Self-assessment · SOC 2 compliance
SOC 2 Self-Assessment
In 16 simple questions, find out whether your company is ready for a SOC 2 audit (the trust report customers of software and service providers expect). Instant score; detailed per-criterion analysis on request.
No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.
- 1
Has management put its security rules in writing, and is someone clearly responsible for keeping them alive?
- 2
Do you know which security commitments you make to your customers (contracts, terms of service)?
- 3
Do you regularly take the time to identify the main risks to your service and customer data?
- 4
Do you control who has access to what (least privilege), and remove access as soon as someone leaves or changes role?
- 5
Does access to your sensitive systems require strong authentication (MFA)?
- 6
Are changes to your application or infrastructure tested and approved before going to production?
- 7
Do you keep logs of what happens on your systems, and can you detect unusual behaviour?
- 8
Do you know how to respond to a security incident, and have you ever put that procedure to the test?
- 9
Do you check the security of your critical vendors (hosting, SaaS tools) before and during the relationship?
- 10
Are your employees trained on security (passwords, phishing), with regular refreshers?
- 11
Are your critical data and systems backed up, and do you test restoring those backups?
- 12
Could you restore your service after a major outage within a timeframe you have defined and tested?
- 13
Do you know which data entrusted by your customers is confidential, and where it lives?
- 14
Do you actually delete confidential data when it is no longer needed or when a customer asks?
- 15
Do you clearly tell people what you do with their personal data (collection, use, retention)?
- 16
Can you respond to someone asking to access or delete their personal data?
0 / 16