Skip to content
CISO Marketplace Services

SOC 2 Readiness Assessment

Comprehensive evaluation of your organization's readiness for SOC 2 compliance, examining your controls against the relevant Trust Services Criteria. Our assessment provides a detailed gap analysis and implementation roadmap to help you prepare for a successful SOC 2 audit.

In scope

  • SOC 2 Type selection guidance
  • Trust Services Criteria gap analysis
  • Control documentation review
  • Evidence collection process assessment
  • Vendor management control review
  • Change management process evaluation
  • Risk assessment framework review
  • Security monitoring evaluation
  • Control testing preparation
  • Auditor selection guidance

You receive

  • SOC 2 readiness report
  • Control gap analysis
  • Documentation enhancement plan
  • Evidence collection framework
  • Remediation roadmap
  • Control implementation guidance
  • Vendor assessment recommendations
  • Pre-audit preparation checklist
  • Type 1 vs. Type 2 strategy
  • Implementation timeline

Tiers

Choose the depth.

Entry — market-sized scope

$15.5K

Type I readiness check: Security criterion only, 1 in-scope product, up to 50 employees. Controls compared to the criteria through document review and up to 6 remote interviews. Output is a gap list and a pre-audit checklist.

employees
50
web apps
1
months
1
  • Security (Common Criteria) gap analysis
  • Review of existing policies and control documentation
  • Up to 6 remote interviews
  • Gap list with owners and priorities
  • Pre-audit preparation checklist
  • — Additional criteria (Availability, Confidentiality, Processing Integrity, Privacy)
  • — Type II evidence collection design
  • — Remediation roadmap with timeline
  • — Writing policies
Scope Entry — market-sized scope

Essential SOC 2 Gap Analysis

$35K

Up to 250 employees, up to 2 in-scope products and up to 3 Trust Services Criteria. Gap analysis, Type 1 vs Type 2 strategy, vendor, change management and risk assessment reviews, remediation roadmap with timeline and auditor selection guidance.

employees
250
web apps
2
months
2
  • Gap analysis for up to 3 Trust Services Criteria
  • Type 1 vs Type 2 strategy
  • Vendor, change management and risk assessment process reviews
  • Remediation roadmap and implementation timeline
  • Auditor selection guidance
  • — Evidence collection framework build
  • — Per-control implementation guidance
  • — Writing policies and procedures
  • — Support during the audit
Scope Essential SOC 2 Gap Analysis

Comprehensive SOC 2 Preparation

$60K

Complete readiness assessment with detailed control implementation guidance and evidence collection framework

employees
500
web apps
3
  • — Writing the policy and procedure set
  • — Hands-on control implementation
  • — Liaison with the auditor during fieldwork
  • — The CPA firm's audit fees
Scope Comprehensive SOC 2 Preparation

Enterprise SOC 2 Implementation Program

$95K

Full-service SOC 2 preparation including control implementation, documentation development, and audit support

employees
1000
web apps
5
  • — The SOC 2 audit and report (issued by a CPA firm)
  • — Compliance automation platform licences
  • — Penetration testing
  • — Organizations above 1,000 employees (scoped separately)
Scope Enterprise SOC 2 Implementation Program

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a readiness & governance assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & framework selection

    The standard or regulation, the systems and the business units in scope are fixed.

    You see · Your audit or regulatory driver.

  2. 02Evidence collection & interviews

    Policies, configurations and records reviewed; control owners interviewed.

    You see · Documents and time with control owners.

  3. 03Gap analysis

    Each requirement mapped to current state: met, partial or missing, with the evidence behind it.

    You see · A clear gap register.

  4. 04Roadmap & evidence plan

    Prioritized remediation with owners, and the evidence an auditor will ask for.

    You see · A plan you can execute or hand to us.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor