SOC 2 Readiness Check by Agent Trust Cloud

Free · 5 minutes · no sign-up

Are you ready for a SOC 2 audit?

Answer 20 yes/no questions. You get a readiness score, the gaps an auditor would most likely flag (with the evidence they'll ask for), and a realistic Type I or Type II timeline.

  • Mapped to the AICPA Trust Services Criteria
  • Covers AI tools and AI agents — the gap most checklists miss
  • Runs in your browser; your answers are never uploaded

Start the check

Which report do you need?
0 of 20 answered

What a SOC 2 readiness assessment is

SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria. A readiness assessment is the step before it: you compare how you actually work with what the criteria require, and fix the gaps before an auditor tests them. Every gap you close now is one fewer exception written into the report your customers read.

Type I vs Type II

Type IType II
What it testsControls are designed properlyControls operated effectively
PeriodA single dateAn observation window, usually 3–12 months
Who asks for itEarly deals, a first stepMost enterprise security reviews
EvidencePolicies and configurationsSamples across the whole window: tickets, reviews, alerts, changes

Many teams do a Type I first to unblock a deal, then start the Type II window straight away. The window can only start once controls are actually running, which is why readiness work comes first.

The five Trust Services Criteria

Security (the common criteria, CC1–CC9) is required in every SOC 2. Availability, Processing Integrity, Confidentiality and Privacy are optional and added when customers need them. This check focuses on the Security criteria plus the parts of availability (backups and recovery) that almost every customer asks about.

AI agents are now in your audit scope

SOC 2 has no special section for AI, and that is exactly the problem. An AI agent that reads your database, opens pull requests or emails customers is a user of your systems like any other. Auditors test it under the same criteria:

  • Logical access (CC6): does each agent have its own identity, least-privilege permissions and an owner, and is it in your access reviews? Shared API keys with admin rights are a classic finding.
  • Monitoring (CC7): can you tell what an agent did in production, when, and on whose behalf?
  • Change management (CC8): are agent-generated code and config changes reviewed like human ones?
  • Vendors (CC9): are the model providers that receive customer data in your vendor reviews?

Most SOC 2 checklists were written before teams ran agents in production. That's why this check includes four AI questions and scores them separately. Agent Trust Cloud was built to close exactly these gaps and turn agent activity into control evidence.

How long SOC 2 readiness takes

The honest answer is "it depends on your gaps", which is why the tool estimates effort from your answers instead of quoting a generic number. As a rule of thumb, scope, policies and access controls take the longest to put in place, while technical settings like MFA, encryption and branch protection are often done in days. For Type II, add the observation window on top.

Frequently asked questions

Is this a SOC 2 audit or certification?

No. Only a licensed CPA firm can issue a SOC 2 report, and SOC 2 is an attestation rather than a certification. This is a free planning tool that shows where you're likely to have gaps.

Where do my answers go?

Nowhere. The page runs entirely in your browser and is configured so it cannot send data to any server. If you copy the results link, your answers are stored in the part of the link after the # sign, which browsers never send to servers.

Why does it ask about AI agents?

Because agents and automations with access to production or customer data are tested under the same access, monitoring and vendor criteria as everything else, and they are now one of the most common blind spots in readiness work.

What does "Not sure" count as?

Mostly as a gap. If you can't show evidence for a control, an auditor will treat it as missing, so "Not sure" scores only a quarter of a "Yes".

How is the effort estimate calculated?

Each gap has a typical effort in person-days for a team of about 11–50 people, scaled by the company size you choose. "Partly" counts half. Enter your loaded cost per person-day to see the internal cost of the work.