The Clean OpinionGet your score
How scoring works

Ten questions, scored the way an auditor would.

Each question covers one control area and has four answers, scored 0 to 3: critical gap, major gap, gap, or in place. That’s the same design-and-operation test an auditor applies. Thirty points total, divided by three and shown as a score out of ten. A zero on any question is flagged individually as critical regardless of the total.

SOC 2 Type 2: what the score means

0–36+ monthsFoundational controls are missing — start with the critical items before engaging an auditor.
4–63–5 monthsYou’re closer than most. The gaps below are fixable without a full program rebuild.
7–81–2 monthsMostly there. Close the remaining gaps and start the observation window.
9–10Audit-readyControls are in place and evidenced. The next step is picking a report date.

The 10 control areas

In the order auditors tend to sample them. Three are marked critical: a zero on any of them is flagged first because they produce the most first-year exceptions.

  1. 01
    Logical access · CC6.2criticalLogical access is the control family with the most exceptions in first-year SOC 2 reports. Auditors sample this one every time.
  2. 02
    Onboarding & offboarding · CC6.1 / CC6.3criticalOffboarding gaps are the easiest finding for an auditor: one ex-employee with a live account is an exception.
  3. 03
    Change management · CC8.1Auditors will pull a sample of changes and ask for the approval on each one.
  4. 04
    Vendor management · CC9.2You inherit your sub-processors’ risk. An auditor expects a documented review of each one.
  5. 05
    Incident response · CC7.3 / CC7.4A written, tested plan is table stakes; an untested one is a finding waiting to happen.
  6. 06
    Risk assessment · CC3.2SOC 2 is built on the premise that controls respond to identified risks. No assessment, no premise.
  7. 07
    Policies · CC1.1 / CC5.3Auditors test that policies are approved, current, and acknowledged by staff — not just written.
  8. 08
    Logging & monitoring · CC7.2Logs that nobody reviews don’t count as monitoring.
  9. 09
    Backups & continuity · A1.2 / A1.3An untested backup is a hope, not a control.
  10. 10
    Evidence collection · Audit readinesscriticalFor Type 2, the auditor samples across the whole observation window. Hand-collection at audit time is where readiness projects stall.

This scorecard is a preliminary readiness screen. It is not an audit, an opinion, or a guarantee.

SOX 404: what the score means

0–3Foundational gapsFoundational ICFR controls are missing. Management cannot yet support its own 404(a) assessment.
4–6Material gapsMaterial readiness gaps require a structured remediation program before management testing.
7–8Substantially implementedSubstantially implemented, with targeted gaps to close before the annual assessment.
9–10Strong baselineStrong baseline. Validate scope, 404(b) status, and the evidence trail with the audit committee.

The 10 control areas

Every area is marked critical: a critical-gap answer generates its own high-priority flag regardless of the overall score.

  1. 01
    Management ownership & 404(a) assessment · SEC 33-8238404(a) is management’s report, not the auditor’s. If nobody owns ICFR, nothing else in the program has a foundation.Sources: SEC Release 33-8238; SEC Financial Reporting Manual, Topic 4.
  2. 02
    Risk assessment & SOX scope · AS 2201 ¶21–36Scope is where programs over- or under-spend. A top-down, risk-based scope is the first thing the auditor asks to see.Sources: SEC Management Guidance on ICFR; PCAOB AS 2201, paragraphs 21–36.
  3. 03
    Process documentation & walkthroughs · AS 2201 ¶34–38Walkthroughs are how design gaps get found before testing does. Undocumented processes push that discovery onto the auditor — at audit prices.Sources: PCAOB AS 2201, paragraphs 34–38; SEC Management Guidance on ICFR.
  4. 04
    Journal entries & segregation of duties · AS 2201 ¶24–27 · AS 2110 App. BManagement override runs through the journal. Auditors test the full entry population every year — this is the control they look at first.Sources: PCAOB AS 2201, paragraphs 24–27; PCAOB AS 2110, Appendix B.
  5. 05
    Revenue recognition & recording · AS 2201 ¶21, 28–41Revenue is a presumed fraud risk under the auditing standards, so it is scoped in every year regardless of size.Sources: PCAOB AS 2201, paragraphs 21 and 28–41; SEC SOX 404 implementing release.
  6. 06
    Quarterly & annual financial close · AS 2201 ¶24–27 · SEC §302Most material weaknesses trace back to the close: late reconciliations, unreviewed estimates, and management reviews that can’t show what was actually reviewed.Sources: PCAOB AS 2201, paragraphs 24–27; SEC Section 302 certification rule.
  7. 07
    IT general controls & financial-reporting information · AS 2110 App. B · AS 2201 ¶36, 47Every automated and IT-dependent control inherits the reliability of the system underneath it. Weak ITGCs undermine the whole control set.Sources: PCAOB AS 2110, Appendix B; PCAOB AS 2201, paragraphs 36 and 47.
  8. 08
    Management testing & evidence · AS 2201 ¶44–52Management’s assessment has to stand on its own evidence. Screenshots and self-certifications don’t survive the auditor’s reperformance.Sources: SEC Management Guidance—evidential matter; PCAOB AS 2201, paragraphs 44–52.
  9. 09
    Deficiencies, fraud, changes & §302 certifications · SEC §302 · AS 2201 ¶62–70, 78–81The CEO and CFO certify every quarter. A deficiency nobody aggregated or escalated becomes their personal certification problem.Sources: SEC Section 302 certification requirements; PCAOB AS 2201, paragraphs 62–70 and 78–81.
  10. 10
    SOX 404(b) auditor attestation · SEC FRM Topic 4Filer status changes with public float and revenue. Companies that assume an exemption lasts forever get surprised by an attestation year they didn’t budget for.Sources: SEC Financial Reporting Manual, Topic 4; SEC Accelerated-Filer Compliance Guide.

This questionnaire is a preliminary readiness screen. It does not constitute an audit opinion or replace company-specific evaluation by management, securities counsel, the audit committee, and the external auditor.

Cybersecurity assessment: what the score means

0–3Foundational gapsFoundational controls are missing.
4–6Material gapsMaterial readiness gaps require a structured remediation program.
7–8Substantially implementedSubstantially implemented, with targeted gaps to close.
9–10Strong baselineStrong baseline; validate scope and applicable regulatory requirements.

The 10 control areas

Every area is marked critical: a critical-gap answer generates its own high-priority flag regardless of the overall score.

  1. 01
    Governance & oversight · NIST CSF 2.0 GovernWithout an accountable executive and board-level reporting, every other control is discretionary. For SEC registrants this also feeds the annual governance disclosure.Sources: NIST Cybersecurity Framework 2.0; SEC Cybersecurity Risk Management and Governance Requirements.
  2. 02
    Asset inventory, data classification & risk assessment · NIST CSF 2.0 IdentifyYou can’t protect what you haven’t inventoried. Unknown cloud services and unowned data stores are where incidents start.Sources: NIST CSF 2.0—Govern and Identify; CISA Cross-Sector Cybersecurity Performance Goals.
  3. 03
    Identity, authentication & access · NIST CSF 2.0 PR.AAStolen credentials are the most common initial access vector. MFA gaps and orphaned accounts are the findings that show up in every breach report.Sources: NIST CSF 2.0—Identity Management, Authentication, and Access Control; CISA Cybersecurity Performance Goals.
  4. 04
    Workforce security & awareness · NIST CSF 2.0 PR.ATPhishing still opens most doors. Training that isn’t tested and followed up is a policy acknowledgment, not a control.Sources: NIST CSF 2.0—Awareness and Training; CISA Cross-Sector Cybersecurity Performance Goals.
  5. 05
    Secure configuration, vulnerability & patch management · NIST CSF 2.0 PR.PSKnown exploited vulnerabilities on internet-facing systems are the second most common way in. Scanning without verified remediation doesn’t reduce that risk.Sources: NIST CSF 2.0—Platform Security and Risk Assessment; CISA Cross-Sector Cybersecurity Performance Goals.
  6. 06
    Logging, monitoring & detection · NIST CSF 2.0 DetectDwell time is decided here. Logs nobody reviews — or that an attacker can edit — mean the first sign of a breach is the ransom note.Sources: NIST CSF 2.0—Detect; CISA Cross-Sector Cybersecurity Performance Goals.
  7. 07
    Incident response & external disclosure · NIST SP 800-61r3 · SEC 8-K 1.05For SEC registrants the materiality clock is four business days. A plan that hasn’t been exercised is a plan that will be improvised.Sources: NIST SP 800-61 Revision 3; SEC Cybersecurity Incident Disclosure Requirements.
  8. 08
    Third-party & supply-chain security · NIST SP 800-161r1Your vendors’ breaches are your breaches. If you can’t list who touches sensitive data, you can’t assess the exposure.Sources: NIST SP 800-161 Rev. 1 Update 1; NIST CSF 2.0 Supply-Chain Quick-Start Guide.
  9. 09
    Backups, recovery & resilience · NIST CSF 2.0 RecoverRansomware is a backup test you didn’t schedule. Backups reachable with the same compromised credentials aren’t backups.Sources: NIST CSF 2.0—Recover and Technology Infrastructure Resilience; CISA Cross-Sector Cybersecurity Performance Goals.
  10. 10
    Control testing & evidence · NIST CSF 2.0 ProfilesCustomers, insurers, and regulators all ask the same question: show me. A program that only assembles evidence on request can’t answer it.Sources: NIST CSF 2.0 and Organizational Profiles; CISA Cross-Sector Cybersecurity Performance Goals.

This questionnaire is a preliminary cybersecurity readiness screen. It is not a certification, audit opinion, penetration test, or determination of compliance with every law or industry-specific requirement.

What it isn’t

It is not an audit, an opinion, or a guarantee. It’s a structured first conversation, scored so that you and the auditor start from the same page. Your answers are yours; the report is yours whether or not you ever book a call.

Get your readiness score