How ready are you for SOC 2?
Five questions below, no account and no email box. The full assessment is free too, and it gives you a score and a written gap list rather than a brochure.
A SOC 2 readiness assessment answers one question: if an audit started tomorrow, what would the auditor write down. It is not the audit. It is the rehearsal, and it is the cheapest place to find out that access reviews were never documented or that the logs roll off after thirty days. Start with five of the questions the real intake asks.
- Access control. MFA required for cloud console access?
- Offboarding. User access removed within 24 hours of termination?
- Data protection. Encryption at rest for databases and backups?
- Monitoring. Centralized log collection for app and infrastructure?
- Governance. Has management formally approved the security and compliance program in the last 12 months?
Answer all five and a direction appears here. Nothing is sent anywhere, and there is no email box on this page.
Those five are copied from the intake, not written for a landing page. They are also the five an auditor tends to reach for first, which is why a No on any of them is worth knowing about now rather than in a request list.
What the free assessment gives you
The full version asks about a hundred more of those, across access, change management, vendors, encryption, logging, incident response and governance. When you finish it, the results screen renders immediately. Free means free here. No card, no payment step, no trial that expires.
- A readiness score and the tier it falls in
- Severity weighted, out of 100, with the count of controls scored and how many of them are passing shown beside it.
- Every gap category, counted exactly
- Worst first, and each one split into what has to be remediated and what merely has to be evidenced. No category is hidden and nothing is blurred out.
- Two or three findings written out in full
- Real prose about your own answers, in the same shape as the rest of the report. Not a control name and a red dot.
- The exact size of what is left
- The remainder is stated as a number, not a range and not a teaser: how many more findings, across how many categories, and how they split.
What you do not get is a file. There is no free PDF, and that is a decision rather than an oversight. The result lives in your account and recomputes when your answers change, so it is a working document instead of a snapshot that is wrong a week later.
How the scoring works
Every answer maps to one or more of the Trust Services Criteria, the AICPA criteria a SOC 2 examination is actually performed against.1 An answer that leaves a criterion uncovered produces a gap, and each gap carries a severity based on how central the control is to the criterion it sits under.
The score is the weighted proportion of scored controls that pass. Weighted, because treating a missing offboarding process and a missing asset inventory as equal would flatter the wrong companies. Two things follow from that, and both are worth stating plainly.
- The score is deterministic. The same answers always produce the same number. No model is asked to judge you, so nothing about the result drifts between runs.
- The score is only as honest as the answers. Nothing is verified at this stage. Overstating a control moves your number up and moves your problem to the audit, where it costs considerably more.
Readiness zones, and what each one means
Scores are compared against the standard rather than against other companies. A benchmark drawn from a small number of assessments would be a made-up statistic, and this is the wrong product to be inventing statistics for.
| Score | What it means | What the work looks like |
|---|---|---|
| 85 to 100 | Controls are largely in place | Mostly evidence collection and writing down what you already do. This is the zone where a date can be set with some confidence |
| 60 to 84 | Real control gaps are open | Configuration changes and policy work, then evidence. The gap list is the plan, and the order it comes in is the order to work it |
| Below 60 | Several first-look controls are missing | Foundational work before anything else is worth doing. Booking an audit from here buys an expensive list of the same findings |
What this engagement costs when somebody else runs it
Readiness assessments are a billable service, and the people who sell them publish what they charge. Both of these were opened and read on the date shown.
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
That is the engagement. Not the audit, which is a separate fee on top of it, and the vendors who quote the audit put it well into five figures of its own:
- Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.
Ours costs nothing, and the reason is narrow enough to state without hedging. The assessment is how we find out whether your company is something we can take to an audit at our price. Charging for that would mean charging you to qualify us. Everything after it is paid: $2,000 one time for onboarding, or $4,000 one time with the Type 1 examination and the auditor engagement fee inside it, then $600 per month for Type 2 on a 12-month term. The cost calculator totals either path across two years, and what SOC 2 actually costs shows where each figure comes from.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
What happens after you finish
Nothing is hidden until you talk to us, so here is the sequence in advance. You finish the intake and the score renders. Underneath it there is a booking calendar for a 30-minute call where we go through every finding, including the ones the free screen did not write out, and what closing each one takes.
That call is a real walkthrough and it is also a sales call. Both are true and there is no point pretending otherwise. If the fit is wrong you will hear that on the call, which is faster for everyone than finding out after an invoice. Below the calendar there is a quiet checkout link for people who already know what they want.
The paid side is where remediation, thirteen policies written from your own answers, the evidence binder and the report package live. The examination itself is performed by an independent partner auditor, a licensed U.S. CPA firm, which is a requirement of the standard rather than a business model.2 An examination is conducted under the AICPA attestation standards regardless of who assembled the package.3
Where to go next
If you want to see what the auditor will actually ask for, the evidence checklist lists it artifact by artifact. If the question is when rather than whether, how long SOC 2 takes walks through what sets the date. If you are trying to work out how a readiness assessment differs from the gap analysis a firm would sell you, the gap analysis page puts all four options in one table.
Or skip the reading. Create an account and answer the intake. It is free, it takes half an hour, and at the end of it you will know your number.
Questions
Is a readiness assessment required for SOC 2?
Does a readiness assessment have to be done by a CPA?
How much does a SOC 2 readiness assessment cost?
What is a good SOC 2 readiness score?
How long does the free assessment take?
Do I need to pay to see my score?
Do I get a downloadable report from the free assessment?
Type 1 or Type 2 first, and does the assessment cover both?
How long does SOC 2 take after the assessment?
Can I do SOC 2 myself?
What do auditors check first?
Is SOC 2 legally required?
Sources
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.