Skip to content
Calcrivo

SOC 2 Readiness Calculator

Assess SOC 2 readiness across the CC1–CC9 common criteria, your control matrix, the observation window and known exceptions.

Inputs

categories
controls
controls
categories
months
exceptions

SOC 2 Readiness Score

62.1%

Common Criteria Coverage

77.8%

Controls Operating Effectively

75.0%

Controls Without Evidence

16controls

Indicative Time to Audit

9weeks

Report Scope

Security common criteria plus 2 additional category(ies) from availability, confidentiality, processing integrity and privacy

Opinion Risk

Exceptions will appear in the report alongside management's response, which is normal and survivable

Next Step

Run a readiness assessment first — the control matrix is not yet operating end to end

Step by step

  1. Values used

    Common criteria categories CC1–CC9 fully evidenced = 7 categories; Controls in the control matrix = 64 controls; Controls operating effectively with evidence = 48 controls; Additional trust services categories in scope = Security plus 2 categories — 2; Additional categories fully evidenced = 1 categories; Observation window completed so far = 2 months; Report type = Type 2 — design and operating effectiveness over a period; Known control exceptions in the window = 3 exceptions

  2. SOC 2 Readiness

    Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30).

  3. SOC 2 Readiness Score

    = 62.1

  4. Common Criteria Coverage

    = 77.8

  5. Controls Operating Effectively

    = 75.0

  6. Controls Without Evidence

    = 16 controls

  7. Indicative Time to Audit

    = 9 weeks

  8. Report Scope

    = Security common criteria plus 2 additional category(ies) from availability, confidentiality, processing integrity and privacy

How it works

SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten. Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.

Formula

SOC 2 Readiness

Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30).

CC1–CC9
The nine common criteria categories that make up the security category
exceptions
Instances where a control did not operate as described during the window
windowNeed
Three months is the shortest Type 2 window most auditors will accept

Frequently Asked Questions

How is SOC 2 Readiness calculated?

Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30). SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten.

Why does SOC 2 Readiness matter?

Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.

What values do I need to enter?

This calculator takes 8 inputs: Common criteria categories CC1–CC9 fully evidenced, Controls in the control matrix, Controls operating effectively with evidence, Additional trust services categories in scope, Additional categories fully evidenced, Observation window completed so far, Report type, Known control exceptions in the window. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Should I start with Type 1 or Type 2?

Type 1 tests design at a point in time and can be issued quickly, which helps if a customer needs something now. Type 2 tests operating effectiveness across a window and is what enterprise procurement actually wants, so treat Type 1 as a bridge rather than a destination.

Do exceptions mean I failed?

No. Reports routinely contain exceptions with a management response, and buyers read the response as much as the exception. What damages a report is a pattern — several exceptions against the same criterion, or an exception that recurs in the next window after you said it was fixed.

You might also need