Skip to content
Ridgeline Compliance
Read this first. We are not a CPA firm, so we provide SOC 2 readiness, gap analysis and preparation consulting only. The formal SOC 2 examination and report are performed by a separate, licensed, independent CPA firm.

Service

A SOC 2 gap assessment ranked by what fails first

A SOC 2 gap assessment is a line-by-line comparison of your controls against the criteria in scope. So instead of a vague worry, you get a list of exactly what is missing.

  • Readiness, not the audit
  • An independent CPA firm signs
  • Written estimate, no call
Soc 2 gap assessment: map the criteria, compare controls and rank the gaps

How a SOC 2 gap assessment works

We take each criterion in scope and ask two questions. First, does a control exist? Second, can you prove it ran? A control that exists but leaves no evidence is still a gap, because an auditor needs proof.

Common gaps we find

Most first-time companies share the same handful of gaps. Therefore we check these early.

  • No written risk assessment
  • Access reviews that never happen
  • Offboarding that leaves accounts active
  • Changes deployed without review
  • No vendor list or vendor review

Mini SOC 2 gap assessment

Tick what you can prove today, not just what you do. Evidence is what counts.

Your result appears here as you tick, so you can see what is still open.

How gaps are ranked in a SOC 2 gap assessment

Not every gap matters equally. So each one is ranked by how likely it is to fail the examination.

RankMeaning
FailWould fail the examination, so fix first.
WeakExists but lacks evidence.
MinorDocumentation tidy-up.

Gap assessment versus readiness assessment

People use the terms loosely. However, the gap assessment is the comparison itself, while readiness includes deciding scope and planning fixes. In practice, both are part of our first stage, which takes two to four weeks.

After the SOC 2 gap assessment

We close the gaps with your engineers, rather than sending a report and leaving. Meanwhile, evidence starts collecting, which is what a Type II watch period later measures. The criteria are set out in the AICPA Trust Services Criteria.

One practical tip helps here. Collect evidence while you fix each gap, rather than at the end, because a Type II later measures months of it. So the gap list doubles as an evidence plan.

SOC 2 gap assessment questions

How long does a SOC 2 gap assessment take?

Usually two to four weeks, depending on scope and how much is documented.

Do you need access to our systems?

Read-only access and screenshots are usually enough, so production is not touched.

Will the SOC 2 gap assessment tell us if we pass?

It tells you what is missing. However, only the CPA firm forms the opinion.

What if we have no policies at all?

That is common, so we write policies that match your real stack.

Related guides

Start your SOC 2 gap assessment

Tell us the criteria and team size. We reply with a written scope and a fixed fee.

See if we can help