The SOC 2 gap assessment
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · SOC 2
Before you hire an auditor, find out what is missing. A gap assessment turns "are we ready?" into a dated to-do list.
What it is
A gap assessment walks the SOC 2 Common Criteria (and any additional categories you scope) and asks, for each, "do we have this control, is it documented, and is it running?" The result is an inventory of gaps — missing controls, undocumented ones, and ones that run inconsistently.
Why do it first
Going into an audit without a gap assessment is how a friendly Type I conversation becomes a list of management responses. The assessment surfaces the gaps while you can still close them cheaply, before the auditor is on the clock and before the observation period starts accruing evidence of controls that are not there yet.
Running one yourself
You do not need to buy a gap assessment to start one. Take the criteria, mark each control as present / partial / missing, and note where the evidence would come from. Be honest about "partial" — a policy with no operating evidence is a gap. The exercise alone clarifies most of the work ahead.
Turn gaps into a plan
The value is the prioritised remediation list: what to build, in what order, and a realistic date for audit readiness. SentinelPanda runs the gap assessment against the criteria automatically and produces that remediation plan, so "are we ready?" becomes a tracked checklist instead of a guess.