What a SOC 2 gap analysis finds

Four different things get sold under three names. Here is what each one produces, who is allowed to run it, and which of them a buyer will actually accept.

A gap analysis compares what you do against what the criteria require, and writes down the difference. That is the whole definition. It carries no opinion, it is not signed by anybody, and no customer will accept it in place of a report. Its value is that it turns an open-ended problem into a finite list, before the expensive part starts.

The confusing part is the naming. Self assessment, readiness assessment, gap analysis and the examination itself get quoted as if they were four rungs of the same ladder, and they are not. Two of them are the same thing under different labels. One is free and one is the only one a buyer cares about.

Four things, one table

Independence is the column that matters. Everything above the last row is you describing yourself, which is useful for planning and worth nothing as proof.

What it isWho runs itWhat comes outIndependent?
Self assessmentYou, against a checklistYour own opinion of your own controls, usually in a spreadsheetNo
Readiness assessmentYou with a platform, or a consultantA score and a list of findings mapped to criteria. The engagement that produces a gap analysisNo
Gap analysisA platform, a consultant, or the audit firm before fieldworkThe finding list itself: what is missing, which criterion it sits under, what closing it takesNo
SOC 2 examinationA licensed U.S. CPA firm, and only a CPA firmA report with an opinion in it, which is the document your customer asked forYes

Read the middle two rows together. The readiness assessment is the activity and the gap analysis is what it hands you, which is why buying both from the same firm is buying one thing twice. Watch for that on a quote.

The line that never moves

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

What the exercise costs as a service

These are published figures for the engagement, read on the dates shown. They describe the preparation, not the examination.

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

The audit is a separate fee after it, and the vendors who quote it put it here:

  • Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.

Ours is free, and the mechanism is worth understanding rather than trusting. The findings are produced by mapping your answers onto the criteria and reporting what is uncovered. That is deterministic work, so it costs nothing to run and there is no reason to bill for it. The free readiness assessment is where it comes from, and it opens with five questions you can answer without an account.

The controls a first examination turns on

A SOC 2 examination is performed against the Trust Services Criteria, and Security is in scope for every engagement.1 The criteria are written as objectives rather than as a control list, which is what makes a first gap analysis feel unbounded, so it helps to know which controls the request list reaches for first.

Access, and who has it
Multi-factor authentication on the cloud console, single sign-on for the applications that support it, role-based access to production, and a periodic review that someone actually signed. This is where fieldwork starts.
Offboarding speed
How long access survives a termination, evidenced against real leavers rather than asserted in a policy. A day is defensible. A week is a finding.
Change management
Whether code reaches production through review and approval, and whether the trail exists in the tooling rather than in memory.
Encryption and data handling
At rest for databases and backups, in transit for anything leaving the perimeter, plus a classification scheme that says which data the controls are protecting.
Logging and alerting
Centralized collection for the application and the infrastructure, retention long enough to cover the period under examination, and alerts that reach a person.
Vendors and subservice organizations
An inventory, evidence that each one was reviewed, and a decision about which are carved out of your report.3
Governance
Named ownership, policies approved inside the last twelve months, and evidence that people read them. Cheap to fix and awkward to explain if missing.
Incident response and continuity
A written plan, and at least one exercise or real incident that shows the plan was used. A plan nobody has ever run is a document, not a control.

Two of those turn out to be the difference between a clean examination and a qualified one, and neither is technical: whether the evidence covers the whole period, and whether what the policy claims matches what the system does. A control that operates but cannot be shown to have operated fails the same way as a control that does not exist. What happens when a control fails covers how an auditor writes that up.

Turning the list into a date

A finding list is only useful if it is ordered. Ours separates gaps that need a control built from gaps where the control operates and the evidence is missing, because those are different kinds of work and only one of them is on the critical path.

  1. Close the design gaps first. A control that does not exist cannot be evidenced, and every day it stays missing is a day the observation window has not started.
  2. Then collect. The evidence checklist lists the artifacts by name, and the prepared-by-client list shows the form the request arrives in.
  3. Then set the date. How long SOC 2 takes walks through what the remaining variables are once the gaps are closed.

After the list, the work is paid: $2,000 one time for onboarding and remediation, or $4,000 one time with the Type 1 examination and the auditor engagement fee inside it. The examination is performed by an independent partner auditor, a licensed U.S. CPA firm, because a SOC 2 report is signed by an independent firm and never by the party being examined.2

The list itself costs nothing. Answer the intake and it renders when you finish.

Questions

What is the difference between a readiness assessment and a gap analysis?
In practice, none worth paying twice for. Both compare what you do against the Trust Services Criteria and produce a list of what is missing. Gap analysis usually names the output, readiness assessment usually names the engagement, and some firms sell them as two line items on the same invoice.
Does a gap analysis have to be done by a CPA firm?
No. Only the examination has to be. A gap analysis carries no opinion and no independence requirement, which is exactly why it can be automated and given away. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Will a customer accept a gap analysis instead of a SOC 2 report?
No. A gap analysis is your own document about your own controls. The thing a buyer asks for is a report signed by an independent licensed CPA firm, and nothing you produce about yourself substitutes for it.
How much does a SOC 2 gap analysis cost?
When a firm performs it as an engagement, published figures put it in the five figures. Automated, it costs whatever the platform charges, and ours costs nothing because it comes out of the free readiness assessment.
How long does a gap analysis take?
A firm engagement runs from a few weeks to a few months, because it involves interviews, document review and a written deliverable. The automated version returns as soon as you finish answering, which for most people is under an hour.
What does a gap analysis actually produce?
A list of findings, each tied to a criterion, each saying what is missing and what closing it requires. A good one separates gaps that need a control built from gaps where the control exists and only the evidence is missing, because those are very different amounts of work.
Can I do a gap analysis myself with a spreadsheet?
Yes, and it is a legitimate way to start. The two things that go wrong are scope, since it is hard to grade yourself against criteria you have not read, and drift, since a spreadsheet is correct on the day it is filled in and never again.
Do the gaps go away if I switch auditors?
No. The criteria are the same for every firm, so the findings travel with you. What changes between firms is the request list and the evidence formats they prefer, not whether your access reviews exist.
Should I fix every gap before booking an audit?
Every gap that is a missing control, yes. Gaps that are missing evidence for a control that genuinely operates can sometimes be closed during fieldwork, but going in with a known design gap means paying for an examination to tell you what you already knew.
Is a gap analysis worth doing if we are early?
It is worth more when you are early, not less. The findings are cheapest to close before the systems that produce the evidence are load bearing, and the list also tells you whether a date somebody promised a customer is realistic.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report or an ISO 27001 certificate, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.