Assess SOC 2 readiness across the CC1–CC9 common criteria, your control matrix, the observation window and known exceptions.
SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten. Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.
SOC 2 Readiness
Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30).
Readiness = 0.40 × CC1–CC9 coverage + 0.30 × controls operating effectively + 0.15 × additional category coverage + 0.15 × observation window completed, minus 3 points per known exception (capped at 30). SOC 2 is not a checklist against a fixed control count — you describe your own controls and the service auditor tests whether they meet the trust services criteria, which is why the control matrix is scored against your own total. Exceptions carry a direct penalty rather than being averaged away, because a single untreated exception changes the wording of the opinion, and the observation window is weighted separately since a Type 2 report needs elapsed time no amount of effort can shorten.
Most SOC 2 programmes slip because the observation window starts before the controls actually operate, producing a report full of exceptions that customers then read. This is a readiness estimate; only a licensed CPA firm acting as service auditor can issue the report or the opinion.
This calculator takes 8 inputs: Common criteria categories CC1–CC9 fully evidenced, Controls in the control matrix, Controls operating effectively with evidence, Additional trust services categories in scope, Additional categories fully evidenced, Observation window completed so far, Report type, Known control exceptions in the window. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Type 1 tests design at a point in time and can be issued quickly, which helps if a customer needs something now. Type 2 tests operating effectiveness across a window and is what enterprise procurement actually wants, so treat Type 1 as a bridge rather than a destination.
No. Reports routinely contain exceptions with a management response, and buyers read the response as much as the exception. What damages a report is a pattern — several exceptions against the same criterion, or an exception that recurs in the next window after you said it was fixed.