SOC 2 Readiness Assessment
Answer 13 quick questions about your security controls and see where you stand, from just getting started to nearly audit-ready. No signup, and your results show on the spot.
0 of 13 answered
Access & Identity
1. You review who has access to production systems on a regular schedule.
Access & Identity
2. Multi-factor authentication is required for production and administrative systems.
Access & Identity
3. You have a defined process to grant and revoke access when people join or leave.
Data Protection
4. Customer data is encrypted both at rest and in transit.
Data Protection
5. You have a data retention and disposal practice in place.
Governance & People
6. Your core security policies (information security, access control, incident response) are written and approved.
Governance & People
7. New hires receive security training, and you run background checks where appropriate.
Change & Vulnerability
8. Code changes go through review before they reach production.
Change & Vulnerability
9. You scan for vulnerabilities and track them through to resolution.
Resilience & Incidents
10. You have a documented incident response plan, and you have tested it.
Resilience & Incidents
11. Critical data is backed up, and you have a recovery plan.
Vendors
12. You track the vendors that handle customer data and review their security.
Evidence
13. You keep evidence (logs, reviews, approvals) showing these controls actually run.
New to the framework? Start with the SOC 2 guides, or read how to start a compliance program.