The importance of SOC readiness cannot be overstated in today's digital landscape, where cybersecurity threats loom large and regulatory requirements have grown increasingly stringent. Yet, many people are confused about the complexities of SOC readiness, while others are looking to understand the basic details – the who, what, where, why and how of SOC readiness in today’s marketplace.
What
What is SOC readiness?
SOC readiness is a consulting project that evaluates an organization’s preparedness to undergo a SOC 1® or SOC 2® examination. The objective of SOC readiness is to understand the organization’s operating environment and develop a road map for the future SOC examination. The level of readiness will establish the organization’s posture and determine whether the existing controls are suitably designed and operating effectively to meet the applicable objectives (SOC 1) or trust services criteria (SOC 2) of the organization. The readiness will define the controls that should be in the organization’s SOC report and outline any controls that require remediation before the examination period begins.
What is the final deliverable from a SOC readiness assessment?
You can expect Baker Tilly to provide you with the following final deliverables:
- An inventory of the SOC reports in scope systems, tools and technologies
- A control matrix that outlines details of the in-scope control activities, including the frequency of required actions, control owners and anticipated control evidence
- The comprehensive list of controls identified in the control matrix:
- For SOC 1 readiness: the controls are mapped to control objectives that we assist your organization in developing


