Framework explainer

SOC 2 Readiness Versus a SOC 2 Audit

Understand who prepares the control environment, who independently evaluates it, and why clear responsibilities reduce rework.

By Shawn Thornton5-minute readReviewed July 2026
Direct answer

SOC 2 readiness defines scope, implements controls, remediates gaps, and organizes evidence. The independent SOC 2 examination is performed by a licensed CPA firm. Readiness prepares the organization; the CPA firm evaluates and reports on the controls.

Readiness and examination are different functions

AreaReadinessExamination
ObjectiveBuild a defensible control environment and evidence setEvaluate management's system description and controls
ProviderInternal team, readiness consultant, or security partnerIndependent licensed CPA firm
OutputsScope, gap analysis, remediation plan, policies, and evidence planSOC 2 report and independent conclusion

What readiness should accomplish

  • Define the product, systems, people, data, locations, and vendors in scope.
  • Select applicable Trust Services Criteria based on buyer needs.
  • Translate criteria into controls that match actual operations.
  • Assign control owners and evidence expectations.
  • Remediate technical and operational gaps.
  • Operate controls long enough to produce reliable evidence.

Responsibility remains with management

Management

Owns scope, risk decisions, policy approval, controls, evidence, and ongoing maintenance.

Readiness partner

Advises, structures, implements, coordinates, and validates preparation work.

CPA firm

Tests selected controls, evaluates the description, and issues the independent report.

After the report

Access reviews, vendors, incidents, training, evidence, and risk governance must continue.

Frequently asked questions

Is a formal readiness engagement mandatory?

No, but the underlying preparation is. Structured readiness reduces disruption and surprises.

Can the same firm provide readiness and examination services?

The exact services and independence requirements matter. The CPA firm should explain the permitted boundaries.

Does readiness prove compliance?

No. Readiness is preparation and gap identification, not an independent conclusion.

What happens after the report?

The control environment must continue to operate and generate evidence.

Recommended next step

Establish scope and ownership before committing to an examination window.

A readiness review clarifies the control burden, remediation sequence, evidence sources, and coordination needs.

Book a Compliance Clarity CallCompare Type I and Type II

Sources and editorial note

Based on official AICPA and NIST guidance. This resource is educational and is not legal advice or a guarantee of compliance.

How the two fit together in sequence

Readiness and examination are not alternatives. They happen in order, and the order matters because an examination tests evidence that only exists if readiness produced it. A typical path looks like this.

Scope

Decide which product, systems, people, data, locations, and vendors are in scope, and which Trust Services Criteria apply. Security, the common criteria, is always included. Availability, Processing Integrity, Confidentiality, and Privacy are added only where customers or the business actually require them.

Gap analysis

Compare the criteria against how the organization currently operates, not against how a policy says it operates. This is where most of the real findings surface.

Remediation

Close the gaps. This is implementation work: configuring access controls, standing up logging, formalizing onboarding and offboarding, establishing vendor review, writing procedures people will actually follow.

Operate

Run the controls long enough to generate evidence. For a Type II, this is the observation period. Controls that were configured the week before the period ends will not produce a clean report.

Examination

An independent licensed CPA firm evaluates management's system description and tests the controls. SOC 2 examinations are assertion-based examination engagements performed under AT-C section 205, as amended by SSAE No. 21.

Why the same firm usually cannot do both

A CPA firm's independence can be impaired if it designed or implemented the controls it would then examine. That is the reason readiness and examination are typically separated between a readiness partner and an audit firm.

The boundary is not always intuitive, and it is the CPA firm's call, not the readiness partner's. Ask the firm directly what it can and cannot do while remaining independent, and get the answer before work starts rather than after. Discovering an independence problem late can mean re-running remediation with a different provider.

Where readiness goes wrong

  • Scope set to impress rather than to match demand. Adding criteria nobody asked for multiplies the control and evidence burden with no commercial return.
  • Policies written that do not describe real operations. A policy the team does not follow is worse than no policy, because the examination will test against it.
  • Controls implemented without named owners. Unowned controls stop operating quietly, and the gap only appears during testing.
  • Evidence treated as a final step. Evidence is a byproduct of controls running. It cannot be assembled retroactively for a period that has already passed.
  • The observation period started too early. Beginning the clock before remediation is finished means the report covers a period that includes the gaps.

What readiness cannot do

Readiness does not produce a report, an opinion, or any form of assurance a customer can rely on. It cannot certify compliance, because SOC 2 is an attestation framework and there is no SOC 2 certification. It cannot guarantee the examination result, because the conclusion belongs to the CPA firm.

It also does not transfer responsibility. Management continues to own scope, risk decisions, policy approval, the accuracy of the system description, and the representations made to the auditor and to customers. A readiness partner prepares the facts, options, and evidence. The decisions remain with leadership.

This resource is educational and is not legal advice, an audit, or a guarantee of any examination outcome. Smart Biz iT supports readiness, implementation, and operations. Independent licensed CPA firms perform SOC 2 examinations and issue reports.