Ten questions, scored the way an auditor would.
Each question covers one control area and has four answers, scored 0 to 3: critical gap, major gap, gap, or in place. That’s the same design-and-operation test an auditor applies. Thirty points total, divided by three and shown as a score out of ten. A zero on any question is flagged individually as critical regardless of the total.
SOC 2 Type 2: what the score means
The 10 control areas
In the order auditors tend to sample them. Three are marked critical: a zero on any of them is flagged first because they produce the most first-year exceptions.
- 01Logical access · CC6.2criticalLogical access is the control family with the most exceptions in first-year SOC 2 reports. Auditors sample this one every time.
- 02Onboarding & offboarding · CC6.1 / CC6.3criticalOffboarding gaps are the easiest finding for an auditor: one ex-employee with a live account is an exception.
- 03Change management · CC8.1Auditors will pull a sample of changes and ask for the approval on each one.
- 04Vendor management · CC9.2You inherit your sub-processors’ risk. An auditor expects a documented review of each one.
- 05Incident response · CC7.3 / CC7.4A written, tested plan is table stakes; an untested one is a finding waiting to happen.
- 06Risk assessment · CC3.2SOC 2 is built on the premise that controls respond to identified risks. No assessment, no premise.
- 07Policies · CC1.1 / CC5.3Auditors test that policies are approved, current, and acknowledged by staff — not just written.
- 08Logging & monitoring · CC7.2Logs that nobody reviews don’t count as monitoring.
- 09Backups & continuity · A1.2 / A1.3An untested backup is a hope, not a control.
- 10Evidence collection · Audit readinesscriticalFor Type 2, the auditor samples across the whole observation window. Hand-collection at audit time is where readiness projects stall.
This scorecard is a preliminary readiness screen. It is not an audit, an opinion, or a guarantee.
SOX 404: what the score means
The 10 control areas
Every area is marked critical: a critical-gap answer generates its own high-priority flag regardless of the overall score.
- 01Management ownership & 404(a) assessment · SEC 33-8238404(a) is management’s report, not the auditor’s. If nobody owns ICFR, nothing else in the program has a foundation.Sources: SEC Release 33-8238; SEC Financial Reporting Manual, Topic 4.
- 02Risk assessment & SOX scope · AS 2201 ¶21–36Scope is where programs over- or under-spend. A top-down, risk-based scope is the first thing the auditor asks to see.Sources: SEC Management Guidance on ICFR; PCAOB AS 2201, paragraphs 21–36.
- 03Process documentation & walkthroughs · AS 2201 ¶34–38Walkthroughs are how design gaps get found before testing does. Undocumented processes push that discovery onto the auditor — at audit prices.Sources: PCAOB AS 2201, paragraphs 34–38; SEC Management Guidance on ICFR.
- 04Journal entries & segregation of duties · AS 2201 ¶24–27 · AS 2110 App. BManagement override runs through the journal. Auditors test the full entry population every year — this is the control they look at first.Sources: PCAOB AS 2201, paragraphs 24–27; PCAOB AS 2110, Appendix B.
- 05Revenue recognition & recording · AS 2201 ¶21, 28–41Revenue is a presumed fraud risk under the auditing standards, so it is scoped in every year regardless of size.Sources: PCAOB AS 2201, paragraphs 21 and 28–41; SEC SOX 404 implementing release.
- 06Quarterly & annual financial close · AS 2201 ¶24–27 · SEC §302Most material weaknesses trace back to the close: late reconciliations, unreviewed estimates, and management reviews that can’t show what was actually reviewed.Sources: PCAOB AS 2201, paragraphs 24–27; SEC Section 302 certification rule.
- 07IT general controls & financial-reporting information · AS 2110 App. B · AS 2201 ¶36, 47Every automated and IT-dependent control inherits the reliability of the system underneath it. Weak ITGCs undermine the whole control set.Sources: PCAOB AS 2110, Appendix B; PCAOB AS 2201, paragraphs 36 and 47.
- 08Management testing & evidence · AS 2201 ¶44–52Management’s assessment has to stand on its own evidence. Screenshots and self-certifications don’t survive the auditor’s reperformance.Sources: SEC Management Guidance—evidential matter; PCAOB AS 2201, paragraphs 44–52.
- 09Deficiencies, fraud, changes & §302 certifications · SEC §302 · AS 2201 ¶62–70, 78–81The CEO and CFO certify every quarter. A deficiency nobody aggregated or escalated becomes their personal certification problem.Sources: SEC Section 302 certification requirements; PCAOB AS 2201, paragraphs 62–70 and 78–81.
- 10SOX 404(b) auditor attestation · SEC FRM Topic 4Filer status changes with public float and revenue. Companies that assume an exemption lasts forever get surprised by an attestation year they didn’t budget for.Sources: SEC Financial Reporting Manual, Topic 4; SEC Accelerated-Filer Compliance Guide.
This questionnaire is a preliminary readiness screen. It does not constitute an audit opinion or replace company-specific evaluation by management, securities counsel, the audit committee, and the external auditor.
Cybersecurity assessment: what the score means
The 10 control areas
Every area is marked critical: a critical-gap answer generates its own high-priority flag regardless of the overall score.
- 01Governance & oversight · NIST CSF 2.0 GovernWithout an accountable executive and board-level reporting, every other control is discretionary. For SEC registrants this also feeds the annual governance disclosure.Sources: NIST Cybersecurity Framework 2.0; SEC Cybersecurity Risk Management and Governance Requirements.
- 02Asset inventory, data classification & risk assessment · NIST CSF 2.0 IdentifyYou can’t protect what you haven’t inventoried. Unknown cloud services and unowned data stores are where incidents start.Sources: NIST CSF 2.0—Govern and Identify; CISA Cross-Sector Cybersecurity Performance Goals.
- 03Identity, authentication & access · NIST CSF 2.0 PR.AAStolen credentials are the most common initial access vector. MFA gaps and orphaned accounts are the findings that show up in every breach report.Sources: NIST CSF 2.0—Identity Management, Authentication, and Access Control; CISA Cybersecurity Performance Goals.
- 04Workforce security & awareness · NIST CSF 2.0 PR.ATPhishing still opens most doors. Training that isn’t tested and followed up is a policy acknowledgment, not a control.Sources: NIST CSF 2.0—Awareness and Training; CISA Cross-Sector Cybersecurity Performance Goals.
- 05Secure configuration, vulnerability & patch management · NIST CSF 2.0 PR.PSKnown exploited vulnerabilities on internet-facing systems are the second most common way in. Scanning without verified remediation doesn’t reduce that risk.Sources: NIST CSF 2.0—Platform Security and Risk Assessment; CISA Cross-Sector Cybersecurity Performance Goals.
- 06Logging, monitoring & detection · NIST CSF 2.0 DetectDwell time is decided here. Logs nobody reviews — or that an attacker can edit — mean the first sign of a breach is the ransom note.Sources: NIST CSF 2.0—Detect; CISA Cross-Sector Cybersecurity Performance Goals.
- 07Incident response & external disclosure · NIST SP 800-61r3 · SEC 8-K 1.05For SEC registrants the materiality clock is four business days. A plan that hasn’t been exercised is a plan that will be improvised.Sources: NIST SP 800-61 Revision 3; SEC Cybersecurity Incident Disclosure Requirements.
- 08Third-party & supply-chain security · NIST SP 800-161r1Your vendors’ breaches are your breaches. If you can’t list who touches sensitive data, you can’t assess the exposure.Sources: NIST SP 800-161 Rev. 1 Update 1; NIST CSF 2.0 Supply-Chain Quick-Start Guide.
- 09Backups, recovery & resilience · NIST CSF 2.0 RecoverRansomware is a backup test you didn’t schedule. Backups reachable with the same compromised credentials aren’t backups.Sources: NIST CSF 2.0—Recover and Technology Infrastructure Resilience; CISA Cross-Sector Cybersecurity Performance Goals.
- 10Control testing & evidence · NIST CSF 2.0 ProfilesCustomers, insurers, and regulators all ask the same question: show me. A program that only assembles evidence on request can’t answer it.Sources: NIST CSF 2.0 and Organizational Profiles; CISA Cross-Sector Cybersecurity Performance Goals.
This questionnaire is a preliminary cybersecurity readiness screen. It is not a certification, audit opinion, penetration test, or determination of compliance with every law or industry-specific requirement.
What it isn’t
It is not an audit, an opinion, or a guarantee. It’s a structured first conversation, scored so that you and the auditor start from the same page. Your answers are yours; the report is yours whether or not you ever book a call.