By Mike Chen, Director of IT Solutions · January 22, 2025

SOC 2 Readiness: The Honest 2025 Playbook

TL;DR: SOC 2 readiness is the work of closing the gap between your current control environment and what an AICPA-accredited auditor will actually test. Expect to pay $5,000 to $25,000 for a readiness assessment and $30,000 to $100,000+ for a Type II audit. Most mid-market companies need 6 to 12 months.

This guide is for IT Directors and CIOs at 50 to 500 employee companies who've just been told by a prospect, an insurer, or a board member that a SOC 2 report isn't optional anymore.

What SOC 2 Readiness Actually Means (And What It Costs)

A SOC 2 report comes in two flavors. Type I is a point-in-time snapshot. Your auditor reviews whether your controls are designed correctly on a given day. Type II observes whether those controls operated effectively over 6 to 12 months. Enterprise procurement teams almost always want Type II. Type I is a stepping stone, not a destination.

Readiness is everything that happens before you sign that audit engagement. Pricing in 2025, based on quotes I've reviewed from A-LIGN, Schellman, and Linford & Co:

For a deeper cost breakdown by company archetype, see our real SOC 2 certification cost breakdown.

The Five Trust Services Criteria: Which Ones Apply to You

The AICPA's 2017 Trust Services Criteria (revised 2022) define five categories:

  1. Security (mandatory, often called the Common Criteria or CC series)
  2. Availability
  3. Confidentiality
  4. Processing Integrity
  5. Privacy

Security is the only required criterion. The other four get scoped in based on what you've promised customers. A SaaS product touching PHI should add Privacy and Confidentiality. A platform with uptime SLAs in MSAs needs Availability. A payments processor needs Processing Integrity.

In my experience, the single most commonly failed area is CC6, logical access. Specifically CC6.2 (user access provisioning and review) and CC6.3 (access modification on role change). If you don't have a quarterly user access review with documented evidence, you're going to fail.

Gap Analysis: The Core of Any Readiness Assessment

A gap analysis produces a control matrix. One column lists each TSC requirement. The next lists your current state. The last lists what's missing and what it takes to remediate.

Auditors test four control families:

The three gaps I see most often at mid-market companies:

  1. No formal vendor management program. You can't name your subprocessors, and there's no annual review of SOC 2 reports from your critical vendors.
  2. Missing access review cadence. Provisioning works. Deprovisioning is sloppy. Terminated employees still have Okta accounts active 30 days later.
  3. No documented incident response runbook. When I ask "what happens if your billing database is encrypted at 11pm Friday," the answer is "we'd call somebody."

A gap analysis from Vanta or Drata is useful. It's not the same as a qualified third-party reviewer who actually understands control design. Tools tell you a control exists. A human tells you whether it's sufficient.

Manual Readiness vs. Automation Platforms: Honest Comparison

The big three compliance automation platforms:

What they do well: continuous evidence collection, integration with AWS/Azure/GCP/Okta/GitHub/Jira, auditor portals, policy templates, employee onboarding workflows.

What they don't do: replace a CPA firm's readiness assessment, evaluate whether your control design is sufficient, conduct penetration testing, or fix the underlying tooling gap if you don't have an EDR or SIEM in place.

My recommended stack for a mid-market SOC 2 effort:

One conflict-of-interest note: Vanta and Drata have built-in auditor marketplaces. A-LIGN, Schellman, and Linford & Co are common partners. That's convenient. It also means the platform has commercial relationships with the firm grading your evidence. Worth asking about. For a deeper look at the platforms, read our compliance automation software comparison.

Why Companies Fail or Delay After a Readiness Assessment

I see four patterns over and over.

Pattern 1: Scope set too narrowly. The readiness assessment covered the production environment. It didn't cover the marketing site's customer support tool, which processes ticket data containing customer PII. The auditor flags it during Type II observation. Now you're remediating in the middle of your audit window.

Pattern 2: Policies on paper, not in practice. Access reviews are documented in a policy. There's no Jira ticket, no signed evidence, no quarterly cadence. The auditor asks for the last four quarters of evidence. You have none.

Pattern 3: Pentest deferred. Most SOC 2 auditors expect at least one annual penetration test against the Security criterion. Companies assume the readiness assessment satisfies it. It doesn't. Scheduling and reporting a quality pentest takes 6 to 8 weeks. Build that into your timeline.

Pattern 4: No monitoring controls. Splunk Cloud for a 100-employee company typically runs $20,000 to $50,000/year. Datadog can be similar. Companies often skip this and hope log forwarding from CloudTrail satisfies CC7.1. It doesn't, especially not for 12 months retroactively when the observation period has already started.

Incidents do not pause for audit windows. An unresolved compromise inside the observation period undermines every control you evidence during it, which is why incident response capability belongs inside readiness scope rather than bolted on after the window opens.

Readiness Timeline by Company Size

Startup (10 to 50 employees, first SOC 2):

Mid-market (50 to 500 employees, legacy infrastructure):

Scope creep is the silent killer at mid-market. A prospect mid-cycle says "we also need Confidentiality and Privacy." You agree. Now your observation period restarts because you've added controls that haven't been operating for six months. Lock scope before starting observation.

If you're trying to figure out whether to staff this internally or outsource, our managed security services TCO guide walks through the math.

The CyberStar Readiness Approach

Our 5-Star Cyber Shield methodology maps directly to SOC 2:

Our public IR SLA: if you get breached Thursday night, we're on-site Friday morning. That isn't marketing. It's the only credible way to demonstrate CC7.3 to an auditor who's asking how you'd respond to an actual incident.

Important honesty: CyberStar is not a CPA firm. We are not your SOC 2 auditor. We handle technical control implementation and readiness. Your attestation comes from a licensed firm, often A-LIGN, Schellman, or Linford & Co. We work alongside them.

We work best with mid-market IT Directors in Nashville, Charlotte, Raleigh, Tampa, Columbus, and Denver who need actual technical remediation, not just a checklist handed to them by an automation tool. If you're in North Carolina, our SOC 2 compliance services in Charlotte page covers our scope there. Nashville teams can review our SOC 2 compliance services in Nashville for local engagement details.

If you're within 90 days of a SOC 2 or HIPAA audit and don't know where you stand, book a free 30-minute audit with Mike. We'll map your current controls against the TSC and tell you exactly what gaps will cost you.

FAQ

How long does a SOC 2 readiness assessment take? The assessment itself takes 2 to 6 weeks. Remediation adds 3 to 12 months depending on the size of the gaps. The Type II observation window then runs 6 to 12 months after remediation is complete.

Can I do a SOC 2 readiness assessment myself? You can use Vanta, Drata, or Secureframe for self-assessment. That's a useful starting point. An independent third-party review still catches control design flaws that automation tools miss, especially around CC6 access controls and CC7.3 incident response.

What is the difference between SOC 2 Type I and Type II? Type I is a point-in-time review of whether your controls are designed correctly. Type II tests whether those controls operated effectively over 6 to 12 months. Most enterprise customers require Type II.

How much does SOC 2 readiness cost? Readiness assessment: $5,000 to $25,000. Full Type II audit: $30,000 to $100,000+. Compliance automation platform: $10,000 to $25,000/year. Technical remediation varies by gap severity and existing tooling.

What happens if my readiness assessment finds major gaps? Remediating before starting the observation period is always cheaper than finding gaps during audit. Major gaps (no SIEM, no documented access reviews, no incident response runbook) typically add 3 to 6 months to the overall timeline.

Know exactly where your security stands.

Get your free security assessment →

Know exactly where your security stands.

Most IT directors are one audit away from a nasty surprise. We remove the guesswork.

Get your free security assessment

The assessment is free, and the plan is yours to keep.

Get your free security assessment →