SOC 2 & ISO 27001
What are the most common gaps found in a SOC 2 readiness assessment?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
The most common gaps found in a SOC 2 readiness assessment are missing or undocumented policies, inconsistent access control and offboarding, weak change management, no central evidence collection, untracked vendors and risk assessments, and gaps in logging, monitoring, and incident response. In short, organizations usually have reasonable security in practice but cannot produce the documentation and repeatable evidence an auditor needs to test each Trust Services Criterion.
On this page
- Why do most SOC 2 gaps come down to documentation and evidence, not security?
- Which policy and documentation gaps show up most often?
- What access control and HR gaps do auditors find?
- What technical and operational control gaps are most common?
- How do vendor, risk, and evidence-collection gaps undermine readiness?
- How does a readiness assessment close these gaps before the audit?
- Frequently asked questions
Why do most SOC 2 gaps come down to documentation and evidence, not security?
Most SOC 2 readiness gaps are not about whether you are secure — they are about whether you can prove it. SOC 2 is an attestation against the AICPA's Trust Services Criteria, and an auditor can only test what you can document and evidence. A control that lives in someone's head, or that happens informally, fails the audit even when it works in practice.
This is why a readiness assessment so often surprises teams: the engineering and security work is largely done, but the policies, records, and repeatable processes that demonstrate it are missing. The gaps below are the ones that recur most consistently, grouped by the part of your program they affect.
Which policy and documentation gaps show up most often?
The single most common gap is missing, outdated, or unenforced policies. SOC 2 expects a documented set of security policies that staff have read, acknowledged, and actually follow — not a template downloaded once and forgotten.
Typical findings in this area include:
- No written information security, acceptable-use, access control, change management, or incident response policies — or policies that no longer match how the company operates.
- Policies exist but employees have never formally acknowledged them, so there is no evidence of awareness.
- No defined policy review cadence (auditors expect at least annual review and sign-off).
- Missing security awareness training records and no proof that staff completed onboarding training.
What access control and HR gaps do auditors find?
Access management and employee lifecycle controls are the second most common source of findings. The Trust Services Criteria expect access to be granted on least privilege, reviewed regularly, and removed promptly when people leave or change roles.
Frequent gaps include:
- No periodic user access reviews, so no evidence that current access is still appropriate.
- Slow or inconsistent offboarding — terminated users still have active accounts or VPN access.
- Multi-factor authentication missing on some critical systems or admin accounts.
- No documented onboarding and offboarding checklists, and HR records that do not tie to access provisioning.
- Shared administrator accounts, or privileged access that is not logged or restricted.
What technical and operational control gaps are most common?
On the technical side, the recurring gaps are weak change management, thin logging and monitoring, and untested recovery and incident response. Auditors want to see that changes are controlled, that you would detect a problem, and that you have practised responding to one.
Common findings include:
- Code or infrastructure changes deployed without documented review, approval, or testing — no audit trail in version control or ticketing.
- Centralized logging and security monitoring or alerting absent or incomplete, so suspicious activity would go unnoticed.
- No documented, tested incident response plan, and no record of tabletop exercises.
- Backups exist but restoration has never been tested, and there is no documented business continuity or disaster recovery plan.
- Vulnerability management and penetration testing not performed on a defined schedule, or findings not tracked through to remediation.
How do vendor, risk, and evidence-collection gaps undermine readiness?
A final cluster of gaps concerns the things that tie the program together: vendor oversight, formal risk assessment, and the practical ability to collect evidence on demand. These are easy to overlook because they are administrative rather than technical, but auditors test them directly.
What we routinely find:
- No vendor or sub-processor inventory and no review of critical vendors' security — for example, collecting and reviewing their SOC 2 reports.
- No documented, repeatable risk assessment, so there is no traceable link between identified risks and the controls in place.
- No data inventory or data flow mapping, leaving it unclear what data is in scope and where it lives.
- Evidence scattered across people and tools with no owner, so pulling samples for the audit period becomes a scramble.
- An overly broad or poorly defined scope that pulls in systems and criteria that did not need to be tested.
How does a readiness assessment close these gaps before the audit?
A readiness assessment exists precisely to surface these gaps while you still have time to fix them, rather than failing them in front of the auditor. It maps your current state against each in-scope Trust Services Criterion, lists every gap, and gives you a prioritized remediation plan with owners and timelines.
Privacy Horizon runs the readiness assessment, helps you define a sensible scope, write and operationalize the missing policies, stand up access reviews and evidence collection, and remediate technical gaps — so that by the time the independent audit firm begins, your controls are not just designed but already operating and evidenced. Because cost and timeline depend on your starting maturity, your scope, and whether you are pursuing a Type I or Type II report, we scope each engagement individually rather than quote a generic figure. Book a consultation for a tailored plan.
Frequently asked questions
The most common reason is a lack of documentation and evidence, not poor security. Controls often work informally but are not written down, acknowledged, or recorded, so the auditor has nothing to test. Closing this gap means formalizing policies and setting up repeatable evidence collection well before the audit period begins.
A penetration test is not strictly mandated by the Trust Services Criteria, but auditors and enterprise customers widely expect one as evidence of a mature security program. The absence of regular, scheduled testing is a frequent readiness gap, so most organizations treat it as a practical requirement even though it is not formally required.
Remediation commonly takes a few weeks to a few months, depending on how mature your controls already are and how many gaps the assessment finds. Documentation and access-review gaps can be closed quickly; standing up logging and monitoring, and running the observation window required for a Type II report, takes longer.
Yes. SOC 2 requires documented policies that staff have acknowledged, because the auditor must be able to verify the control rather than take it on trust. Informal good practice that is not written down or evidenced is the single most frequent gap, even at well-run small companies.
A readiness assessment is an internal, advisory review that finds and helps you close gaps before the audit; it produces no opinion or report for customers. The SOC 2 audit is performed by an independent CPA firm and results in the attestation report you share with buyers.
Keep exploring
All SOC 2 & ISO 27001What is SOC 2, and does my business need it?
SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.
ReadSOC 2 & ISO 27001What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I assesses control design at a point in time; Type II tests operating effectiveness over months. Compare the two, plus typical timeline and cost drivers.
ReadSOC 2 & ISO 27001SOC 2 vs ISO 27001 — which should we pursue first?
SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadSOC 2 & ISO 27001How much does SOC 2 cost and how long does it take?
How much does SOC 2 cost and how long does it take? Learn the real cost drivers — readiness vs audit fees, scope, Type I vs Type II — and a realistic timeline.
ReadSOC 2 & ISO 27001What documents and evidence do you need for a SOC 2 audit?
What documents and evidence do you need for a SOC 2 audit? A plain-language checklist of policies, system descriptions, and proof your controls operate.
Read