

SOC2 Gap Assessment
The SOC2 Gap Assessment is a free tool that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022) used in SOC2 examinations.
Cost / License
- Free
- Proprietary
Platforms
- Online
Features
- SOC 2 Compliant
SOC2 Gap Assessment News & Activities
Recent activities
- IRM added SOC2 Gap Assessment
IRM added SOC2 Gap Assessment as alternative to Humadroid.io and Comp AI
SOC2 Gap Assessment information
What is SOC2 Gap Assessment?
The SOC2 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), the control criteria a licensed CPA firm uses in a SOC2 examination.
You choose your level: SOC2 Type I assesses all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy as a point-in-time readiness review, and SOC2 Type II assesses the same criteria and adds an Evidence (12 Months) field to every criterion so you can insert links to evidence artifacts covering the last 12 months. You assess each criterion, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
The assessment is built for small and medium organizations, startups, and growing SaaS companies that face customer security questionnaires or enterprise procurement requirements and want to understand where they stand against the Trust Services Criteria before engaging a CPA firm.
The SOC2 Type I level is the right starting point for teams preparing for their first examination, while the SOC2 Type II level suits teams heading into an operating-effectiveness review period who need to start collecting and organizing 12 months of evidence.
Safe and Secure to Use - We never see your assessment data, we do not store it, it stays in your local Browser.

