# SOC 2 Readiness Assessment

> From $15.5K · Compliance & GRC · https://cisomarketplace.services/services/soc2-readiness-assessment

Comprehensive evaluation of your organization's readiness for SOC 2 compliance, examining your controls against the relevant Trust Services Criteria. Our assessment provides a detailed gap analysis and implementation roadmap to help you prepare for a successful SOC 2 audit.

## In scope

- SOC 2 Type selection guidance
- Trust Services Criteria gap analysis
- Control documentation review
- Evidence collection process assessment
- Vendor management control review
- Change management process evaluation
- Risk assessment framework review
- Security monitoring evaluation
- Control testing preparation
- Auditor selection guidance

## Deliverables

- SOC 2 readiness report
- Control gap analysis
- Documentation enhancement plan
- Evidence collection framework
- Remediation roadmap
- Control implementation guidance
- Vendor assessment recommendations
- Pre-audit preparation checklist
- Type 1 vs. Type 2 strategy
- Implementation timeline

## Tiers

### Entry — market-sized scope: $15.5K

Type I readiness check: Security criterion only, 1 in-scope product, up to 50 employees. Controls compared to the criteria through document review and up to 6 remote interviews. Output is a gap list and a pre-audit checklist.

Limits: employees 50, web apps 1, months 1

Includes:
- Security (Common Criteria) gap analysis
- Review of existing policies and control documentation
- Up to 6 remote interviews
- Gap list with owners and priorities
- Pre-audit preparation checklist

Excludes:
- Additional criteria (Availability, Confidentiality, Processing Integrity, Privacy)
- Type II evidence collection design
- Remediation roadmap with timeline
- Writing policies

### Essential SOC 2 Gap Analysis: $35K

Up to 250 employees, up to 2 in-scope products and up to 3 Trust Services Criteria. Gap analysis, Type 1 vs Type 2 strategy, vendor, change management and risk assessment reviews, remediation roadmap with timeline and auditor selection guidance.

Limits: employees 250, web apps 2, months 2

Includes:
- Gap analysis for up to 3 Trust Services Criteria
- Type 1 vs Type 2 strategy
- Vendor, change management and risk assessment process reviews
- Remediation roadmap and implementation timeline
- Auditor selection guidance

Excludes:
- Evidence collection framework build
- Per-control implementation guidance
- Writing policies and procedures
- Support during the audit

### Comprehensive SOC 2 Preparation: $60K

Complete readiness assessment with detailed control implementation guidance and evidence collection framework

Limits: employees 500, web apps 3

Excludes:
- Writing the policy and procedure set
- Hands-on control implementation
- Liaison with the auditor during fieldwork
- The CPA firm's audit fees

### Enterprise SOC 2 Implementation Program: $95K

Full-service SOC 2 preparation including control implementation, documentation development, and audit support

Limits: employees 1000, web apps 5

Excludes:
- The SOC 2 audit and report (issued by a CPA firm)
- Compliance automation platform licences
- Penetration testing
- Organizations above 1,000 employees (scoped separately)

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=soc2-readiness-assessment
