For Founders facing a first SOC 2
Find out what you already have, what you genuinely do not, and roughly how much of it is real work, before you sign anything with anyone.
The job: Decide whether to buy a compliance platform, hire a consultant, or start by finding out what the actual gap is.
If you hold nothing yet, that is a real answer and worth knowing early. If you hold ISO 27001 or run to CIS Controls, a large part of SOC 2 is already evidenced and the coverage number says how much.
Check your starting pointMost companies in this position already have security policies that were written for something else. A gap analysis reads them control by control and tells you which parts already count.
Watch it run on a sampleWe publish our position on all 93 ISO 27001 Annex A controls, including the fifteen we do not meet. It is a realistic picture of what a small company actually looks like against a standard, which is useful calibration before anyone quotes you.
Read our own gap reportThis does not get you certified and does not replace an auditor. It tells you the size and shape of the work. Somebody still has to do the work, and somebody independent still has to attest to it.
Probably not for the same job. They collect evidence continuously against a set of standards. This answers which standard to take on and how much of it your existing work already satisfies, which is a question you answer once, before you buy the thing that collects evidence.
Nothing to see the coverage numbers, which are published for every released pair. The full per-control report is $299 for a pair. The free tier gives you the graph and the agent tools without an account.
The graph holds 686 frameworks and 59,673 judged cross-framework mappings, with 29,549 more that were judged and rejected and kept where you can read them.