What a SOC 2 readiness assessment is
SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria. A readiness assessment is the step before it: you compare how you actually work with what the criteria require, and fix the gaps before an auditor tests them. Every gap you close now is one fewer exception written into the report your customers read.
Type I vs Type II
| Type I | Type II | |
|---|---|---|
| What it tests | Controls are designed properly | Controls operated effectively |
| Period | A single date | An observation window, usually 3–12 months |
| Who asks for it | Early deals, a first step | Most enterprise security reviews |
| Evidence | Policies and configurations | Samples across the whole window: tickets, reviews, alerts, changes |
Many teams do a Type I first to unblock a deal, then start the Type II window straight away. The window can only start once controls are actually running, which is why readiness work comes first.
The five Trust Services Criteria
Security (the common criteria, CC1–CC9) is required in every SOC 2. Availability, Processing Integrity, Confidentiality and Privacy are optional and added when customers need them. This check focuses on the Security criteria plus the parts of availability (backups and recovery) that almost every customer asks about.
AI agents are now in your audit scope
SOC 2 has no special section for AI, and that is exactly the problem. An AI agent that reads your database, opens pull requests or emails customers is a user of your systems like any other. Auditors test it under the same criteria:
- Logical access (CC6): does each agent have its own identity, least-privilege permissions and an owner, and is it in your access reviews? Shared API keys with admin rights are a classic finding.
- Monitoring (CC7): can you tell what an agent did in production, when, and on whose behalf?
- Change management (CC8): are agent-generated code and config changes reviewed like human ones?
- Vendors (CC9): are the model providers that receive customer data in your vendor reviews?
Most SOC 2 checklists were written before teams ran agents in production. That's why this check includes four AI questions and scores them separately. Agent Trust Cloud was built to close exactly these gaps and turn agent activity into control evidence.
How long SOC 2 readiness takes
The honest answer is "it depends on your gaps", which is why the tool estimates effort from your answers instead of quoting a generic number. As a rule of thumb, scope, policies and access controls take the longest to put in place, while technical settings like MFA, encryption and branch protection are often done in days. For Type II, add the observation window on top.
Frequently asked questions
Is this a SOC 2 audit or certification?
No. Only a licensed CPA firm can issue a SOC 2 report, and SOC 2 is an attestation rather than a certification. This is a free planning tool that shows where you're likely to have gaps.
Where do my answers go?
Nowhere. The page runs entirely in your browser and is configured so it cannot send data to any server. If you copy the results link, your answers are stored in the part of the link after the # sign, which browsers never send to servers.
Why does it ask about AI agents?
Because agents and automations with access to production or customer data are tested under the same access, monitoring and vendor criteria as everything else, and they are now one of the most common blind spots in readiness work.
What does "Not sure" count as?
Mostly as a gap. If you can't show evidence for a control, an auditor will treat it as missing, so "Not sure" scores only a quarter of a "Yes".
How is the effort estimate calculated?
Each gap has a typical effort in person-days for a team of about 11–50 people, scaled by the company size you choose. "Partly" counts half. Enter your loaded cost per person-day to see the internal cost of the work.