>

SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) — Gap Analysis

AICPA SOC 2 — Security, Availability, Confidentiality, Processing Integrity, Privacy
SOC 2 2017 Edition All Gaps only
Compliant
Partial
Non-compliant
Not assessed

About SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022)

SOC 2 is the AICPA System and Organization Controls report on the Trust Services Criteria (TSC). The Common Criteria (CC) cover Security and form the baseline; additional categories (Availability, Confidentiality, Processing Integrity, Privacy) are added based on the services in scope. SOC 2 reports are issued by a licensed CPA firm as either Type I (point-in-time design) or Type II (operating effectiveness over a period, typically 6 or 12 months). They are a standard contractual requirement for B2B SaaS in North America and increasingly globally.

Issuing Body

American Institute of Certified Public Accountants (AICPA)

Edition

2017

Coverage

Trust Services Criteria covering Common Criteria (Security) + Availability + Confidentiality + Processing Integrity + Privacy.

Typical Users

SaaS, cloud, MSPs, fintech, healthtech, B2B service providers needing customer assurance over data controls.

How to use this tool

1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.

2. Add notes against any requirement to record evidence, gaps, or corrective actions.

3. Click Save progress in the sidebar — data is stored locally in your browser, never uploaded.

4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.

Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.

ISO Xpert — Get in touch

UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.

Phone / WhatsApp

+44 7853 109840

Office

71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK

Common Questions

SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria — Frequently Asked Questions

Quick answers about the SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis tool, data privacy, audit preparation, and ISO Xpert consulting.

What is the SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis tool and how does it work?
The SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis tool is a free browser-based checklist that compares your current management system against the clauses of SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria. You answer clause-by-clause questions and rate each requirement as Compliant, Partial or Non-compliant. The tool calculates a live compliance score, highlights gaps on a heat-map, captures evidence and corrective-action notes, and exports the full assessment as JSON, CSV, TXT or print-ready PDF for management review and Stage 1 / Stage 2 audit preparation.
Is the SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis tool really free to use?
Yes — the SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria tool is 100% free with no sign-up, no email capture, no credit card, no watermarks, and no usage limits. It runs entirely in your browser; nothing is transmitted to ISO Xpert servers. You can clear or export your data at any time.
Where is my SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria assessment data stored?
All SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria assessment data is stored locally in your browser’s storage. Nothing is uploaded to our servers. This makes the tool GDPR-friendly and suitable for confidential audit data classified up to Restricted. Export anytime as JSON (re-importable), CSV (Excel-pivotable), TXT (executive summary) or PDF (audit-trail evidence).
Can I use this tool to prepare for SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria certification or surveillance audits?
Yes. The SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis is designed to support preparation for certification by UKAS-, IAS- or ANAB-accredited bodies. Use the exported report as evidence of internal audit, feed it into management review, and prioritise high-severity non-conformities ahead of Stage 1 / Stage 2 visits. ISO Xpert consultants can assist with documented information, internal audits and full implementation if required.
How long does a SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis typically take?
Most users complete an initial SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis in 60 to 120 minutes for a single site, depending on system maturity and clause depth. The tool auto-saves continuously, so you can pause, switch devices via JSON export/import, and resume at any time. Re-assessments after corrective action usually take 20 to 40 minutes.
Does ISO Xpert offer SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria consulting or training?
Yes. ISO Xpert Ltd (London, UK) provides SOC 2 (AICPA Trust Services Criteria 2017, rev. 2022) Trust Services Criteria gap analysis consulting, internal audits, Stage 1 and Stage 2 certification preparation, lead auditor / internal auditor training, and full management-system implementation. Contact info@iso-xpert.com or WhatsApp +44 7853 109840.

More questions? Contact ISO Xpert or browse other cyber-gap-analysis tools.