SOC 2 & ISO 27001 Readiness Assessment
Answer a short control-by-control checklist and get an instant readiness score, your gap list, and exactly what to fix before you engage an auditor.
Multi-factor authentication is enforced on all critical systems, admin accounts and email.
User access is reviewed and documented at least quarterly.
Access is revoked within one business day when someone leaves.
Sensitive data is encrypted both at rest and in transit.
Security logs are centralized and you alert on suspicious events.
You scan for vulnerabilities regularly and patch on a defined timeline.
Code and infrastructure changes are peer-reviewed and tracked.
Backups run automatically and you have tested restoring from them.
You have a written incident-response plan, tested in the last 12 months.
Critical vendors and subprocessors get a documented security review.
Security policies are documented, approved, and acknowledged by staff.
Staff complete security-awareness training at least annually.
You keep a current inventory of systems, assets and data.
A formal risk assessment is performed and documented at least annually.
0/14 answered — answer all to see your readiness score.
This is a directional self-assessment, not an audit or a guarantee of certification. Your real readiness depends on scope, evidence quality and your auditor. Nothing you enter leaves your browser.
Readiness, explained
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment is a gap analysis you run before engaging an auditor: you check your current controls against what a SOC 2 audit expects — access control, change management, monitoring, incident response and so on — to find and close gaps first. This free tool gives you a directional readiness score and a prioritised list of gaps in a few minutes, so you fix issues before they become audit exceptions.
How do I know if I am ready for a SOC 2 or ISO 27001 audit?
You are close to ready when your core controls are not just in place but documented and consistently operating: MFA everywhere, quarterly access reviews, encryption at rest and in transit, centralised logging with alerting, peer-reviewed changes, tested backups, a tested incident-response plan, vendor reviews and approved policies. This assessment scores you across exactly those areas and flags the ones that still need work.
What is the difference between a SOC 2 and ISO 27001 readiness check?
The two frameworks share most of their underlying controls, so a readiness check looks similar for both. ISO 27001 additionally expects a formal ISMS with defined scope and a Statement of Applicability (SoA) plus a risk-treatment plan, which this tool surfaces when you select ISO 27001. SOC 2 places more emphasis on the Trust Services Criteria and the operating effectiveness of controls over a period.
How long does it take to get from a gap assessment to audit-ready?
For a startup or SMB with a few gaps, it is typically weeks; from a low starting score it can be several months. The two big accelerators are automating evidence collection (so controls prove themselves continuously instead of you screenshotting quarterly) and cross-mapping one control to many frameworks. A platform like CATAAM does both.
Is this assessment a substitute for an actual audit?
No. It is a directional self-assessment to help you prioritise. A SOC 2 attestation or ISO 27001 certificate still requires an independent auditor or certification body. What this tool — and CATAAM — do is get you audit-ready faster and cheaper, so the auditor finds fewer exceptions.