Free tool · Updated 6 October 2026
In short: Free SOC 2 Type 2 gap analysis: 18 questions on CC1 to CC9 and Availability, a readiness score, your biggest gaps and what closes each one with ITSECOPS readiness pricing and typical CPA audit fees.
SOC 2 Type 2 reports now gate most US SaaS procurement, and the observation window of 3 to 12 months means every control missing today delays the report by that much. CPA audit fees for SMBs run $12,000 to $45,000 and readiness boutiques charge $15,000 to $40,000 on top; the tool shows which controls you would fail during the observation period and what it costs to fix them before the window starts.
How it works
- Answer 18 questions: Written the way a CPA samples evidence across the period: approvals, reviews, logs and records. About four minutes.
- See your score: A readiness percentage, a bar per criteria group and your three biggest gaps, free and without an email.
- Unlock the plan: The full table: what closes each gap, the ITSECOPS readiness price, the typical boutique and CPA audit prices, totals and the shortest observation window you can realistically run, plus a copy by email within one business day.
Frequently asked questions
Type 1 or Type 2 first?
If a customer is waiting, a Type 1 report on a point-in-time design can be delivered in about 30 days (see the SOC 2 Type 1 in 30 days page) while the Type 2 observation period starts. Most companies do both in that order.
How much does SOC 2 Type 2 cost?
Readiness and remediation priced per gap by the tool, plus the CPA audit at $12,000 to $45,000 depending on scope, criteria and firm. All-in year-one figures for SMBs typically land between $20,000 and $80,000; ITSECOPS readiness sits well below the boutique range because delivery is remote.
Which criteria matter most?
CC6 (logical access), CC7 (monitoring and incident response) and A1 (availability, backup) produce most exceptions in first-year reports, which is why they carry triple weight in the score.
Can one control set serve ISO 27001 and SOC 2?
Yes. The case studies on this site show one control set clearing both; VEDVERA GRC maps evidence once to both frameworks.
Related
SOC 2 Type 1 report in 30 days · SOC 2 readiness services · Top SOC 2 readiness consultants · ISO 27001 vs SOC 2 · Client testimonials