Loading tools
Loading tools
Applies the AICPA 2017 Trust Services Criteria (with 2022 revised Points of Focus) and the 2018 SOC 2 Description Criteria — CC1–CC9 governance, risk, access, change, operations, vendors and audit engagement — to score your Type I / Type II audit readiness and sequence the evidence window before you engage a CPA firm.
Is there a named owner of security at leadership level (CISO, CTO, or designated security lead) with defined accountability and authority?
Auditors require a clear organisational chart and a formal delegation of security authority to an executive or senior technical lead.
Required CPA evidence artifact: Signed org chart, job description, or board meeting minutes confirming security oversight responsibility.
Fix guidance: Formally designate the CTO or Head of Engineering as the Information Security Officer in writing.
// Answer all 25 questions to see your results. (0 answered)
Deterministic self-assessment based on the AICPA 2017 Trust Services Criteria (2022 revised Points of Focus), the 2018 SOC 2 Description Criteria and 2026 AICPA peer-review guidance. Informational guidance only — not legal or audit advice; only a licensed CPA firm can issue a SOC 2 report.
A second pair of eyes before the expensive mistakes. Get in touch for a strategy call.