Free calculator · Cloud
Check your SOC 2 readiness against the Trust Services Criteria
Rate 20 example controls mapped to the AICPA Common Criteria, plus a few for each optional category you put in scope. See a score for each criteria family, a readiness band, a gap list with access, operations and change gaps first, and a timeline for a Type 1 or Type 2 report.
How this is calculated
You rate 20 example controls mapped to the Common Criteria (CC1 to CC9) of the AICPA 2017 Trust Services Criteria, plus two to four for each optional category you select. The scoring and the bands are QuantmHill's own convention for planning, not an AICPA scale.
Step by step
- Score each control: in place with evidence 1, partly or undocumented 0.5, not in place 0.
- Score each criteria family (CC1 to CC9, and A1, C1, PI1 or P when in scope) as the average of its controls.
- Overall score: the average of every control in scope.
- Band: early below 50%; developing from 50% to below 80%; ready for a readiness review at 80% or more, unless any control in CC6, CC7 or CC8 is not in place, which keeps it at developing.
- Gap list: controls not in place in CC6 to CC8 first, then other controls not in place, then partly in place, each in criteria order.
- Timeline: for Type 1, the months you plan to close gaps; for Type 2, those months plus the observation period. The auditor's reporting time is added by your auditor, not by the tool.
Default assumptions
Assumptions marked adjustable can be changed in the calculator; the others are fixed parts of the model.
| Assumption | Default | Sources |
|---|---|---|
| Report typeadjustable | Type 2 | |
| Type 2 observation periodadjustable | 6 months | |
| Time to close gaps before the report date or observation periodadjustable | 3 months | None |
What this doesn’t model
- It is a self-assessment of example controls, not an examination. It can't test evidence, and only an independent CPA firm can issue a SOC 2 report.
- The questions don't cover every criterion or point of focus, such as physical access (CC6.4) or fraud risk (CC3.3).
- Every control counts equally, though auditors weigh controls by risk and by the commitments in your system description.
- The timeline leaves out auditor selection, scoping and the auditor's reporting time.
- Encryption, multi-factor authentication and the other controls shown are common examples; the criteria don't require specific technologies.
Sources
- AICPA & CIMA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022) (30 September 2023 (page date)). Accessed . The criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy used in SOC 2 examinations. The PDF needs a free AICPA & CIMA account.
- AICPA & CIMA, 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022) (9 July 2025 (page date)). Accessed . Benchmarks for preparing and evaluating the description of your system that goes into a SOC 2 report.
- AICPA & CIMA, SOC 2 Reporting on an Examination of Controls at a Service Organization (guide) (Updated as of 15 October 2022). Accessed . The AICPA guide for SOC 2 examinations, performed by CPAs, covering the description of the system and the design and effectiveness of controls.
- Journal of Accountancy (AICPA), Explaining the 3 faces of SOC (13 June 2016). Accessed . SOC 1 and SOC 2 both have type 1 and type 2 reports: type 1 covers the design of controls as of a specified date; type 2 adds an opinion on their operating effectiveness throughout a specified period.
- Journal of Accountancy (AICPA), Promises of 'fast and easy' threaten SOC credibility (1 February 2026). Accessed . Auditors warn that 'fast and easy' SOC reports can come at the expense of quality, and that 'compliance' is a term never used in SOC 2 examinations.
- Amazon Web Services, SOC FAQs. Accessed . An example of a Type 2 period: AWS's SOC 2 reports each cover 12 months, ending 31 March or 30 September.
Last reviewed by the QuantmHill engineering team. Found an error?
Link to or cite this tool
Writing about this topic? Link to the calculator or cite it. Its method, defaults and sources are all on this page, so readers can check the numbers.
Embed this calculator
You can put this calculator on your own site for free. Paste the code below where it should appear. It loads the same calculator in a frame, with a link back to this page for the full method and sources.
The credit line links to this page with the anchor text “QuantmHill”. You may edit it, add rel="nofollow" or remove it — the calculator works the same either way. Add ?theme=light or ?theme=dark to the iframe address to fix its colour scheme; otherwise it follows the visitor's system setting.
Add this once per page, after the iframe, if you want the frame to grow and shrink with the calculator instead of using the fixed height above. It accepts messages from quantmhill.com only and resizes only the frame that sent them.
Frequently asked questions
A Type 1 report covers whether your controls are suitably designed as of a specified date. A Type 2 report adds an opinion on whether they operated effectively throughout a specified period, so it needs an observation period before the auditor can report. Both are issued by an independent CPA firm.
It is agreed with your auditor and has to be long enough for them to judge how controls operated. The tool lets you plan with 3, 6 or 12 months; AWS's own SOC 2 reports, for example, each cover 12 months. Add the auditor's time to write the report, which only they can tell you.
Every SOC 2 covers Security, the Common Criteria CC1 to CC9: control environment, communication, risk assessment, monitoring, control activities, access, system operations, change management and risk mitigation, including policies, vendors and incident response. You can add Availability, Confidentiality, Processing Integrity and Privacy if your customers ask for them.
No. The score reflects your own answers about example controls. Only an independent CPA firm's examination can say whether your controls meet the criteria, and the tool reports readiness for a readiness review, not an audit result. We can help prepare the evidence; the opinion is the auditor's.
Access controls (CC6), system operations such as monitoring and incident response (CC7) and change management (CC8) are where much of the day-to-day evidence comes from. If any of those controls is not in place, the tool keeps the band at developing even when the overall score reaches 80%.
No. Each question is an example control with the criteria reference it addresses, such as CC6.1. The criteria themselves are published by the AICPA, and your own controls can meet them in other ways; the points of focus are guidance, not a checklist.
Want an engineer to check your numbers?
Send us your inputs and the decision you're weighing. We'll reply within one business day with an honest read on whether we can help.