Sylvan Assurance SOC 2 Audit-Readiness · Free Edition ← Free assessments
Free SOC 2 audit-readiness assessment

How audit-ready is your SOC 2 programme?

Twenty-four plain-English questions across the eight control areas this assessment covers on the way to a SOC 2 (System and Organization Controls 2) examination — scope, governance, access, change management, vendors and sub-processors, monitoring and incident response, availability, and evidence. You get a scored snapshot of where you sit on the Readiness Ladder, area by area. About ten minutes. No email required.

Plain-English readiness — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.

Don't take our word for it — verify in 30 seconds.
  1. Right-click this page and choose Inspect, then open the Network tab.
  2. Start the assessment and answer a few questions.
  3. Watch the list: nothing leaves the page while you answer — your answers stay on your device.
What does this assessment cover?

The eight control areas this assessment covers on the way to a SOC 2 examination. The assessment walks the same ground an auditor does: scope and the report you need (Type I versus Type II, and which Trust Services Criteria apply), governance and risk, access control and identity, change management and development, vendors and sub-processors, monitoring and incident response, availability, and evidence and continuous operation.

What you get. A weighted readiness score and your band on the six-rung Readiness Ladder — from just getting started to audit-ready — plus an area-by-area breakdown with plain-English next steps. One honest note from the books: the goal is a scope proportionate to your size and risk — a small team can be genuinely audit-ready without an enterprise control set.

What it isn't. This is general guidance. It is not a SOC 2 audit, not a readiness opinion from a licensed CPA (Certified Public Accountant) firm, and not legal advice. Every recommendation is optional. Following it can reduce common gaps but does not guarantee any audit outcome. Responsibility for your programme remains with you.

Start here — the free edition

Version 1 · Updated 2026-07-21

For a founder or first security hire who has just been asked for a SOC 2 and needs the plain-English version first.

When you have worked through this, you will have: your free readiness result, and the five first moves toward an audit. Download this as a PDF.

The one guide
Your First SOC 2 Moves
PDF · 10 min to read · The founder or first security hire who has just been asked for a SOC 2
Three pages on what a SOC 2 report actually is, the five moves that get you ready, and what a first year tends to cost.
Reach for it when: First, if SOC 2 is new to you — and worth handing to whoever has to approve the spend.
You finish with: A clear idea of what SOC 2 involves, what a first year is likely to cost, and which five things to do first.
The interactive assessment — a short questionnaire that scores where you stand and points at the gaps.

When you outgrow the free tier, the Solo toolkit turns these five into a worked readiness path — the scoping notes, the control list, and the evidence you will be asked for — with a Start here catalog to sequence them. See the Solo, Team and Pro editions →

When you're ready for the full toolkit

The full edition gets you audit-ready, document by document.

Everything behind this free assessment — the checklist, policy set, evidence tracker, and audit-prep kit that close the gaps before you spend $20,000. Three editions to fit how you work.

See the full toolkit & pricing →

One-time purchase · files you own forever · 30-day money-back guarantee.