SOC 2 Gap Assessment Checklist Form
Evaluate your organization's SOC 2 readiness with this focused checklist. Identify and rate your current controls, policies, and practices against SOC 2 criteria.
Which SOC 2 Trust Service Criteria are in scope for your assessment?
*
Security
Availability
Processing Integrity
Confidentiality
Privacy
Do you have documented security policies and procedures?
*
Yes
No
Partially
How would you rate your organization's access control practices?
*
1
2
3
4
5
Which areas currently lack formal documentation? (Select all that apply)
*
Risk Assessment
Incident Response
Vendor Management
Change Management
None of the above
How frequently are risk assessments performed?
*
Annually
Semi-annually
Quarterly
Not performed
Incident Response Plan: How prepared is your team to respond to incidents?
*
Not prepared
1
2
3
4
Fully prepared
5
1 is Not prepared, 5 is Fully prepared
Which of the following technical controls are currently implemented?
*
Multi-factor authentication
Encryption at rest
Encryption in transit
Vulnerability scanning
None of the above
Vendor Risk Management: Rate your current process maturity.
*
No process
1
2
3
4
Fully mature
5
1 is No process, 5 is Fully mature
Gap Assessment Table: For each area, indicate status and add notes.
*
Rows
Status
Notes
Access Control
Met
Partially Met
Not Met
N/A
Incident Response
Met
Partially Met
Not Met
N/A
Risk Management
Met
Partially Met
Not Met
N/A
Change Management
Met
Partially Met
Not Met
N/A
List your top three SOC 2 readiness gaps or concerns.
*
Submit Assessment
Should be Empty: