Free tool · no signup

SOC 2 & ISO 27001 Readiness Assessment

Answer a short control-by-control checklist and get an instant readiness score, your gap list, and exactly what to fix before you engage an auditor.

Access control

Multi-factor authentication is enforced on all critical systems, admin accounts and email.

Access control

User access is reviewed and documented at least quarterly.

Access control

Access is revoked within one business day when someone leaves.

Data protection

Sensitive data is encrypted both at rest and in transit.

Monitoring

Security logs are centralized and you alert on suspicious events.

Vulnerability mgmt

You scan for vulnerabilities regularly and patch on a defined timeline.

Change management

Code and infrastructure changes are peer-reviewed and tracked.

Resilience

Backups run automatically and you have tested restoring from them.

Incident response

You have a written incident-response plan, tested in the last 12 months.

Vendor risk

Critical vendors and subprocessors get a documented security review.

Governance

Security policies are documented, approved, and acknowledged by staff.

Governance

Staff complete security-awareness training at least annually.

Governance

You keep a current inventory of systems, assets and data.

Risk management

A formal risk assessment is performed and documented at least annually.

0/14 answered — answer all to see your readiness score.

This is a directional self-assessment, not an audit or a guarantee of certification. Your real readiness depends on scope, evidence quality and your auditor. Nothing you enter leaves your browser.

Readiness, explained

What is a SOC 2 readiness assessment?

A SOC 2 readiness assessment is a gap analysis you run before engaging an auditor: you check your current controls against what a SOC 2 audit expects — access control, change management, monitoring, incident response and so on — to find and close gaps first. This free tool gives you a directional readiness score and a prioritised list of gaps in a few minutes, so you fix issues before they become audit exceptions.

How do I know if I am ready for a SOC 2 or ISO 27001 audit?

You are close to ready when your core controls are not just in place but documented and consistently operating: MFA everywhere, quarterly access reviews, encryption at rest and in transit, centralised logging with alerting, peer-reviewed changes, tested backups, a tested incident-response plan, vendor reviews and approved policies. This assessment scores you across exactly those areas and flags the ones that still need work.

What is the difference between a SOC 2 and ISO 27001 readiness check?

The two frameworks share most of their underlying controls, so a readiness check looks similar for both. ISO 27001 additionally expects a formal ISMS with defined scope and a Statement of Applicability (SoA) plus a risk-treatment plan, which this tool surfaces when you select ISO 27001. SOC 2 places more emphasis on the Trust Services Criteria and the operating effectiveness of controls over a period.

How long does it take to get from a gap assessment to audit-ready?

For a startup or SMB with a few gaps, it is typically weeks; from a low starting score it can be several months. The two big accelerators are automating evidence collection (so controls prove themselves continuously instead of you screenshotting quarterly) and cross-mapping one control to many frameworks. A platform like CATAAM does both.

Is this assessment a substitute for an actual audit?

No. It is a directional self-assessment to help you prioritise. A SOC 2 attestation or ISO 27001 certificate still requires an independent auditor or certification body. What this tool — and CATAAM — do is get you audit-ready faster and cheaper, so the auditor finds fewer exceptions.