Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

SOC 2 & ISO 27001

What are the most common gaps found in a SOC 2 readiness assessment?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

The most common gaps found in a SOC 2 readiness assessment are missing or undocumented policies, inconsistent access control and offboarding, weak change management, no central evidence collection, untracked vendors and risk assessments, and gaps in logging, monitoring, and incident response. In short, organizations usually have reasonable security in practice but cannot produce the documentation and repeatable evidence an auditor needs to test each Trust Services Criterion.

On this page

Why do most SOC 2 gaps come down to documentation and evidence, not security?

Most SOC 2 readiness gaps are not about whether you are secure — they are about whether you can prove it. SOC 2 is an attestation against the AICPA's Trust Services Criteria, and an auditor can only test what you can document and evidence. A control that lives in someone's head, or that happens informally, fails the audit even when it works in practice.

This is why a readiness assessment so often surprises teams: the engineering and security work is largely done, but the policies, records, and repeatable processes that demonstrate it are missing. The gaps below are the ones that recur most consistently, grouped by the part of your program they affect.

Which policy and documentation gaps show up most often?

The single most common gap is missing, outdated, or unenforced policies. SOC 2 expects a documented set of security policies that staff have read, acknowledged, and actually follow — not a template downloaded once and forgotten.

Typical findings in this area include:

  • No written information security, acceptable-use, access control, change management, or incident response policies — or policies that no longer match how the company operates.
  • Policies exist but employees have never formally acknowledged them, so there is no evidence of awareness.
  • No defined policy review cadence (auditors expect at least annual review and sign-off).
  • Missing security awareness training records and no proof that staff completed onboarding training.

What access control and HR gaps do auditors find?

Access management and employee lifecycle controls are the second most common source of findings. The Trust Services Criteria expect access to be granted on least privilege, reviewed regularly, and removed promptly when people leave or change roles.

Frequent gaps include:

  • No periodic user access reviews, so no evidence that current access is still appropriate.
  • Slow or inconsistent offboarding — terminated users still have active accounts or VPN access.
  • Multi-factor authentication missing on some critical systems or admin accounts.
  • No documented onboarding and offboarding checklists, and HR records that do not tie to access provisioning.
  • Shared administrator accounts, or privileged access that is not logged or restricted.

What technical and operational control gaps are most common?

On the technical side, the recurring gaps are weak change management, thin logging and monitoring, and untested recovery and incident response. Auditors want to see that changes are controlled, that you would detect a problem, and that you have practised responding to one.

Common findings include:

  • Code or infrastructure changes deployed without documented review, approval, or testing — no audit trail in version control or ticketing.
  • Centralized logging and security monitoring or alerting absent or incomplete, so suspicious activity would go unnoticed.
  • No documented, tested incident response plan, and no record of tabletop exercises.
  • Backups exist but restoration has never been tested, and there is no documented business continuity or disaster recovery plan.
  • Vulnerability management and penetration testing not performed on a defined schedule, or findings not tracked through to remediation.

How do vendor, risk, and evidence-collection gaps undermine readiness?

A final cluster of gaps concerns the things that tie the program together: vendor oversight, formal risk assessment, and the practical ability to collect evidence on demand. These are easy to overlook because they are administrative rather than technical, but auditors test them directly.

What we routinely find:

  • No vendor or sub-processor inventory and no review of critical vendors' security — for example, collecting and reviewing their SOC 2 reports.
  • No documented, repeatable risk assessment, so there is no traceable link between identified risks and the controls in place.
  • No data inventory or data flow mapping, leaving it unclear what data is in scope and where it lives.
  • Evidence scattered across people and tools with no owner, so pulling samples for the audit period becomes a scramble.
  • An overly broad or poorly defined scope that pulls in systems and criteria that did not need to be tested.

How does a readiness assessment close these gaps before the audit?

A readiness assessment exists precisely to surface these gaps while you still have time to fix them, rather than failing them in front of the auditor. It maps your current state against each in-scope Trust Services Criterion, lists every gap, and gives you a prioritized remediation plan with owners and timelines.

Privacy Horizon runs the readiness assessment, helps you define a sensible scope, write and operationalize the missing policies, stand up access reviews and evidence collection, and remediate technical gaps — so that by the time the independent audit firm begins, your controls are not just designed but already operating and evidenced. Because cost and timeline depend on your starting maturity, your scope, and whether you are pursuing a Type I or Type II report, we scope each engagement individually rather than quote a generic figure. Book a consultation for a tailored plan.

Frequently asked questions

The most common reason is a lack of documentation and evidence, not poor security. Controls often work informally but are not written down, acknowledged, or recorded, so the auditor has nothing to test. Closing this gap means formalizing policies and setting up repeatable evidence collection well before the audit period begins.

A penetration test is not strictly mandated by the Trust Services Criteria, but auditors and enterprise customers widely expect one as evidence of a mature security program. The absence of regular, scheduled testing is a frequent readiness gap, so most organizations treat it as a practical requirement even though it is not formally required.

Remediation commonly takes a few weeks to a few months, depending on how mature your controls already are and how many gaps the assessment finds. Documentation and access-review gaps can be closed quickly; standing up logging and monitoring, and running the observation window required for a Type II report, takes longer.

Yes. SOC 2 requires documented policies that staff have acknowledged, because the auditor must be able to verify the control rather than take it on trust. Informal good practice that is not written down or evidenced is the single most frequent gap, even at well-run small companies.

A readiness assessment is an internal, advisory review that finds and helps you close gaps before the audit; it produces no opinion or report for customers. The SOC 2 audit is performed by an independent CPA firm and results in the attestation report you share with buyers.

Keep exploring

All SOC 2 & ISO 27001

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.