The Clean OpinionGet your score
Free · 10 questions · About four minutes

Find out if you’d pass a SOC 2 audit before a customer asks.

A readiness scorecard built by a licensed CPA firm with CISSP auditors on staff. Answer ten questions about your controls and get a score, a gap list, and a straight answer — no sales call required.

No account neededResults emailed as a PDFReviewed by a human auditor
Sample result
6
out of 10SOC 2 Type 2 · Likely 3–5 months out
What an auditor would flag first
Evidence collectionGap
Vendor managementGap
Logical accessIn place
Onboarding & offboardingIn place
1,000+completed engagements
CPA + CISSPlicensed accountants and security auditors under one roof
1 business dayguaranteed response on every engagement
Mid-market only$10M–$100M companies in the US and Canada
Three reasons people land here

Pick the audit you’re being asked for. The scorecard adapts.

Each path asks different questions because each auditor looks for different evidence. You’ll be scored against the standard you’ll actually be examined on.

How scoring works

Value first. The sales call is optional and comes last.

01
Answer ten questions about your controls

Access reviews, vendor management, incident response, evidence collection. The questions are the ones an auditor asks in the first meeting — written by the people who run those meetings.

02
Get your score and gap list on the spot

A number out of ten, a realistic time-to-audit, and the specific controls that would be flagged first. Emailed to you as a PDF with a reference number you can keep.

03
If you want, talk it through with the auditor — 30 minutes, no pitch

Your results go to Carl Grifka at Alpha Secure, who reads every one. Book a call if the gap list raises questions; ignore it if it doesn’t. Either way, you keep the report.

Who reads your results

An auditor, not a sales rep.

Alpha Secure LLP is a licensed CPA firm fused with a cybersecurity audit practice. It serves mid-market companies that the largest firms don’t prioritize — and that’s exactly who this scorecard is for.

SOC 1 · SOC 2 · SOC 3SOX 404Cyber assessmentInternal audit
Carl Grifka
Carl GrifkaCISSP · CISA · CISM · PMP

Internal controls and SOC reporting specialist. Eighteen years in IT risk advisory, most of it at a top-five national accounting firm, before joining Alpha Secure as a principal. He wrote the questions you’re about to answer.

Read Carl’s articles
From the practice

What the auditor wishes you knew before the kickoff.

All articles

Ten questions now beats a failed audit in nine months.

Free, takes four minutes, and you keep the report whether or not you ever talk to us.