SOC 2 Readiness Calculator
Assess SOC 2 readiness across the CC1–CC9 common criteria, your control matrix, the observation window and known exceptions.
Inputs
SOC 2 Readiness Score
62.1%
Common Criteria Coverage
77.8%
Controls Operating Effectively
75.0%
Controls Without Evidence
16controls
Indicative Time to Audit
9weeks
Report Scope
Security common criteria plus 2 additional category(ies) from availability, confidentiality, processing integrity and privacy
Opinion Risk
Exceptions will appear in the report alongside management's response, which is normal and survivable
Next Step
Run a readiness assessment first — the control matrix is not yet operating end to end
Step by step
Values used
Common criteria categories CC1–CC9 fully evidenced = 7 categories; Controls in the control matrix = 64 controls; Controls operating effectively with evidence = 48 controls; Additional trust services categories in scope = Security plus 2 categories — 2; Additional categories fully evidenced = 1 categories; Observation window completed so far = 2 months; Report type = Type 2 — design and operating effectiveness over a period; Known control exceptions in the window = 3 exceptions
SOC 2 Readiness
Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30).
SOC 2 Readiness Score
= 62.1
Common Criteria Coverage
= 77.8
Controls Operating Effectively
= 75.0
Controls Without Evidence
= 16 controls
Indicative Time to Audit
= 9 weeks
Report Scope
= Security common criteria plus 2 additional category(ies) from availability, confidentiality, processing integrity and privacy
How it works
SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten. Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.
Formula
SOC 2 Readiness
Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30).
- CC1–CC9
- The nine common criteria categories that make up the security category
- exceptions
- Instances where a control did not operate as described during the window
- windowNeed
- Three months is the shortest Type 2 window most auditors will accept
Frequently Asked Questions
How is SOC 2 Readiness calculated?
Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30). SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten.
Why does SOC 2 Readiness matter?
Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.
What values do I need to enter?
This calculator takes 8 inputs: Common criteria categories CC1–CC9 fully evidenced, Controls in the control matrix, Controls operating effectively with evidence, Additional trust services categories in scope, Additional categories fully evidenced, Observation window completed so far, Report type, Known control exceptions in the window. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Should I start with Type 1 or Type 2?
Type 1 tests design at a point in time and can be issued quickly, which helps if a customer needs something now. Type 2 tests operating effectiveness across a window and is what enterprise procurement actually wants, so treat Type 1 as a bridge rather than a destination.
Do exceptions mean I failed?
No. Reports routinely contain exceptions with a management response, and buyers read the response as much as the exception. What damages a report is a pattern — several exceptions against the same criterion, or an exception that recurs in the next window after you said it was fixed.
You might also need
- ISO 27001 Compliance CalculatorCommonly used together
- Audit Coverage CalculatorCommonly used together
- Control Effectiveness CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- Residual Risk CalculatorAlso in Compliance & GRC