ISMS Copilot

Last updated: 2026-08-13 · Jurisdiction: United States (AICPA attestation)

How to run a SOC 2 gap analysis

A SOC 2 gap analysis compares the system you actually run against the Trust Services Criteria a CPA firm will attest. It is the first real piece of work on the road to a Type 1 or Type 2 report. This is a vendor-neutral method. No product is required to follow it. We link our free tools where they save you a day.

The short version

Pick Type 1 or Type 2. Write the system description. Keep Security (CC1 to CC9) and only elect extra criteria you will evidence. Walk each in-scope criterion to a control, an owner, and expected evidence. Name complementary user-entity controls before the firm does. If you want Type 2, fill an evidence calendar for the observation window. Then hand a CPA firm a pack. They still issue the report.

What a SOC 2 gap analysis is, and what it is not

It is a planning tool. You run it before you pay for fieldwork, so the firm confirms what you already know. It is deliberately yours to run: your team, your system, your words.

It is not three other things. It is not the readiness assessment a firm sells you, which is their paid look at the same material. It is not the examination itself, which only a licensed CPA firm can perform. And it is not an ISO 27001 gap analysis, which measures a management system against a certifiable standard and aims at a certificate, not an attestation report. Same overlapping controls. Different output, different auditor, different buyer.

What you measure against: criteria, not a control catalog

SOC 2 does not hand you 93 numbered controls. It hands you criteria. You design the controls. That is the page-unique difference from ISO 27001, and it is why two good SOC 2 reports can describe different control sets for the same criterion.

Security (always in)

The common criteria CC1 through CC9. Governance, communication, risk, monitoring, control activities, access, operations, change, and vendor / risk mitigation. This is the minimum SOC 2. Most first reports are Security only.

The four you elect

Availability, Processing Integrity, Confidentiality, Privacy. Add them when the system and the buyer require them. Each one is extra points of focus and extra evidence, not a free logo on the report cover.

Version note: this guide uses the 2017 Trust Services Criteria with the 2022 revised points of focus, which is the version still in effect for current SOC 2 examinations. Wording here is original paraphrase. The AICPA owns the official criteria text. Obtain it from AICPA & CIMA.

How to run a SOC 2 gap analysis, step by step

  1. 1

    Decide Type 1 or Type 2 before you measure anything

    SOC 2 produces an attestation report from a licensed CPA firm, not a certificate you hang on the wall. Type 1 is a snapshot of whether controls are suitably designed at a date. Type 2 adds operating effectiveness over an observation window, typically three to twelve months. Pick the report type first. A Type 1 gap analysis is a design review. A Type 2 gap analysis is a design review plus an evidence calendar: tickets, access reviews, backup tests, incident logs, vendor assessments. Teams that skip this choice measure the wrong thing and then wonder why the auditor asks for six months of screenshots they never kept.

  2. 2

    Write the system description, then gap against that system

    ISO 27001 asks you to scope an ISMS. SOC 2 asks you to describe a system: the services you sell, the infrastructure they run on, the software, the people, the procedures, and the data. That description appears in the report. If you have not written it, you do not know which Trust Services Criteria apply or which complementary user-entity controls (CUECs) your customers must operate. Draft it first, even as a one-page outline. Then gap only against that system. Expanding the description later expands the gap list; shrinking it is how teams hide services the buyer actually uses.

  3. 3

    Lock the criteria: Security is mandatory, the rest are optional

    Every SOC 2 includes Security, expressed as the common criteria CC1 through CC9 (control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management, risk mitigation). The other four categories (Availability, Processing Integrity, Confidentiality, Privacy) are elected. Each one you add multiplies points of focus and evidence. Elect them because the buyer or the system requires them, not because a sales deck listed five logos. Privacy in particular is not a synonym for “we have a privacy policy.” It is a criterion about how the system collects, uses, retains, discloses, and disposes of personal information.

  4. 4

    Walk each in-scope criterion down to the points of focus

    The 2017 Trust Services Criteria (with the 2022 revised points of focus) are what the CPA firm attests against. Points of focus are illustrative, not a mandatory checklist. Use them as prompts, not as a second control catalog. For each in-scope criterion, write four things in your own words: the control you actually operate, the evidence it produces, the owner, and whether it is ready for Type 1 (design) or Type 2 (design plus operation). Score absent, partial, or in place. A “partial” with no note on what would close it is theatre.

  5. 5

    Name the complementary user-entity controls before the firm does

    If your product is only secure when the customer turns on SSO, that is a complementary user-entity control. It belongs in the system description. Auditors find undeclared CUECs late, and late is how reports get qualified. Walk every control that assumes the customer did something (access reviews of their own users, encryption of data they upload, configuration of webhooks) and either you operate it, or they do and you disclose it.

  6. 6

    Build the Type 2 evidence calendar, or stop at Type 1 on purpose

    Type 2 is not “Type 1 plus nicer fonts.” It is a period of operation. For every control you scored in place, name the artifact (ticket, screenshot, export, meeting notes), the frequency (weekly access review, quarterly vendor review, annual pen test), and the first date you can prove it ran. If that calendar is empty for the next ninety days, you are not Type 2 ready. Issue Type 1, start the clock, and re-run this gap analysis against the calendar before you book the Type 2 fieldwork.

  7. 7

    Hand a CPA firm a pack, not a vibe

    No tool, including this one, issues a SOC 2 report. A licensed CPA firm does, under the attestation standards (SSAE 18 and the AT-C sections that govern examination engagements). The gap analysis exists so that firm walks into fieldwork with a draft system description, a scored criterion list, a CUEC list, and an evidence calendar. That is the difference between a two-week readiness assessment and a six-month rewrite. You still pay the firm for the opinion.

Two free tools that sit next to this method

The SOC 2 red flags checker walks report-quality signals a reviewer looks for (including who is allowed to issue the report). The ISO 27001 to SOC 2 control mapper is for teams harvesting both outputs from one control set. Neither replaces the seven steps above.

Five mistakes that make a SOC 2 gap analysis useless

  • Treating points of focus as mandatory controls

    They illustrate the criterion. Implementing all of them as if they were a catalog is how a 40-control program becomes a 200-row spreadsheet nobody owns.

  • Skipping the system description

    If you have not named the system, every criterion is ambiguous. Write the description first.

  • Electing all five categories on day one

    Security-only Type 1 is a real first report. Privacy and Availability are extra programs. Add them when the buyer or the data requires them.

  • Calling Type 1 a Type 2

    Policies are design. Type 2 is operation over time. If the evidence calendar is empty, you are not Type 2 ready.

  • Hiding complementary user-entity controls

    If the control only works when the customer does something, write that down. The firm will find it anyway.

Where a gap analysis sits in the SOC 2 journey

ActivityWhenWho runs itOutput
Gap analysisBefore you book the firmYour teamRemediation list, draft system description, CUECs, evidence calendar
Readiness assessmentOptional, paidThe same CPA firm, or anotherTheir view of remaining gaps
Examination (Type 1 or Type 2)When the pack is readyLicensed CPA firmThe SOC 2 report and opinion

Want the product-assisted version? See SOC 2 gap analysis with ISMS Copilot. For US SaaS framing, see ISMS Copilot for US SaaS startups. For the framework hub, see SOC 2 Copilot.

Frequently asked questions

Is a SOC 2 gap analysis the same as an ISO 27001 gap analysis?

No. ISO 27001 measures a management system against clauses 4 to 10 and 93 Annex A controls, and the output is a path to an accredited certificate. SOC 2 measures a described system against the Trust Services Criteria, and the output is a pack a CPA firm can attest. Control language overlaps (access, change, vendors), but the artifact, the auditor, and the buyer signal are different. See /learn/how-to-run-an-iso-27001-gap-analysis for the ISO method, and /compare/iso-27001-vs-soc-2 for which to do first.

Do points of focus have to be implemented one-for-one?

No. Points of focus illustrate the criterion. They are not themselves criteria. A firm can conclude a criterion is met with a different control set than the published points of focus, if the design (and, for Type 2, the operation) addresses the criterion. Treating every point of focus as a mandatory control is how gap lists balloon past what the report needs.

Who issues the SOC 2 report?

A licensed CPA / AICPA member firm, under SSAE 18. Software can draft policies, map criteria, and assemble evidence. It cannot sign the opinion. If a vendor implies otherwise, that is a red flag; the free SOC 2 red flags checker at /resources/soc2-red-flags-checker is built around that class of problem.

How long does a first SOC 2 gap analysis take?

A focused Type 1 design review for a single-product SaaS with Security only can be done in days if someone owns the system description. Adding optional criteria, multi-product scope, or a Type 2 evidence calendar stretches it into weeks. The bottleneck is almost never writing policies. It is agreeing what the system is.

Should we do SOC 2 or ISO 27001 first?

If the next closed deal is a US enterprise buyer, Type 1 first. If the next deal is an EU tender or a regulated buyer that asks for a certificate, ISO 27001 first. If you sell both, build one control set and harvest both outputs. Sequence by whichever buyer closes revenue. See /compare/iso-27001-vs-soc-2.

Primary sources

  • AICPA, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (with revised points of focus, 2022). www.aicpa-cima.com (checked 2026-08-13).
  • AICPA, Statement on Standards for Attestation Engagements No. 18 (SSAE 18), the attestation standard under which a CPA firm issues a SOC 2 examination report. www.aicpa-cima.com (checked 2026-08-13).
  • AICPA, SOC 2 overview (what a SOC 2 report is, who may issue it, and how it differs from a certification). www.aicpa-cima.com (checked 2026-08-13).

Written and maintained by the ISMS Copilot team. Last reviewed 2026-08-13.

The Trust Services Criteria and SSAE 18 are AICPA intellectual property. This guide paraphrases in original wording and does not reproduce official criteria text. It is educational content, not an attestation, not legal advice, and not a substitute for a licensed CPA firm. Only that firm issues the SOC 2 report.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.