Free Tool

SOC 2 Readiness Assessment

Answer 13 quick questions about your security controls and see where you stand, from just getting started to nearly audit-ready. No signup, and your results show on the spot.

0 of 13 answered

  1. Access & Identity

    1. You review who has access to production systems on a regular schedule.

  2. Access & Identity

    2. Multi-factor authentication is required for production and administrative systems.

  3. Access & Identity

    3. You have a defined process to grant and revoke access when people join or leave.

  4. Data Protection

    4. Customer data is encrypted both at rest and in transit.

  5. Data Protection

    5. You have a data retention and disposal practice in place.

  6. Governance & People

    6. Your core security policies (information security, access control, incident response) are written and approved.

  7. Governance & People

    7. New hires receive security training, and you run background checks where appropriate.

  8. Change & Vulnerability

    8. Code changes go through review before they reach production.

  9. Change & Vulnerability

    9. You scan for vulnerabilities and track them through to resolution.

  10. Resilience & Incidents

    10. You have a documented incident response plan, and you have tested it.

  11. Resilience & Incidents

    11. Critical data is backed up, and you have a recovery plan.

  12. Vendors

    12. You track the vendors that handle customer data and review their security.

  13. Evidence

    13. You keep evidence (logs, reviews, approvals) showing these controls actually run.

New to the framework? Start with the SOC 2 guides, or read how to start a compliance program.