What a SOC 2 gap analysis finds
Four different things get sold under three names. Here is what each one produces, who is allowed to run it, and which of them a buyer will actually accept.
A gap analysis compares what you do against what the criteria require, and writes down the difference. That is the whole definition. It carries no opinion, it is not signed by anybody, and no customer will accept it in place of a report. Its value is that it turns an open-ended problem into a finite list, before the expensive part starts.
The confusing part is the naming. Self assessment, readiness assessment, gap analysis and the examination itself get quoted as if they were four rungs of the same ladder, and they are not. Two of them are the same thing under different labels. One is free and one is the only one a buyer cares about.
Four things, one table
Independence is the column that matters. Everything above the last row is you describing yourself, which is useful for planning and worth nothing as proof.
| What it is | Who runs it | What comes out | Independent? |
|---|---|---|---|
| Self assessment | You, against a checklist | Your own opinion of your own controls, usually in a spreadsheet | No |
| Readiness assessment | You with a platform, or a consultant | A score and a list of findings mapped to criteria. The engagement that produces a gap analysis | No |
| Gap analysis | A platform, a consultant, or the audit firm before fieldwork | The finding list itself: what is missing, which criterion it sits under, what closing it takes | No |
| SOC 2 examination | A licensed U.S. CPA firm, and only a CPA firm | A report with an opinion in it, which is the document your customer asked for | Yes |
Read the middle two rows together. The readiness assessment is the activity and the gap analysis is what it hands you, which is why buying both from the same firm is buying one thing twice. Watch for that on a quote.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
What the exercise costs as a service
These are published figures for the engagement, read on the dates shown. They describe the preparation, not the examination.
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
The audit is a separate fee after it, and the vendors who quote it put it here:
- Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.
Ours is free, and the mechanism is worth understanding rather than trusting. The findings are produced by mapping your answers onto the criteria and reporting what is uncovered. That is deterministic work, so it costs nothing to run and there is no reason to bill for it. The free readiness assessment is where it comes from, and it opens with five questions you can answer without an account.
The controls a first examination turns on
A SOC 2 examination is performed against the Trust Services Criteria, and Security is in scope for every engagement.1 The criteria are written as objectives rather than as a control list, which is what makes a first gap analysis feel unbounded, so it helps to know which controls the request list reaches for first.
- Access, and who has it
- Multi-factor authentication on the cloud console, single sign-on for the applications that support it, role-based access to production, and a periodic review that someone actually signed. This is where fieldwork starts.
- Offboarding speed
- How long access survives a termination, evidenced against real leavers rather than asserted in a policy. A day is defensible. A week is a finding.
- Change management
- Whether code reaches production through review and approval, and whether the trail exists in the tooling rather than in memory.
- Encryption and data handling
- At rest for databases and backups, in transit for anything leaving the perimeter, plus a classification scheme that says which data the controls are protecting.
- Logging and alerting
- Centralized collection for the application and the infrastructure, retention long enough to cover the period under examination, and alerts that reach a person.
- Vendors and subservice organizations
- An inventory, evidence that each one was reviewed, and a decision about which are carved out of your report.3
- Governance
- Named ownership, policies approved inside the last twelve months, and evidence that people read them. Cheap to fix and awkward to explain if missing.
- Incident response and continuity
- A written plan, and at least one exercise or real incident that shows the plan was used. A plan nobody has ever run is a document, not a control.
Two of those turn out to be the difference between a clean examination and a qualified one, and neither is technical: whether the evidence covers the whole period, and whether what the policy claims matches what the system does. A control that operates but cannot be shown to have operated fails the same way as a control that does not exist. What happens when a control fails covers how an auditor writes that up.
Turning the list into a date
A finding list is only useful if it is ordered. Ours separates gaps that need a control built from gaps where the control operates and the evidence is missing, because those are different kinds of work and only one of them is on the critical path.
- Close the design gaps first. A control that does not exist cannot be evidenced, and every day it stays missing is a day the observation window has not started.
- Then collect. The evidence checklist lists the artifacts by name, and the prepared-by-client list shows the form the request arrives in.
- Then set the date. How long SOC 2 takes walks through what the remaining variables are once the gaps are closed.
After the list, the work is paid: $2,000 one time for onboarding and remediation, or $4,000 one time with the Type 1 examination and the auditor engagement fee inside it. The examination is performed by an independent partner auditor, a licensed U.S. CPA firm, because a SOC 2 report is signed by an independent firm and never by the party being examined.2
The list itself costs nothing. Answer the intake and it renders when you finish.
Questions
What is the difference between a readiness assessment and a gap analysis?
Does a gap analysis have to be done by a CPA firm?
Will a customer accept a gap analysis instead of a SOC 2 report?
How much does a SOC 2 gap analysis cost?
How long does a gap analysis take?
What does a gap analysis actually produce?
Can I do a gap analysis myself with a spreadsheet?
Do the gaps go away if I switch auditors?
Should I fix every gap before booking an audit?
Is a gap analysis worth doing if we are early?
Sources
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.