Self-assessment · SOC 2 compliance

SOC 2 Self-Assessment

In 16 simple questions, find out whether your company is ready for a SOC 2 audit (the trust report customers of software and service providers expect). Instant score; detailed per-criterion analysis on request.

No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.

  1. 1

    Has management put its security rules in writing, and is someone clearly responsible for keeping them alive?

  2. 2

    Do you know which security commitments you make to your customers (contracts, terms of service)?

  3. 3

    Do you regularly take the time to identify the main risks to your service and customer data?

  4. 4

    Do you control who has access to what (least privilege), and remove access as soon as someone leaves or changes role?

  5. 5

    Does access to your sensitive systems require strong authentication (MFA)?

  6. 6

    Are changes to your application or infrastructure tested and approved before going to production?

  7. 7

    Do you keep logs of what happens on your systems, and can you detect unusual behaviour?

  8. 8

    Do you know how to respond to a security incident, and have you ever put that procedure to the test?

  9. 9

    Do you check the security of your critical vendors (hosting, SaaS tools) before and during the relationship?

  10. 10

    Are your employees trained on security (passwords, phishing), with regular refreshers?

  11. 11

    Are your critical data and systems backed up, and do you test restoring those backups?

  12. 12

    Could you restore your service after a major outage within a timeframe you have defined and tested?

  13. 13

    Do you know which data entrusted by your customers is confidential, and where it lives?

  14. 14

    Do you actually delete confidential data when it is no longer needed or when a customer asks?

  15. 15

    Do you clearly tell people what you do with their personal data (collection, use, retention)?

  16. 16

    Can you respond to someone asking to access or delete their personal data?

0 / 16