// Free tool

SOC 2 readiness quiz

Customers asking whether you are SOC 2? Answer twelve high-level questions about the controls a SOC 2 audit looks for, access, monitoring, change management, vendors and policies, and get a readiness score with the gaps to close before you start. It will not make you compliant, but it will tell you where you stand.

The 12 checks in this quiz

Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.

Governance & policies

  1. Do you have written, approved information-security policies that staff read and acknowledge?

    Put your security policies in writing, get leadership to approve them, and have staff acknowledge them. Auditors start here, and so do most readiness gaps.

  2. Do you run a documented risk assessment and track the issues it finds to closure?

    Run a recurring risk assessment and track remediation. SOC 2 expects you to identify risks and show you act on them.

Access control

  1. Is access to systems and data granted by role and reviewed periodically (least privilege)?

    Grant access by role, remove what is not needed, and review access lists on a schedule. Document who approved what.

  2. Is MFA enforced on production systems, admin accounts and anything internet-facing?

    Enforce MFA on admin access and key systems. It is one of the controls auditors check first.

  3. Is there a documented process to grant access when people join and revoke it the day they leave?

    Document and follow a joiner/leaver process so access is provisioned and removed on time, with a record of each change.

Operations & monitoring

  1. Do you collect and review logs and alerts from key systems, with someone responsible for them?

    Centralise logs and alerts and make someone accountable for reviewing them. Monitoring evidence is core to SOC 2 Security.

  2. Are changes to production reviewed, tested and recorded (change management)?

    Use a lightweight change process: review, test and record production changes. The paper trail is the evidence.

  3. Are systems backed up and is recovery tested (supporting availability and resilience)?

    Automate backups and test recovery. If you scope in Availability, this becomes a graded control.

Vendors & risk

  1. Do you track your vendors and subprocessors and review their security (for example their SOC 2 reports)?

    Keep a vendor inventory and review the security of any vendor that touches your data, collecting their reports where they have them.

  2. Do you have a documented incident-response plan, and have you tested it?

    Document an incident-response plan and run a tabletop test. Auditors look for both the plan and proof you exercise it.

People

  1. Does staff complete security-awareness training at least once a year?

    Run annual (or more frequent) security training and keep completion records as evidence.

  2. Could you produce evidence (tickets, logs, approvals, reviews) showing these controls actually operated over the last several months?

    Start capturing evidence now. A SOC 2 Type II report covers a period, so controls must be running and documented well before the audit window.

About this quiz. SOC 2 has hundreds of detailed criteria assessed by a licensed CPA firm over a period of time, so this short quiz cannot tell you whether you would pass, it is a readiness indicator, not an audit or an opinion. The one thing auditors care about most is that controls actually operate consistently over time and that you can show evidence. Everything here runs in your browser and is not saved. Use it to scope the work before you engage an auditor.
// What this means for your business

SOC 2 is a project, and we have run it before

Getting audit-ready means closing the gaps above, writing the policies, turning on the controls, and gathering evidence for months before the auditor arrives. We help Canadian businesses get there without derailing the team, then keep the controls running so the next audit is the easy one.