Skip to content
Ridgeline Compliance
Read this first. We are not a CPA firm, so we provide SOC 2 readiness, gap analysis and preparation consulting only. The formal SOC 2 examination and report are performed by a separate, licensed, independent CPA firm.

Guide

A SOC 2 self assessment you can run this afternoon

A SOC 2 self assessment gives you a rough sense of how far you are from an examination. It cannot replace a gap assessment. However, it helps you decide how urgent the work is.

  • Readiness, not the audit
  • An independent CPA firm signs
  • Written estimate, no call
Soc 2 self assessment: answer honestly, count the gaps and decide next steps

How to run a SOC 2 self assessment

Answer each question with what you can prove, not what you intend. So if a control exists but leaves no record, mark it as missing.

The ten SOC 2 self assessment questions

These cover the areas where first audits most often fail.

  • Which criteria does the customer need?
  • Are our policies written and approved?
  • Is MFA enforced on key systems?
  • Is access reviewed quarterly?
  • Do leavers lose access on their last day?
  • Are production changes reviewed?
  • Does someone act on log alerts?
  • Is there a risk assessment?
  • Are key vendors reviewed?
  • Has a restore been tested?

Run the SOC 2 self assessment here

Tick only what you can prove today.

Your result appears here as you tick, so you can see what is still open.

Reading your score

Count the questions you answered yes, with proof. Then use the rough guide below.

Yes answersWhat it suggests
8 to 10Close to ready, so a short gap assessment fits.
4 to 7Typical first-timer, so plan remediation.
0 to 3Early stage, so start with scope and policies.

What a SOC 2 self assessment cannot tell you

It cannot judge whether your evidence would satisfy a CPA firm. Also, it cannot confirm scope, because that depends on the customer's request. So treat it as a starting point.

Next step

If several answers were no, a formal gap assessment is the efficient next step. It sits inside our fixed readiness fee, while the examination is always performed by a separate licensed CPA firm. Criteria: AICPA Trust Services Criteria.

Be strict with yourself when scoring. For example, an access review done once last year, with no record, should count as a no. Otherwise the score looks better than the reality, and the surprise arrives during the examination instead, when it costs most.

SOC 2 self assessment questions

Is a SOC 2 self assessment accepted by customers?

No. Customers want a report from a licensed CPA firm.

How accurate is a self assessment?

Rough, because people tend to count intentions as controls.

Should we repeat the SOC 2 self assessment?

Yes, quarterly during readiness, so progress is visible.

What comes after it?

Usually a formal gap assessment and a remediation plan.

Related guides

Turn your self-check into a real plan

Send your answers with the scoping form. We reply with a written scope and price range.

See if we can help