A SOC 2 gap analysis compares what your company does today with what an auditor will test, and hands you the list of what is missing. There are three ways to get that list: fill in a spreadsheet yourself, pay a consultant or audit firm for a readiness assessment, or connect your systems to a SOC 2 gap analysis tool and let it check.
On cash alone, the tool loses. A spreadsheet costs nothing. A readiness assessment for a company of 10 to 50 people typically runs $5,000 to $12,000, once. A compliance platform for a company of up to 50 people runs $12,000 to $28,000, every year.
We still think the tool is the right default for a startup with no security hire, for one reason: a gap list is only useful while it is true. A spreadsheet and a consultant’s report are both snapshots. A tool rechecks after every fix, and the same checks become your audit evidence later. Two catches apply, and we cover both. No tool can check all 33 criteria by itself, and finding a gap is not the same as closing it.

Key takeaways
- Security, the only category every SOC 2 report must cover, has 33 common criteria in nine series (CC1 to CC9) and over 200 points of focus. That is the list a gap analysis works through.
- A readiness assessment from a firm costs about $5,000 to $25,000 depending on company size, and, going by Schellman’s published phases, takes roughly three to eight weeks to produce a gap list.
- Vendr’s buyer data, updated February 2026, puts the median Vanta contract at $20,000 a year and the median Drata contract at $25,000. For companies of up to 50 people, it lists $12,000 to $28,000 for each.
- Schellman tells first-time companies to plan 12 to 15 months from readiness through a Type 2 report, so a late or stale gap list delays everything behind it.
A gap analysis covers 33 criteria, and fewer than half can be read off a system
Schellman, a CPA firm that performs SOC examinations, describes a readiness assessment as a gap analysis of your existing practices against the SOC 2 Trust Services Criteria. It is optional. Schellman says outright that it is not a required step, and the deliverable is a list of gaps for internal use, not an audit opinion.
The criteria come from the AICPA’s 2017 Trust Services Criteria, with points of focus revised in 2022. Security is the only required category. It contains 33 common criteria grouped into nine series. The four optional categories (availability, confidentiality, processing integrity and privacy) add 28 more, for 61 in total. Audit firm Linford & Company counts over 200 points of focus under the security criteria alone, and almost 300 across all five categories.
Where those 33 sit decides how you can check them. By our grouping, 14 are in the three series where a system can be inspected directly: access controls (CC6, 8 criteria), system operations (CC7, 5) and change management (CC8, 1). The other 19 cover governance, communication, risk assessment and vendors (CC1 to CC5, and CC9), and the evidence for those is documents and people’s answers.

That split is why none of the three methods is complete alone. A scanner that only reads cloud settings sees fewer than half the list. A spreadsheet can cover all 33 rows, but only with whatever you type into it.
The gap analysis is the shortest phase, and every other clock waits for it
A Type 2 report covers how your controls operated over a period, which Vanta’s cost guide puts at usually three to twelve months. The controls have to exist before that window opens, and the same guide says preparation usually takes one to five months. Schellman advises first-time companies to plan on 12 to 15 months of calendar time from readiness through a Type 2 report.

The order matters because the observation window does not forgive late discoveries. A control that was missing for part of the period can surface as an exception when the auditor tests it. Audit firm Sensiba notes that minor exceptions are unlikely to change the overall opinion, but significant or numerous ones can lead to a qualified opinion. You want to find the gap before the window opens, not in month four of it.
The pressure to start is real, too. In Vanta’s State of Trust 2024 survey of 2,500 business and IT leaders, 65% said customers, investors and suppliers increasingly require proof of compliance. In A-LIGN’s 2022 benchmark report, 22% of respondents said they had lost a new deal over a missing certification. Neither figure is recent or specific to startups, but the startup version is familiar: a larger customer’s security review asks for SOC 2, with a deadline attached.
Option 1, the spreadsheet: free, complete on paper, and only as honest as your answers
The do-it-yourself version is a sheet with one row per criterion and columns for the control you have, its status, an owner and the evidence. The raw material is free. The AICPA publishes the criteria and its own mapping spreadsheets to frameworks such as NIST CSF, and free templates are easy to find.
What it does well: it costs nothing, it handles the governance and policy rows as easily as the technical ones, and filling it in forces a founder to read what SOC 2 actually asks. For a company with no customer deadline yet, that first pass is worth doing.
What it does badly:
- It needs an interpreter. The criteria are written for auditors. Turning a sentence about logical access security into “every admin account has MFA, and here is the proof” takes someone who has done it before. That is the person a startup does not have.
- It is self-reported. You type “yes” next to MFA. Nothing checks the three accounts created before the policy existed.
- It goes stale. The sheet is true on the day you fill it in. Nobody updates it when a contractor gets admin rights.
- It produces no evidence. When the audit starts, you collect every screenshot again by hand.
We could not find a published benchmark for how many hours a spreadsheet gap analysis takes, so we will not invent one. The closest data point is broader: Vanta’s 2024 survey found teams spend 11 working weeks a year on compliance tasks, and respondents estimated that automation could give back up to 5 of them.
Option 2, the consultant or auditor: real judgment, delivered once
Paying a firm gets you someone who knows what auditors accept. Published prices sit in one band. Vanta says an external readiness assessment starts around $10,000 and scales with size. Secureframe puts a professional one at about $15,000. SOC2Auditors.org, an independent directory of audit firms, lists typical 2026 ranges of $5,000 to $12,000 for 10 to 50 employees, $10,000 to $18,000 for 51 to 200, and $15,000 to $25,000 or more above that. Treat all three as estimates. Firms quote privately.
Time is the other cost. Schellman’s readiness process runs two to five business days of planning, about a week of walkthrough meetings and about a week of reporting. Its timeline guide allows three to five weeks for gathering evidence alone. Reading the two together, three to eight weeks is a fair planning number before you hold the gap list.
What it does well is scoping: which categories you actually need, where the system boundary sits, which controls your cloud provider already covers. Those are judgment calls, and they are where software helps least.
The limits are structural, not a criticism of the people:
- It is a snapshot. The report describes the weeks of the walkthrough. Fix six gaps afterwards and you do not know they are closed until someone looks again.
- The auditor cannot fix it for you. Schellman is explicit that its assessors evaluate only, and do not provide advisory, remediation or implementation services. You get the list. The work is still yours.
- The evidence problem remains. A readiness report collects nothing during the observation window.
Option 3, the tool: the biggest invoice, and the only list that updates itself
A SOC 2 gap analysis tool, usually sold as a compliance automation platform, connects to your cloud, identity provider, code host and HR system, runs automated tests against them, and asks you questions about everything it cannot read. Vanta says it pulls data from 400+ tools and runs 1,200+ tests hourly. Drata says it tests controls daily.
The price is real. These vendors do not publish list prices, so the best public data is Vendr’s record of what buyers paid. For Vanta, the median is $20,000 a year across 374 purchases, with a range of $7,500 to $57,207. For Drata, the median is $25,000 across 235 purchases, with a range of $9,415 to $68,250. Both were updated in February 2026, and both list $12,000 to $28,000 for companies of up to 50 people. There are cheaper routes. Comp AI, for example, publishes most of its platform as open source under AGPL-3.0, if you are willing to host it yourself.
So why pay the most? Four reasons, in order of how much they matter to a team with no security hire:
- It translates. Instead of a criterion to interpret, you get a failing test: this bucket is public, these accounts lack MFA, this repository merges without review. An engineer can act on that without learning audit language.
- It rechecks. Tests rerun hourly or daily, so the gap list is current the morning after a fix, and it catches the gap you reopen by accident in month five.
- The checks turn into evidence. The tests that found the gap keep running through the observation window and record that the control held. You are not paying $12,000 for a gap list. You are paying for the gap list plus a year of evidence collection.
- It is fast where speed is possible. Going by those test schedules, the system-readable part of the list shows up within about a day of connecting your accounts, not after weeks of meetings.
Now the two catches. The first is coverage. Automated tests are strongest on the 14 criteria in CC6 to CC8. The other 19 still come down to documents and answers, so a good tool is half scanner and half guided questionnaire, and a green dashboard is only as true as what you typed into the second half. The second is authority. A tool’s dashboard is not an audit opinion. Only the CPA firm’s testing counts.
| Spreadsheet | Consultant or auditor | Tool | |
|---|---|---|---|
| Cash cost, up to 50 people | $0 | $5,000 to $12,000, once | $12,000 to $28,000 a year |
| Time to a gap list | No published benchmark | About 3 to 8 weeks | System checks within about a day of connecting; questions at your pace |
| Who interprets the criteria | You | The assessor | The tool, for what it can test |
| Stays current after a fix | No | No, until someone looks again | Yes, tests rerun hourly or daily |
| Becomes audit evidence | No | No | Yes, for tested controls |
| Best at | A first read of the criteria | Scoping and judgment calls | Technical gaps, and keeping them closed |
| Weakest at | Accuracy | Speed and freshness | Governance rows and scoping |
What we would do with no security hire
- Scope to Security only. It is the one required category. Add another only when a customer contract names it.
- With no deadline yet, do a spreadsheet first pass. It costs nothing and teaches you the criteria.
- Once a customer asks, run the gap analysis in a tool. Get more than one quote. Vendr’s ranges show how far the same product’s price moves.
- Buy judgment separately. If scope or system boundary is unclear, pay a consultant for that question instead of a full assessment.
- Sort every gap into three piles: change a setting, write something down, or start doing something. Start the third pile first, because it needs history before the window opens.
- Rerun before the observation window starts. Open the window on a clean list.
The gaps a tool can find but cannot close for you
The third pile is where startups get stuck. System operations (CC7) has five criteria covering how you detect vulnerabilities and anomalies, evaluate security events, respond to incidents and recover. A gap analysis tool will tell you nobody is watching your logs. It will not watch them. And a Type 2 auditor will ask for records showing that someone did, across the whole period.
That part is what Jutsu does. To be clear about the boundary: Jutsu is not a full SOC 2 gap analysis tool and it is not an auditor. It does not write your policies, run your risk assessment or review your vendors. It covers the security operations rows and a slice of configuration:
- The Jutsu platform monitors connected sources such as Google Cloud, Google Workspace, GitHub and Windows hosts around the clock. Jutsu’s AI agents triage each alert with a category, severity, risk score and verdict, escalate uncertain ones to a person, and keep an audit trail of alerts, investigations and response actions. That record is what closes the “start doing something” gaps.
- Posture checks run read-only compliance checks on connected Google Cloud projects and Google Workspace domains, and osquery on Windows hosts, on plans that include compliance. For those three sources it works as a gap finder. For everything else, use a compliance platform.
- Evidence exports turn that record into SOC 2 evidence from the Startup plan ($149 a month as of October 2026), with continuous compliance evidence and dashboards on Growth. See the plans, or how each auditor question maps to a record.
- Exposure gives an outside-in view in about ten minutes from public signals only: nine scores and a prioritized fix list. It is not a pen test, but it is a quick way to catch externally visible gaps before your assessment starts.
The snapshot problem is not unique to compliance. We made the same argument about security testing in why a clean automated pentest does not mean you would see the attack, and what an AI SOC is explains how AI agents do the monitoring work. To see the monitoring side before paying for anything, the Free plan covers five assets with no credit card. Evidence exports start at Startup.
The bottom line
A spreadsheet tells you what you believe. A consultant tells you what was true when they looked. A tool tells you what is true this morning. For a startup with no security hire and a customer waiting, pay for the one that keeps checking, and spend consultant money only on the questions software cannot answer. A gap list is worth exactly as much as it is still right about.
FAQ
What is a SOC 2 gap analysis?
It is a comparison of your current practices against the SOC 2 Trust Services Criteria that produces a list of what is missing before an audit. Audit firms call it a readiness assessment. For most startups it covers the 33 common criteria in the Security category.
How much does a SOC 2 gap analysis cost?
A spreadsheet self-assessment costs nothing but time. Published estimates for a readiness assessment from a firm run about $5,000 to $25,000 depending on company size. Compliance platforms that include gap analysis run $12,000 to $28,000 a year for companies of up to 50 people, according to Vendr’s buyer data from February 2026.
Is a SOC 2 readiness assessment required?
No. Schellman states that a readiness assessment is not a required step. It is a way to find problems before the auditor does, while fixing them is still cheap.
How long does a SOC 2 gap analysis take?
With an audit firm, plan on roughly three to eight weeks, based on Schellman’s published phases. With a tool, automated tests run hourly or daily once your systems are connected, so the technical findings come quickly. The policy and governance questions take as long as your team needs to answer them.
Can a SOC 2 gap analysis tool replace a consultant?
For finding and tracking technical gaps, mostly yes. For scoping decisions, such as which criteria apply and where your system boundary sits, a person with audit experience is still the better source. Neither replaces the CPA firm that issues the report.
Does Jutsu do a SOC 2 gap analysis?
Partly. Jutsu runs read-only posture checks on connected Google Cloud, Google Workspace and Windows hosts, and it produces the monitoring and incident response records that the system operations criteria ask for. It does not cover policies, risk assessment or vendor reviews, and it is not an auditor.