Security / SOC 2 readiness

SOC 2 readiness for Australian software companies.

An enterprise customer or a US partner asked for a SOC 2 report. Readiness is the work before the audit.

SOC 2 readiness is the work before the audit. Sorami selects the Trust Services Criteria that apply, runs a gap assessment against them, and builds the evidence index the auditor will ask for. The report itself is issued by a licensed CPA firm, which Sorami is not, and most contracts asking for a SOC 2 report mean Type II.

Score yourself first

How ready you actually are

Twenty questions across the common Trust Services Criteria. Answer no if you cannot show an auditor the evidence today.

Scope and governance

Have you decided which Trust Services Criteria are in scope, beyond Security?

Is the system description limited to the product your customer buys?

Does someone own each control by name rather than by team?

Has a risk assessment been done in the last 12 months?

Access control

Is multi-factor authentication enforced on every production and administrative path?

Are user access reviews performed and recorded at least quarterly?

Is access revoked within one business day of someone leaving?

Are production credentials held in a secrets manager rather than in code or a spreadsheet?

Change and development

Does every production change go through review and leave a record?

Is there a separate environment for testing before production?

Are vulnerabilities in dependencies tracked with an owner and a due date?

Has a penetration test been run in the last 12 months?

Monitoring and response

Are security-relevant logs centralised and retained for at least a year?

Do alerts reach a person who is on the hook to respond?

Is there an incident response plan that has been exercised, not just written?

Do you notify affected customers on a defined timeline?

Vendors, people and evidence

Do you review subservice organisation reports for your critical vendors?

Do staff complete security training and accept policies on a recorded schedule?

Are backups tested by restoring, not just by checking the job succeeded?

Could you produce a year of evidence for any control without a scramble?

20 questions. Answer them all and your score appears here.

Nothing is sent anywhere. The scoring runs in your browser.

Self-assessment. Not an audit opinion.

If the result is useful, send us the answers and we will scope against them.

Want to send this to a colleague? It has its own page: the SOC 2 readiness self-check, with the scoring bands explained.

Included

What the work covers

  • Scope and Trust Services Criteria selection.
  • Gap assessment against each selected criterion.
  • Policy set drafted to fit how your team already works.
  • Control implementation plan with named owners.
  • Evidence index: what the auditor asks for and where it lives.
Excluded

What we do not do

  • The audit itself. A licensed CPA firm attests.
  • Compliance tool licences.
  • Operating the controls for you.
The criteria this work maps to

Named, so you can check us.

The 2017 AICPA Trust Services Criteria with revised points of focus, 2022. Security is the only required category, and the 33 common criteria sit across CC1 to CC9. The rows below are the ones that generate the most evidence work.

Common criteria that drive the evidence
ReferenceWhat it requiresWhat readiness produces
CC6.1Logical access security software, infrastructure and architecturesAccess model, and the configuration that enforces it.
CC6.2Registration and authorisation before credentials are issuedAn approval record per account. Auditors sample joiners and leavers.
CC6.3Role-based access, least privilege and segregation of dutiesQuarterly access reviews with the decisions retained.
CC6.6Protection against threats from outside the system boundaryWhere a penetration test report becomes evidence.
CC7.1Detection of configuration changes and new vulnerabilitiesScan output with an owner and a remediation record.
CC7.2Monitoring system components for anomaliesAlerting that demonstrably reached a person.
CC7.4Response to identified security incidentsAn incident response programme, exercised.
CC8.1Change managementReview, test and approval evidence for production changes.
CC9.2Vendor and business partner risk managementSubservice organisation reports you actually read.

Source. AICPA Trust Services Criteria. Identifiers verified against the primary source, not quoted from a summary.

Category selection changes the criteria in scope. Adding Availability or Confidentiality adds criteria and adds evidence, so the selection decision comes before any tooling decision. Sorami does not attest. A licensed CPA firm issues the report.

Failure modes

What usually goes wrong.

  • Evidence collected by hand in the last two weeks.
  • Scope set to everything instead of the product the customer buys.
  • Type II chosen first, missing the deal deadline.
  • A tool bought before anyone decided the scope.
The evidence index

What the auditor will actually ask for.

Ten lines from an evidence index, showing the form each answer takes.
Control areaEvidence an auditor accepts
Access controlQuarterly access review export, signed. Joiner and leaver tickets with dates.
AuthenticationIdentity provider policy screenshot showing MFA enforcement and the exception list.
Change managementPull request history with reviewer, plus the deployment record for a sampled change.
Vulnerability managementDependency scan output, the triage decision and the remediation ticket.
Penetration testingReport with dates and scope, and the retest record for the findings raised.
Logging and monitoringRetention configuration, one alert that fired, and the response it triggered.
Incident responseThe plan, the last exercise notes, and any real incident record for the period.
Backup and recoveryA restore test with the date, the operator and the outcome.
Vendor managementVendor inventory, criticality rating and the subservice report you reviewed.
PeopleTraining completion export and policy acceptance records for the period.

Extract. The full index is built against your selected criteria during the engagement.

Deciding between the two report types first? Read SOC 2 Type I vs Type II. For running the controls after readiness closes, see the vCISO retainer. Not sure how far off you are? Take the two minute self-check at the top of this page.

Questions before you book

Practical answers.

Is Sorami SOC 2 audited?

No. Sorami has not undergone a SOC 2 audit and cannot issue a SOC 2 report. Only a licensed CPA firm can attest.

Type I or Type II?

Type I is a point-in-time design check and usually unblocks the deal. Type II covers three to twelve months of operation. Read the contract wording before choosing.

Do we need a tool like Vanta or Drata?

Not always. A tool speeds evidence collection. It does not decide scope or close a control gap.

Can you do the audit?

No. We prepare you and liaise with the auditor you select. Doing both would defeat the point.

Let’s scope it

Ready to scope soc 2 readiness?

Send the requester wording and your deadline. We will confirm scope and fee before any work starts.

Request a quote

Last reviewed: