Are you ready for a SOC 2 audit?
Eight questions, two minutes. Scored against the control areas auditors test first — access, logging, policies, vendors, and recovery.
1. Do you have written information-security policies that employees have acknowledged?
2. Do you review who has access to production systems and customer data?
3. Are security logs collected centrally and reviewed for incidents?
4. Do you run background checks and security training for new hires?
5. Is there a tested backup and disaster-recovery plan for critical systems?
6. Do you have an incident-response plan and know who runs it?
7. Do you assess the security of vendors that touch customer data?
8. Have you had a penetration test or vulnerability assessment in the last 12 months?
How scoring works
Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with a readiness assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready to engage auditors. This is a self-assessment aid, not an audit opinion.
Know your score? Get quotes
Auditors scope fees around readiness. Tell us where you stand and get matched.