design, implementation, and operating effectiveness of your controls over a review period, commonly 3 to 12 months.
Evidence requiredEvidence that each control exists and is suitably designed as of the review date, such as policies, configurations, and walkthroughs.Evidence that each control operated throughout the period: access review records, change tickets, incident records, monitoring reports, and training logs sampled across the full window.
How this tool maps to itThe SOC2 Type I level assesses all 61 Trust Services Criteria as a point-in-time readiness review.The SOC2 Type II level assesses the same 61 criteria and adds an Evidence (12 Months) field to every criterion, so you can capture links to the artifacts that prove each control operated over the last 12 months.
Typical timelineFaster: readiness, remediation, then a point-in-time examination.Longer: an observation period must elapse before the examination, so evidence collection discipline matters from day one.
Who usually asks for itEarly-stage customers and partners who need initial assurance quickly.Enterprise customers and procurement teams, who usually expect a Type II report renewed annually.

What the five Trust Services Categories cover

The 2017 Trust Services Criteria (with Revised Points of Focus, 2022) contain 61 criteria organized into five categories. Security, expressed as the 33 Common Criteria CC1 to CC9, is mandatory in every SOC2 examination; the other four categories are added to the report scope based on the commitments you make to customers. This assessment covers all five categories so nothing is missed when you decide your report scope.

The five Trust Services Categories and what they cover
CategoryCriteria seriesCriteriaWhat it covers
SecurityCC1 to CC933The Common Criteria, mandatory in every SOC2 examination: control environment, communication and information, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, and risk mitigation.
AvailabilityA13Capacity management, environmental protections, data backup and recovery infrastructure, and recovery plan testing that keep the system available per your commitments and SLAs.
Processing IntegrityPI15Processing specifications plus controls over system inputs, processing, outputs, and stored items so processing is complete, valid, accurate, timely, and authorized.
ConfidentialityC12Identifying, protecting, retaining, and verifiably disposing of confidential information in line with your confidentiality commitments.
PrivacyP1 to P818Notice, choice and consent, collection, use, retention and disposal, data subject access, disclosure and breach notification, data quality, and privacy dispute handling and compliance monitoring for personal information.

How the Evidence (12 Months) field prepares you for Type II

The single biggest cause of SOC2 Type II findings is not missing controls, it is missing evidence: the control operated, but nobody can produce the access review, the change ticket, or the test result from eight months ago. At the Type II level, this tool adds an Evidence (12 Months) field to every criterion where you type or insert links to the artifacts that demonstrate operation over the last 12 months, for example policy documents, ticketing queries, monitoring reports, or folders in SharePoint, Google Drive, or your GRC platform.

Your evidence links are included against each criterion in the Detailed Findings section of the downloadable report, giving you a working evidence index you can hand to your auditor at the start of fieldwork, and an immediate view of which controls are operating without a paper trail. Criteria with no evidence link are your earliest warning of a Type II exception.

Trust Services Criteria Series Reference

The table below summarizes each criteria series in the 2017 Trust Services Criteria and the evidence auditors typically expect to see. The summaries are condensed guidance prepared by IRM Consulting & Advisory, not verbatim AICPA criteria text; the assessment tool above walks you through all 61 criteria at either level.

Trust Services Criteria series summaries and typical audit evidence
SeriesAreaSummaryEvidence auditors expect
CC1Control EnvironmentDemonstrate integrity and ethical values, board oversight, defined structures and reporting lines, commitment to competence, and individual accountability for internal control.Code of conduct, org chart, board minutes, job descriptions, training and performance records.
CC2Communication and InformationGenerate and use quality information for internal control, communicate objectives and responsibilities internally, and communicate commitments and incidents to external parties.System description, policy portal, security awareness communications, customer notifications, whistleblower channel.
CC3Risk AssessmentSpecify clear objectives, identify and analyse risks including fraud risk, and assess changes that could significantly impact internal control.Risk assessment procedure, risk register, fraud risk analysis, change impact assessments.
CC4Monitoring ActivitiesPerform ongoing and separate evaluations of internal control and communicate deficiencies to those responsible for corrective action.Vulnerability scans, penetration test reports, internal audit reports, deficiency tracking.
CC5Control ActivitiesSelect and develop control activities including general controls over technology, and deploy them through policies and procedures.Control matrix, approved policies and procedures with owners and review dates.
CC6Logical and Physical Access ControlsRestrict logical and physical access to protected information assets: identity management, authentication, least privilege, access reviews, physical security, secure disposal, boundary protection, encryption, and anti-malware.Access control policy, MFA configuration, joiner-mover-leaver tickets, access review records, badge logs, disposal certificates, encryption settings.
CC7System OperationsDetect configuration changes and vulnerabilities, monitor for anomalies and security events, evaluate and respond to incidents, and recover from them.Monitoring and alerting configuration, SIEM reports, incident response plan, incident records and post-mortems, response test results.
CC8Change ManagementAuthorize, design, test, approve, and implement changes to infrastructure, data, software, and procedures.Change management policy, change tickets with approvals and test evidence, emergency change reviews.
CC9Risk MitigationDevelop risk mitigation activities for business disruptions and manage risks associated with vendors and business partners.Business continuity plan, insurance review, vendor inventory, vendor due diligence and periodic review records.
A1AvailabilityManage processing capacity, implement environmental protections, backups and recovery infrastructure, and test recovery plans.Capacity monitoring dashboards, backup configuration and restoration tests, BC/DR test results.
PI1Processing IntegrityDefine processing specifications and control system inputs, processing, outputs, and stored items for complete, accurate, timely, authorized processing.Data definitions, input validation rules, processing error and reconciliation reports, output delivery controls.
C1ConfidentialityIdentify and maintain confidential information, and dispose of it in a manner that prevents recovery when no longer needed.Data classification policy, retention schedule, destruction and erasure records.
P1 to P8PrivacyProvide notice, obtain consent, limit collection and use, retain and dispose securely, grant data subject access and correction, control disclosures with breach notification, maintain data quality, and handle privacy inquiries, complaints and disputes.Privacy notice, consent records, retention schedule, DSAR process records, disclosure logs, breach notification procedure, complaint register.

Closing the gaps is where most organizations want help. IRM's Virtual CISO services take teams from gap assessment through certification readiness for SOC2, ISO 27001, ISO 42001 and CMMC, and our Governance, Risk & Compliance services build the policies, evidence habits and vendor management programs a clean Type II report depends on.

floating circle
Frequently Asked Questions

SOC2 Gap Assessment FAQs

Yes. The SOC 2 Gap Assessment is a free, self-serve tool. You capture your company profile, choose the SOC 2 Type I or SOC 2 Type II assessment level, assess each AICPA Trust Services Criterion, and download a professional report with a remediation roadmap at no cost.

The Trust Services Criteria are the control criteria a licensed CPA firm uses in a SOC 2 examination, published by the AICPA. The current version is the 2017 Trust Services Criteria with Revised Points of Focus (2022). It contains 61 criteria in five categories: Security (the 33 Common Criteria, CC1 to CC9, mandatory in every SOC 2 report), Availability, Processing Integrity, Confidentiality, and Privacy.

Both levels assess all 61 Trust Services Criteria across the five categories. The SOC 2 Type I level is a point-in-time readiness review of how your controls stand today. The SOC 2 Type II level adds an Evidence (12 Months) field to every criterion, where you type or insert links to evidence artifacts covering the last 12 months, because a Type II examination tests that controls operated effectively over a review period, not just that they exist.

Each criterion is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).

The report includes an executive summary with your compliance score and top risks, detailed findings for every assessed Trust Services Criterion, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. At the SOC 2 Type II level your Evidence (12 Months) links are included in the detailed findings. It downloads in PDF or Word format with your company logo.

No. The tool runs entirely in your browser. Your answers and evidence links are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.

No. The assessment is a self-serve readiness working draft to support professional review and decision-making. A SOC 2 report can only be issued by a licensed CPA firm following an examination, and this independent tool is not affiliated with or endorsed by the AICPA. We recommend you seek advice from a Virtual CISO to validate findings, close the gaps, and prepare for the examination.

Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.