Do You Need a Readiness Assessment Before Your Audit?
A readiness assessment is a paid dress rehearsal of the examination you are about to buy, and it is optional. Nothing in the AICPA attestation standards or in ISO/IEC 27001 requires one. Secureframe publishes a range of $10,000 to $17,000 for a SOC 2-scoped engagement, and our own cost breakdown puts a standalone consultancy engagement at $8,000 to $20,000, so the published figure sits inside the band we see. Both are as of August 2026. Buy one if this is your first examination against this framework, if your evidence is scattered across a dozen tools nobody has inventoried, or if a customer deadline means you cannot afford a qualified opinion. Skip it if you have already been through the same examination at the same scope and nothing material has changed since.
That is the decision. The rest of this is what the money buys, the rule that decides who is allowed to take it, and the three situations where we would tell you to spend it on remediation instead.
Key takeaways
- A readiness assessment is a paid dress rehearsal of the examination, and it is optional. Nothing in the AICPA attestation standards or in ISO/IEC 27001 requires one.
- Gap assessment, readiness assessment and audit are three different purchases. The rehearsal is what separates the middle one, and it is the part that changes your outcome, so ask in writing which one is in the statement of work.
- Independence decides who may run yours. A CPA firm cannot attest to controls it designed or implemented, and under ISO/IEC 17021-1 a certification body cannot consult for an organisation it certifies.
- The fee should buy five named deliverables: a scope recommendation, a gap list classified by state, a rehearsal of evidence collection against real populations, a remediation plan with owners and dates, and a call on when the observation window should open.
- Skip it if you have been examined at this scope before, if your gaps are already obvious and unarguable, or if your scope is genuinely simple and a platform has already produced the technical gap list.
Gap assessment, readiness assessment, audit: three different things
The three words get used interchangeably by people selling all three, which is how buyers end up paying twice for the same work.
A gap assessment answers one question: where does our current control environment fall short of the criteria? It is a comparison exercise. The output is a list, usually ranked, of things that are missing, partially in place, or in place but undocumented. It does not test whether anything works.
A readiness assessment is a gap assessment plus a rehearsal. The good ones walk the controls the way an examiner will: pull a real population, sample it, ask for the evidence, and see what comes back. The output is the gap list plus a remediation plan with owners and dates, a view of whether your evidence will actually survive sampling, and a scope recommendation. Firms differ enormously on how much of the rehearsal they actually perform, which is the single biggest driver of what you get for the fee.
An audit (for SOC 2, more precisely an examination) is the independent engagement that produces the report your customer reads. It ends in an opinion, and the opinion belongs to a licensed CPA firm for SOC 2 or to an accredited certification body for ISO 27001.
The practical consequence: a firm quoting you a "readiness assessment" that is really a gap assessment is not overcharging you if the price matches, but you are not buying the rehearsal, and the rehearsal is the part that changes your outcome. Ask which one you are getting, in writing, before you sign.
The independence rule that decides who may run yours
This is the constraint most first-time buyers discover late, and it is not negotiable.
For SOC 2, the report is an attestation issued by a licensed CPA firm, and the AICPA's independence requirements prevent that firm from attesting to controls it designed or implemented. A shop offering to build your control environment and then issue your opinion is describing an independence problem, not a package deal. Large firms that maintain separated advisory and attestation practices can sometimes do both with real safeguards and distance; a small firm offering both to the same client generally cannot.
For ISO 27001, the same principle lives in the accreditation rules rather than in professional ethics. Certification bodies operate under ISO/IEC 17021-1, which prohibits a certification body from providing management-system consultancy to an organisation it certifies. If one firm built your ISMS and its sister company is certifying it, ask to see how the accreditation body has been told about that relationship.
So the structure that works is the boring one: one party helps you get ready, a different and independent party examines you. That is also the structure this article assumes throughout, and it is why we do readiness work and never issue attestations. We have no report to sell you at the end, which is exactly why we can tell you to skip the assessment.
What the fee actually buys
A readiness engagement worth its price produces five things, and you should ask for all five by name in the statement of work:
- A scope recommendation. Which systems, which entities, which Trust Services Categories, which Annex A controls, and what the exclusions cost you commercially. Scope is the biggest lever on your examination fee, and it is set before anybody tests anything.
- A control-by-control gap list, mapped to the criteria, with each item classified as missing, designed but not operating, or operating but not evidenced. Those three states have completely different remediation costs, and a list that does not distinguish them is a to-do list, not an assessment.
- A rehearsal of evidence collection. The assessor pulls the same populations your examiner will (the full termination list, the full change log, the full user roster), samples them, and requests the evidence. This is where first-timers learn that their offboarding tickets do not record dates, or that the change log lives in three systems.
- A remediation plan with owners and dates, sequenced so the long-lead items (a penetration test, a policy cycle that needs board approval, an access review that only proves itself over time) start first.
- A readiness call on your observation window. For a Type II, the single most valuable output is a defensible answer to "when should the window open", because opening it early is how you buy a report full of exceptions.
What it does not buy is the fix. The assessment is the diagnosis; remediation is the treatment, and the treatment is almost always the larger bill. Teams that budget for the assessment and not for the sprints it generates are the ones who end up asking their auditor for a date extension.
Three situations where we would tell you to skip it
Against our own interest, because this is work we sell.
You have done this examination before at this scope. Your second SOC 2 does not need a rehearsal for the same control set in the same environment. What it needs is someone actually running the program between audits, which is a different purchase and the subject of our year-two piece. If the only thing that changed is the calendar, a readiness assessment is a re-audit you are paying for twice.
Your gaps are already obvious and unarguable. If you know you have no access reviews, no formal offboarding, no change approvals and no risk assessment, you do not need to buy a readiness assessment to tell you that. Spend the money on the four things. Come back for a rehearsal when the controls exist and the open question is whether the evidence survives sampling.
Your compliance platform has already produced the technical gap list and your scope is genuinely simple. One product, one cloud account, Security only, a technical founder who will own the program. The platform sees configuration well and process poorly, so the residual risk is your process controls, and a half-day conversation with your examiner about scope will serve you better than a full engagement. We make the same argument about the platform-versus-consultant decision in our Vanta and Drata piece.
The case where the assessment clearly earns its fee is the mirror image: first time through, real customer deadline, evidence spread across tools with nobody owning the calendar, and a scope decision (multiple products, multiple entities, an optional category a contract seems to demand) that nobody internal can make with confidence.
Can your examiner do it instead?
Some can, within limits, and it is worth asking because the economics are attractive: the firm doing the examination already has to understand your environment, so a light readiness pass performed by them costs less than a separate engagement.
The limit is the independence rule above. Your CPA firm can tell you that a control does not meet the criteria. It cannot design the replacement control, write the policy, or build the process, and then attest to it. In practice that means an examiner-led readiness pass is diagnostic only: you get the gap list and no help closing it. That is a perfectly reasonable purchase if you have the hands to do the remediation and only need the map.
Ask the question directly, in these words: "If you perform readiness for us, what specifically will you decline to do, and does that change anything about your independence for the examination?" A firm that answers crisply has thought about it. A firm that says it is all fine has not.
Where Top Floor fits
We run readiness engagements and we run the program afterwards, which are two different purchases. The first is a project: scope, gap list, rehearsal, remediation plan. The second is compliance as a service, where the recurring reviews, evidence collection, and examiner management stop being somebody's fifth priority. What we never do is issue your opinion, so when we tell you the assessment is unnecessary, that recommendation costs us the engagement rather than protecting a downstream audit fee.
If you are still choosing between frameworks rather than preparing for one, start with the ISO 27001 versus SOC 2 comparison instead. Buying readiness for the wrong framework is a more expensive mistake than skipping readiness for the right one.
How to decide this week
Three questions, in order. First, have we been examined against this framework at this scope before? If yes, skip and put the money into the ownership problem. Second, do we know what our gaps are, specifically enough to assign them to people? If yes, remediate first and buy the rehearsal later, when the question is whether the evidence holds. Third, does a customer contract name a date? If yes, work the calendar backwards from it (report issuance, fieldwork, observation window, remediation) and buy whatever de-risks the earliest milestone, which for a first-timer is almost always the scope decision.
Then get two quotes and compare them on the five deliverables above rather than on price. As of August 2026 the spread between a gap list and a genuine rehearsal is wider than the spread between vendors' fees, and only one of them changes what your report says.
Frequently asked questions
How much does a readiness assessment cost?
Secureframe publishes a range of $10,000 to $17,000 for a SOC 2-scoped readiness assessment, and our own published range for a standalone consultancy engagement is $8,000 to $20,000, so the two agree closely and the published figure sits inside the wider band. Scope is what moves the number: one product on one cloud account with the Security category only sits at the bottom, and multiple products, multiple entities or extra Trust Services Categories move it up. Both figures are as of August 2026, and neither includes remediation, which is usually the larger cost.
Can our readiness firm also perform the audit?
For SOC 2, no, not the same small firm: AICPA independence requirements stop a CPA firm from attesting to controls it designed or implemented. Large firms with separated advisory and attestation practices sometimes can, with real safeguards, but a shop offering to get you ready and then certify you is describing an independence violation. For ISO 27001 the same separation comes from ISO/IEC 17021-1, which prohibits a certification body from consulting for an organisation it certifies. The clean structure is one party for preparation and a different, independent party for the examination.
Is a gap assessment the same as a readiness assessment?
No, and the difference is the rehearsal. A gap assessment compares your current controls against the criteria and produces a list. A readiness assessment does that and then tests the way an examiner will: it pulls real populations, samples them, requests the evidence, and reports whether what came back would survive fieldwork. Firms sell both under both names, so ask which one is in the statement of work before you sign, because the rehearsal is the part that changes your outcome.
What should we do instead if we skip it?
Spend the money on the three things that fail first: name an owner for the compliance calendar, stand up the recurring controls that only prove themselves over time (access reviews, offboarding inside your stated SLA, change approvals), and fix the evidence trail so those controls produce dated artifacts nobody has to reconstruct later. Then have a scoping conversation with your examiner before the observation window opens. That sequence removes more risk per dollar than an assessment does when the gaps are already known.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.