SOC 2 Readiness Assessment vs Formal Gap Analysis
A readiness assessment defines your scope and system first, then a gap analysis finds what to fix.

Two terms get thrown around interchangeably in SOC 2 vendor pitches and audit firm sales decks: gap analysis and readiness assessment. They are not the same thing, and starting with the wrong one costs an organization weeks of runway and thousands of dollars it didn't need to spend. Most companies default to the gap analysis because it's cheaper and faster to book, then find out mid-audit that nobody ever defined the system boundary the auditor needs. For any company without existing scaffolding, that's the wrong order to go in, and the rest of this piece explains why.
What the SOC 2 framework actually requires organizations to prove
SOC 2 is not a law. No regulator enforces it, and no government agency issues fines for failing it. It's an attestation framework built by the AICPA, and companies pursue it because customers, usually enterprise buyers, demand proof of security discipline before they'll sign a contract.
The framework rests on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only one required in every SOC 2 report. The other four get picked based on what the organization actually promises its customers. A payments company handling financial data probably needs Processing Integrity. A healthtech platform storing patient records likely needs Confidentiality and Privacy layered in too.
Report type matters just as much as which criteria get chosen. A Type I report checks whether controls are designed correctly at one moment in time, a snapshot. A Type II report checks whether those same controls actually worked across a window, typically at least several months, and demands far more evidence: logs, tickets, access reviews, the whole operational trail behind the claim.
Whichever type an organization pursues, the opinion letter attached to the final report is what procurement teams actually read. It either confirms the controls held up against each criterion, or it flags where they didn't. A qualified opinion, meaning controls failed somewhere during the observation window, can sink an enterprise deal even after the company technically holds a SOC 2 certificate. That downstream risk is exactly what pre-audit work exists to head off.
What a gap analysis does and what it produces
A gap analysis is a structured comparison, not a vague gut check on "how secure are we." Current security controls get mapped against the AICPA Trust Services Criteria, and each one gets scored: Met, Partial, or Not Met. It's mechanical in the best sense, a checklist run with rigor.
A thorough gap analysis, per Thoropass's 2025 guide, looks at four things. What data gets processed, sorted by sensitivity and regulatory obligation. Where that data physically or virtually sits, mapped across infrastructure and vendor systems. How data moves, traced through actual network architecture diagrams rather than assumed from memory. And who can touch it: roles, access controls, provisioning logic.
The work goes past reading policy documents. It includes technical review of software configurations and network setups, interviews with security and HR staff, and a look at the broader risk landscape the organization sits inside. The output is a prioritized remediation roadmap, not a certificate, and not anything shown to customers.
Timing runs one to four weeks for the assessment itself, depending on company size, according to ComplyJet. Remediation of whatever gets found adds weeks or months on top of that. Catching problems here rather than later matters structurally, because gaps found internally stay private and fixable, while exceptions found during a formal SOC 2 Type II audit end up written into the customer-visible report. Bright Defense, in a July 2026 update, put the first-attempt failure rate for organizations skipping a prior gap assessment at over 70% for Type I audits. That's most companies walking in blind.
What a readiness assessment adds that a standalone gap analysis does not cover
When a service auditor runs a readiness assessment, the gap analysis sits inside it as one piece, not the whole exercise. The readiness assessment goes further, and it's the part most vendors skip past in a sales pitch.
It starts with scope definition: the service organization has to draw exact boundaries around the system under review, not the entire company, but the specific system tied to one or more service lines sold to customers. It also covers system description drafting, a document laying out background on the organization, the scope and boundaries just defined, and a detailed account of every relevant process and control. Every control included in the SOC 2 has to show up here in enough detail that an outside reader understands it without a walkthrough.
Report type selection happens at this stage too, Type I versus Type II, based on what customers are actually asking for and how much runway the organization has. Evidence preparation follows, making sure documentation is organized and audit-ready before the formal engagement starts. The process closes with a dry-run review, a final check that controls are working as expected before the real audit begins.
Most people underrate the system description. An unclear one is a well-documented cause of audit delays and scope overruns, so it functions as load-bearing work, not a paperwork afterthought tacked on at the end.
Schellman states that when a service auditor runs a readiness assessment, they're checking preparedness against SOC 2 criteria and handing back a deliverable meant for internal remediation, not an audit opinion. That distinction matters. Readiness assessments check whether controls actually function day to day, not just whether they exist on paper somewhere, whether evidence is organized enough to hand over, and whether the people who own each process actually understand what they're on the hook for.
Readiness isn't mandatory. An organization can walk straight into a Type I or Type II audit without one, and some do, against their own interest. Organizations skipping readiness typically find their significant gaps during fieldwork instead, which is the most expensive and slowest place to find them. Fieldwork is where the auditor's clock is running and the fix has to happen live, in front of the person writing the opinion.
How to decide which one to start with, and when to do either
Skip the standalone gap analysis if there's no existing control documentation, no system description, and no prior mapping of data flows. Go straight to a full readiness assessment instead. A gap analysis alone would hand back a list of findings, but findings without a scope definition or a system description to remediate against just sit there unused. Nobody knows what to fix first because nobody's defined what "the system" even means yet.
An organization that already has a defined scope, a working security program, and is heading into a Type II renewal doesn't need that scaffolding rebuilt from scratch. A focused gap analysis against the Trust Services Criteria catches what's drifted since the last cycle, and that's enough on its own.
Per ComplyJet's May 2026 guide, four business situations tend to trigger the decision. An enterprise RFP lists SOC 2 as a hard requirement, an approaching Type II renewal has the existing report nearing its twelve-month mark, a material infrastructure change shifts the system boundary, or a new service line expands what the organization promises customers.
The stakes go past compliance for its own sake. Fraxtional's May 2026 analysis put the average enterprise deal at six to ten stakeholders involved in the decision, with B2B buying timelines stretching 54 days longer between 2021 and 2024. Security concerns have caused businesses to walk away from vendor relationships, making the assessment as much a sales tool as a compliance one. A gap assessment works as a sales tool as much as a compliance one, because the alternative is losing a deal mid-cycle over a question procurement should never have had to ask in the first place.
The industries where this comes up most: SaaS companies selling into enterprise accounts, cloud infrastructure and hosting providers, managed service providers, fintech platforms whose banking partners require it, healthtech companies layering SOC 2 alongside HIPAA, and HR tech or legal tech handling sensitive personal data. Timing matters as much as the choice itself. Either process should wrap with enough runway left to fix what it finds before the audit's observation period starts, since remediation commonly takes additional months beyond the assessment itself.
The control failures that gap analyses and readiness assessments most reliably surface
Certain failures show up again and again. Thoropass's 2025 guide points to a recurring list: access controls that grant too much privilege and don't get cleaned up after employees leave, risk assessment processes that exist in name only, weak or absent oversight of third-party vendors, informal change management, thin vulnerability management, and logging or monitoring that doesn't actually catch anything when something goes wrong.
Change management deserves a closer look, because it's the failure that catches teams by surprise. CC8.1 requires a formal change approval workflow before anything gets deployed to production. Self-approvals, where a developer pushes their own code with no second reviewer, break segregation of duties. It is a commonly cited finding across Type II reports. It's an easy failure to understand once you see it: nobody meant to skip the review, the process just never got written down formally enough to enforce.
Vendor risk sits as a structural blind spot for most organizations pursuing SOC 2. An annual data breach report found that 62% of breaches involved a third party somewhere in the chain. Yet most companies going through a gap analysis for the first time have no formal vendor inventory, no tiering by risk level, and have never once asked a critical vendor for its own SOC 2 report.
Multi-factor authentication turns up as a persistent gap even among organizations that consider themselves mature. Konfirmity, reporting on audits run over the prior twelve months, found that 63% of clients coming from modern GRC platforms still had a gap in proving continuous control effectiveness, often on something as basic as MFA on email and cloud accounts. Having the control exist and proving it worked continuously turn out to be two different problems, and auditors only care about the second one.
Incident response documentation rounds out the list. Auditors want evidence that response capabilities were actually tested, not just described in a policy binder somewhere. Gaps show up when incidents go undocumented, tabletop exercises never happen, or nobody's clear on who owns response when something breaks. A quiet year with no incidents doesn't prove readiness on its own; auditors need to see the muscle exercised, not just assumed dormant. ComplyJet's May 2026 figures put the gap rate for first-time SOC 2 pursuers between 40% and 60%, which means most companies walking into their first audit carry deficiencies they don't yet know they have.
What assessments cost and what skipping them actually costs
Pricing varies by scope and who's doing the work. Readiness assessments run $3,000 to $15,000, according to Compyl. Consultant-led gap assessments for a company in the 50 to 100 person range run $15,000 to $25,000, per Scrut. GRCTrail, in a March 2026 breakdown, puts an external consultant's structured gap analysis, meaning evaluation of controls, policies, and evidence against SOC 2 requirements plus a prioritized remediation plan, at $5,000 to $15,000.
Remediation costs stack on top of those fees. Closing gaps, new access control systems, mobile device management, better logging, policy rewrites, commonly adds $5,000 to $50,000 depending on how much security infrastructure already exists, per Compyl's August 2026 figures. Compliance automation tools cut that remediation effort by 60% to 80%, according to ComplyJet, which changes the math considerably for organizations willing to spend on tooling upfront instead of paying consultants by the hour.
Skipping the assessment defers the cost to later. It just moves the cost downstream and multiplies it. Treat the assessment fee as a mandatory line item inside the real security budget, the cheap branch of that decision tree, not an optional add-on sitting beside it.
On the other side of the ledger, it is worth noting that a SOC 2 report with zero exceptions, zero qualifications, nothing flagged, is not automatically the strongest possible outcome. Real security programs surface exceptions, because real operations aren't perfect, and a spotless report can invite questions about audit scope rather than confidence in the result.
How 2026 changes to auditor guidance affect what a gap analysis needs to cover
Several shifts changed what a gap analysis has to account for going into 2026. Organizations juggling more than one compliance regime increasingly need their gap analysis to account for overlapping requirements across frameworks, making multi-framework coverage a practical necessity rather than an advanced option.
The line between Confidentiality and Privacy also sharpened, following the AICPA's 2022 update, according to ComplyJet's account, though the source doesn't spell out exactly how the two criteria now diverge beyond naming the update itself. Supply chain risk, along with emerging technology considerations, got folded explicitly into the AICPA's 2022 Points of Focus guidance. Vendor risk management is no longer a secondary checkbox tacked onto the end of a gap analysis; it's part of the core mapping exercise now, and any gap analysis that still treats it as an afterthought is running on an outdated template.
Running controls through multiple frameworks at once, rather than one at a time in sequence, cuts total compliance effort meaningfully for organizations that answer to more than one standard. The bigger shift underway is toward continuous monitoring. The old model, a gap analysis as a single point-in-time snapshot, is giving way to real-time detection of control drift, which keeps the gap register current instead of accurate only on the day the assessment wrapped. Organizations heading into a Type II renewal should treat gap analysis as something ongoing, not a task closed out once a year and forgotten about until the next one comes due.
Scope decisions made back in 2024, before the Confidentiality/Privacy distinction sharpened and before supply chain guidance became explicit, probably undercount both the criteria and the vendor relationships auditors are now prepared to scrutinize closely.
How to run either process, and what to expect from each phase
A readiness assessment, per Clark Nuber PS's May 2026 outline, moves through a set sequence. Scope definition comes first: deciding which systems, services, and controls actually fall under review. Documenting that scope early matters, since an unclear boundary is the single most common cause of delays and overruns later in the audit. Report type selection follows, Type I or Type II, chosen against customer demands and the organization's own timeline.
Then comes the gap assessment itself, comparing current policy and practice against SOC 2 requirements, the diagnostic piece embedded inside the larger readiness process. Remediation follows: strengthening documentation, training staff, fixing whatever controls fell short. The sequence closes with a final review, a dry run confirming every control operates as expected before the formal audit actually begins.
Who runs each piece varies. A gap analysis can be handled internally or brought in through a third party; it's voluntary either way and produces no attestation. A readiness assessment typically comes from the same service auditor who'll later run the formal exam, or from a specialist advisory firm working alongside them. The actual Type I or Type II audit, though, has to come from a licensed CPA firm. That's the only step in the whole sequence that produces the official opinion procurement teams will eventually read, and no amount of internal prep substitutes for it.
Evidence organization is the phase most companies underestimate going in. Process owners need to know, ahead of time, exactly what documentation proves their control worked, not just that some policy exists somewhere in a folder nobody's opened since the day it got written.
Sources
- Your complete 2025 guide to SOC 2 gap analysis - Thoropass
- What is a SOC 2 Gap Assessment?
- SOC 2 Gap Analysis (2026): How to Assess & Close Every Compliance Gap Before Your Audit
- What to Expect from a SOC 2 Readiness Assessment | Schellman
- SOC 2 Gap Analysis: Identifying and Closing Compliance Gaps
- konfirmity.com
- compyl.com
- grctrail.com


