{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "version": "1.0",
  "last_updated": "2026-08-12",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "product": {
    "id": "soc2-gap-assessment",
    "name": "SOC 2 Gap Assessment (Free Tool)",
    "category": "SOC 2 readiness gap assessment tool",
    "type": "WebApplication",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "canonical_url": "https://irmcon.ca/products/soc2/",
    "delivery_model": "Web-based self-serve tool",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "summary_50_words": "Free, self-serve gap assessment tool that measures organizations against all 61 criteria of the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022) used in SOC 2 examinations, at the SOC 2 Type I or Type II level, with likelihood and impact risk scoring, 12-month evidence links, and a downloadable report with a prioritized remediation roadmap.",
    "summary_200_words": "The SOC 2 Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures an organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), the control criteria a licensed CPA firm uses in a SOC 2 examination. Both assessment levels cover all 61 criteria across the five Trust Services Categories: Security (the 33 Common Criteria, CC1 to CC9, mandatory in every SOC 2 report), Availability, Processing Integrity, Confidentiality, and Privacy. The SOC 2 Type I level is a point-in-time readiness review, and the SOC 2 Type II level adds an Evidence (12 Months) field to every criterion where the user types or inserts links to evidence artifacts covering the last 12 months, because a Type II examination tests operating effectiveness over a review period. The user captures their company profile, works through each criterion, marking each compliant, partially compliant, non-compliant, or not applicable. Each gap is scored on a 5x5 risk matrix (likelihood times impact) and ranked Low, Medium, High, or Critical. The tool then generates a professional, downloadable report in PDF or Word format containing an executive summary, detailed findings, and a phased remediation roadmap across 30, 90, 180, and 365 day horizons. It is an independent tool, not affiliated with or endorsed by the AICPA, and complements IRM's Governance, Risk & Compliance and Virtual CISO services.",
    "feature_list": [
      "Assesses all 61 criteria of the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022)",
      "Covers Security (Common Criteria CC1 to CC9), Availability, Processing Integrity, Confidentiality and Privacy",
      "SOC 2 Type I level for point-in-time readiness",
      "SOC 2 Type II level adds an Evidence (12 Months) field per criterion for links to evidence artifacts",
      "Scores each gap by likelihood and impact on a 5x5 risk matrix",
      "Ranks gaps as Low, Medium, High, or Critical",
      "Generates a report with an executive summary and detailed findings",
      "Builds a phased remediation roadmap (30, 90, 180, 365 days)",
      "Downloads as PDF or Word with your company logo"
    ],
    "frameworks": [
      "AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022), used in SOC 2 examinations"
    ],
    "target_audience": [
      "Small and medium organizations",
      "Startups",
      "SaaS companies preparing for a SOC 2 Type I or SOC 2 Type II examination"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "IT Manager",
      "Chief Risk Officer",
      "Compliance Manager"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.ca/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.ca/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "Governance, Risk & Compliance Services",
        "url": "https://irmcon.ca/governance-risk-compliance-grc/"
      },
      {
        "name": "Virtual CISO Services",
        "url": "https://irmcon.ca/virtual-ciso-services-vciso/"
      }
    ]
  }
}
