SOC 2 readiness guide
This page helps teams understand and self-assess the technical and organizational prerequisites for a SOC 2 readiness review.
Framework scope
Relevant for US and international SaaS providers that want to build trust with customers, investors and auditors through the AICPA Trust Services Criteria.
SOC 2 evaluates systems and processes against the Trust Services Criteria: Security (always required), Availability, Confidentiality, Processing Integrity and Privacy. Most organizations start with Security (Common Criteria) and add others based on contractual needs.
Orientation score
0 / 100 points
Evidence examples
- Policy documentation (access, change, incident, vendor)
- Screenshots or configuration exports for MFA and SSO
- Change and approval logs
- Incident tickets and post-mortem reports
- Backup and recovery test records
- Risk assessments and remediation plans
Common gaps
- Controls are implemented informally but not documented
- Missing control owners and review cadences
- Evidence is scattered in email or not versioned
- Access reviews happen only ad-hoc
- Audit trails are not adequately protected or retained
CloudForge workflow
CloudForge maps SOC 2 criteria to actionable controls, collects evidence through integrations, runs readiness assessments and tracks gaps with priority and owner up to the external audit.
Official references
- AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy
- AICPA SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality or Privacy
Assessments must be validated with owners, scope and reliable evidence. This page is not a certification or audit attestation.
This guide is for orientation and preparation. It does not replace a formal SOC 2 audit and does not automatically lead to certification or an external auditor's opinion.