How ready are you for SOC 2?

Five questions below, no account and no email box. The full assessment is free too, and it gives you a score and a written gap list rather than a brochure.

A SOC 2 readiness assessment answers one question: if an audit started tomorrow, what would the auditor write down. It is not the audit. It is the rehearsal, and it is the cheapest place to find out that access reviews were never documented or that the logs roll off after thirty days. Start with five of the questions the real intake asks.

  1. Access control. MFA required for cloud console access?
  2. Offboarding. User access removed within 24 hours of termination?
  3. Data protection. Encryption at rest for databases and backups?
  4. Monitoring. Centralized log collection for app and infrastructure?
  5. Governance. Has management formally approved the security and compliance program in the last 12 months?

Answer all five and a direction appears here. Nothing is sent anywhere, and there is no email box on this page.

Those five are copied from the intake, not written for a landing page. They are also the five an auditor tends to reach for first, which is why a No on any of them is worth knowing about now rather than in a request list.

What the free assessment gives you

The full version asks about a hundred more of those, across access, change management, vendors, encryption, logging, incident response and governance. When you finish it, the results screen renders immediately. Free means free here. No card, no payment step, no trial that expires.

A readiness score and the tier it falls in
Severity weighted, out of 100, with the count of controls scored and how many of them are passing shown beside it.
Every gap category, counted exactly
Worst first, and each one split into what has to be remediated and what merely has to be evidenced. No category is hidden and nothing is blurred out.
Two or three findings written out in full
Real prose about your own answers, in the same shape as the rest of the report. Not a control name and a red dot.
The exact size of what is left
The remainder is stated as a number, not a range and not a teaser: how many more findings, across how many categories, and how they split.

What you do not get is a file. There is no free PDF, and that is a decision rather than an oversight. The result lives in your account and recomputes when your answers change, so it is a working document instead of a snapshot that is wrong a week later.

How the scoring works

Every answer maps to one or more of the Trust Services Criteria, the AICPA criteria a SOC 2 examination is actually performed against.1 An answer that leaves a criterion uncovered produces a gap, and each gap carries a severity based on how central the control is to the criterion it sits under.

The score is the weighted proportion of scored controls that pass. Weighted, because treating a missing offboarding process and a missing asset inventory as equal would flatter the wrong companies. Two things follow from that, and both are worth stating plainly.

  1. The score is deterministic. The same answers always produce the same number. No model is asked to judge you, so nothing about the result drifts between runs.
  2. The score is only as honest as the answers. Nothing is verified at this stage. Overstating a control moves your number up and moves your problem to the audit, where it costs considerably more.

Readiness zones, and what each one means

Scores are compared against the standard rather than against other companies. A benchmark drawn from a small number of assessments would be a made-up statistic, and this is the wrong product to be inventing statistics for.

ScoreWhat it meansWhat the work looks like
85 to 100Controls are largely in placeMostly evidence collection and writing down what you already do. This is the zone where a date can be set with some confidence
60 to 84Real control gaps are openConfiguration changes and policy work, then evidence. The gap list is the plan, and the order it comes in is the order to work it
Below 60Several first-look controls are missingFoundational work before anything else is worth doing. Booking an audit from here buys an expensive list of the same findings

What this engagement costs when somebody else runs it

Readiness assessments are a billable service, and the people who sell them publish what they charge. Both of these were opened and read on the date shown.

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

That is the engagement. Not the audit, which is a separate fee on top of it, and the vendors who quote the audit put it well into five figures of its own:

  • Drata estimates a SOC 2 Type 1 audit at $7,500 to $15,000 and a Type 2 at $12,000 to $20,000, and puts a small startup first-year total at $25,000 or more. Source, checked 2026-07-30.

Ours costs nothing, and the reason is narrow enough to state without hedging. The assessment is how we find out whether your company is something we can take to an audit at our price. Charging for that would mean charging you to qualify us. Everything after it is paid: $2,000 one time for onboarding, or $4,000 one time with the Type 1 examination and the auditor engagement fee inside it, then $600 per month for Type 2 on a 12-month term. The cost calculator totals either path across two years, and what SOC 2 actually costs shows where each figure comes from.

One thing no platform can do

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

What happens after you finish

Nothing is hidden until you talk to us, so here is the sequence in advance. You finish the intake and the score renders. Underneath it there is a booking calendar for a 30-minute call where we go through every finding, including the ones the free screen did not write out, and what closing each one takes.

That call is a real walkthrough and it is also a sales call. Both are true and there is no point pretending otherwise. If the fit is wrong you will hear that on the call, which is faster for everyone than finding out after an invoice. Below the calendar there is a quiet checkout link for people who already know what they want.

The paid side is where remediation, thirteen policies written from your own answers, the evidence binder and the report package live. The examination itself is performed by an independent partner auditor, a licensed U.S. CPA firm, which is a requirement of the standard rather than a business model.2 An examination is conducted under the AICPA attestation standards regardless of who assembled the package.3

Where to go next

If you want to see what the auditor will actually ask for, the evidence checklist lists it artifact by artifact. If the question is when rather than whether, how long SOC 2 takes walks through what sets the date. If you are trying to work out how a readiness assessment differs from the gap analysis a firm would sell you, the gap analysis page puts all four options in one table.

Or skip the reading. Create an account and answer the intake. It is free, it takes half an hour, and at the end of it you will know your number.

Questions

Is a readiness assessment required for SOC 2?
No. Nothing in the attestation standards requires one. It is a preparation step, not a deliverable, and its whole value is finding what an auditor would raise while it is still cheap to fix.
Does a readiness assessment have to be done by a CPA?
No. Only the examination itself has to be performed by a licensed U.S. CPA firm. Anyone can run a readiness assessment, including you. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
How much does a SOC 2 readiness assessment cost?
When a firm performs it, published figures put the engagement in the five figures. Ours is free, with no card and no payment step in front of it, because the assessment is how we find out whether we can help you at all.
What is a good SOC 2 readiness score?
There is no industry scale, so treat any score as a description of your own answers rather than a rank against other companies. In our scoring, 85 and above means the remaining work is mostly evidence, 60 to 84 means real control gaps are open, and below 60 means several of the controls an auditor looks at first are missing.
How long does the free assessment take?
The five questions on this page take about a minute. The full intake takes most people 15 to 30 minutes, it saves as you go, and you can leave and come back without losing answers.
Do I need to pay to see my score?
No. The score, the tier, every gap category with exact counts, and two or three findings written out in full all render before any payment ask appears. Payment buys remediation, the policies and the report package, not the result.
Do I get a downloadable report from the free assessment?
No, and there is not going to be one. The free result lives in your account and recomputes as your answers change, which is more useful than a file and is also the honest description of what it is.
Type 1 or Type 2 first, and does the assessment cover both?
The assessment is the same for both, because both examine the same controls. Type 1 looks at whether the controls are designed and in place on one date, and Type 2 looks at how they operated across a period, so the readiness work is identical and only the observation window differs.
How long does SOC 2 take after the assessment?
The remediation work is the variable. Closing gaps and collecting evidence is what sets the date, and the observation window for a Type 2 adds a fixed period on top of it once the controls are in place.
Can I do SOC 2 myself?
You can do all of the preparation yourself. You cannot do the examination yourself, because a SOC 2 report is signed by an independent licensed CPA firm and a company cannot sign its own.
What do auditors check first?
Access control and offboarding, nearly always. Multi-factor authentication on the cloud console, how fast access is removed when somebody leaves, encryption at rest, centralized logging, and whether management has approved the program are the first five things a request list asks about.
Is SOC 2 legally required?
No. No law requires it. It is required by buyers, which in practice means it blocks enterprise deals until you have it, and that is why the deadline is usually somebody else’s.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report or an ISO 27001 certificate, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.