Auditen

Are you ready for a SOC 2 audit?

17 questions an auditor will effectively be asking anyway. You get a readiness score, a prioritised list of gaps, and a link to what each gap actually requires.

Nothing is submitted, stored, or sent anywhere. The whole thing is scored in your browser. Your answers are kept in this browser and in the address bar, so you can bookmark the result or send the link to a colleague — no account, no email.

Access

Every person has a unique named account for production — no shared or generic logins.

Multi-factor authentication is enforced on production, cloud consoles and the identity provider.

Access is revoked within one business day of someone leaving or changing role.

Someone reviews who has production access at least quarterly, and the review is evidenced.

Change management

Production code changes are peer-reviewed before they are merged.

An automated test or CI gate must pass before a change can be deployed.

You can trace any deployed change back to the person who approved it.

Risk

A formal risk assessment has been carried out and documented in the last 12 months.

You keep a risk register with a named owner and treatment plan per risk.

Monitoring & response

Security-relevant logs are centrally collected and retained for at least 90 days.

Alerts go somewhere a named person is responsible for triaging.

The incident response plan has been tested — tabletop or real — in the last 12 months.

Vendors

You maintain an inventory of vendors and subprocessors that can reach customer data.

Vendor security is reviewed before onboarding and at least annually afterwards.

Governance

Written security policies exist and staff formally acknowledge them each year.

All staff complete security awareness training annually, with records kept.

Scope

You have decided between Type I and Type II, and know your observation window.

This is an informal self-assessment to help you prepare, not an audit, an opinion, or a guarantee of any outcome. Only a licensed CPA firm can perform a SOC 2 examination and issue a report.