BLOG

What a SOC 2 Compliance Gap Assessment Actually Finds: The Most Common Control Failures

"A SOC 2 gap assessment measuring current controls against the AICPA Trust Services Criteria to surface findings"

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 21, 2026

Key Takeaways

  • The most common SOC 2 gap finding is not missing controls, but controls that exist in practice but are not documented, formalized, or producing evidence that an auditor can review.
  • Access management gaps are the most frequently identified findings, including missing user access review processes, absence of MFA on critical systems, and inconsistent offboarding procedures.
  • Policy gaps are almost universal in organizations starting their SOC 2 journey. Most have informal security practices but lack the documented policies that SOC 2 requires.
  • Vendor management and risk assessment are consistently underinvested in growth-stage technology companies and represent a common gap category.
  • The gap assessment output is a prioritized remediation roadmap with estimated effort and cost for each finding, not a theoretical list of weaknesses.

What Is a SOC 2 Gap Assessment and What Does It Cover?

A SOC 2 gap assessment is a structured evaluation of an organization’s current security controls, policies, processes, and evidence against the AICPA Trust Service Criteria requirements. It is the first step in any SOC 2 engagement and the foundation of the remediation roadmap that drives the compliance program. When more than one framework is in scope, the same assessment can be run as an integrated engagement that maps the findings against every required standard at once.

The assessment covers every control domain that SOC 2 requires: risk assessment, access management, system operations, change management, monitoring, incident response, business continuity, and vendor management. For each control, the assessment determines the current state, identifies the gap between that state and the SOC 2 requirement, and produces a prioritized finding with a remediation recommendation, estimated effort, and estimated cost.

The assessment process involves stakeholder interviews with key personnel across engineering, IT, HR, legal, and leadership, documentation review of existing policies and procedures, and technical configuration review of systems in scope. The combination of these three inputs produces a complete picture of where the organization stands and what is required to reach audit-ready status.

What Are the Most Common Gap Assessment Findings?

Access Management: The Most Frequent Category

Access management findings appear in almost every gap assessment. The most common specific findings are: absence of multi-factor authentication on critical systems and administrative accounts, no formal user access review process that produces evidence at a defined frequency, inconsistent offboarding that leaves former employees with active accounts or access to systems, privileged access that is not separated from regular user accounts, and access provisioning that occurs without a formal approval workflow.

These findings are common for a straightforward reason: access management controls are implemented informally in most organizations before they pursue SOC 2. Someone who needs access asks for it, it is granted, and no one tracks when it should be revoked. MFA is deployed on some systems but not systematically enforced across all critical applications. The controls exist conceptually, but the processes to implement them consistently and produce evidence of that consistency are not in place.

Policy Documentation: Present in Practice, Absent on Paper

Policy gaps are among the most consistent findings across gap assessments for growth-stage technology companies. Most organizations have informal security practices that their engineering and IT teams follow. What they lack are the documented policies that describe those practices formally, that have been approved by management, and that staff have acknowledged and agreed to follow.

SOC 2 requires documented policies for information security, acceptable use, access management, change management, incident response, data classification and handling, vendor risk management, business continuity and disaster recovery, and human resources security. Organizations that have ten of these and lack three will receive gap findings for the missing three. Organizations that have all of them in draft form but have not completed the approval and acknowledgment process will receive gap findings for the incomplete implementation.

Policy development that produces real organizational documents that teams actually use is different from policy development that produces template documents uploaded to a shared drive. The gap assessment distinguishes between the two, because auditors will ask management to attest that policies are followed, and then test whether the evidence supports that attestation.

Vendor and Third-Party Risk Management

Vendor management gaps are consistently found in organizations that have grown their vendor stack rapidly without a formal risk management process. SOC 2 requires organizations to identify vendors who have access to customer data or critical systems, assess the security posture of those vendors, conduct security review before onboarding significant new vendors, and monitor ongoing vendor security through contract terms, questionnaires, or audit reports.

The typical finding in this category is: the organization uses dozens of SaaS tools, cloud services, and third-party providers, some of which have access to customer data or internal systems, but has no formal process for assessing them, no inventory of vendor access and risk levels, and no contract terms that require vendors to maintain security standards. The remediation does not require dropping existing vendors. It requires building the inventory, conducting a risk-tiered assessment, and implementing a process for ongoing management.

Change Management: Deployment Without Documentation

Change management findings are common in software companies where deployment velocity is prioritized and formal approval processes are seen as friction. SOC 2 requires that changes to systems in scope, including software deployments, infrastructure changes, and configuration modifications, go through a defined process that includes review, testing, and approval before reaching production. The process must produce evidence that can be reviewed by an auditor.

The common finding is that deployments occur through a CI/CD pipeline without documented approval steps, or that a formal change management process exists for major releases but not for routine deployments and configuration changes. The remediation is typically implementing approval gates in the deployment pipeline, configuring the ticketing or CI/CD system to record approvals, and defining what constitutes a change that requires the formal process versus a change that can follow a lighter workflow.

Monitoring, Logging, and Incident Response

Monitoring gaps appear in organizations that have some visibility into their environment but have not formalized the detection, alerting, and response processes that SOC 2 requires. Specific findings include: log collection from critical systems without a defined retention period or centralized storage, security events that generate alerts without a documented response procedure, no formal incident classification and response workflow, and incidents that occurred without documentation of the response steps taken.

Incident response gaps are particularly important because they affect both the Security criterion and, for organizations with the Privacy criterion in scope, privacy incident requirements. An organization that experienced a security event during the SOC 2 observation period and cannot demonstrate that it was detected, classified, and responded to according to a documented process has a gap that may affect the Type II report. The incident response plan must exist before the observation period begins, and staff must have been trained on it.

Business Continuity and Disaster Recovery

Business continuity and disaster recovery findings appear in organizations that have implemented technical backup solutions without the complementary organizational processes. Backup solutions may be in place, but recovery time objectives and recovery point objectives have not been defined or tested. A business continuity plan may exist in draft form without having been approved, communicated, or exercised. Critical vendors may not be included in the continuity analysis.

SOC 2 requires not just that backups exist, but that recovery has been tested and that the organization can demonstrate it can actually recover within defined parameters. An organization that cannot produce a record of a backup restoration test will receive a gap finding regardless of whether the backups are technically in place.

What Does the Remediation Roadmap Look Like?

The remediation roadmap produced by the gap assessment is a prioritized action plan, not a list of abstract findings. For each gap, it specifies the specific control requirement, the current state, the remediation action required, the estimated effort in person-hours, and the estimated cost if tooling or external resources are needed. A compliance readiness score gives leadership a single measure of how far the organization sits from audit-ready.

Findings are prioritized by their criticality to audit readiness and their risk exposure. Critical findings that would result in audit qualification or significant findings are addressed first. High-priority findings that represent meaningful security gaps are addressed in the second tier. Lower-priority findings that represent best practices rather than hard requirements are sequenced later in the remediation program or after certification if timeline constraints require it.

Armour Cybersecurity’s integrated compliance audit program includes an effort and cost estimate for every finding, which allows leadership to understand the total investment required to reach audit readiness before committing to the remediation phase. The roadmap is built to execute, not to file. Every finding has an owner, a timeline, and a definition of done that produces the evidence the auditor will review.

Frequently Asked Questions

How long does the gap assessment take?

Armour Cybersecurity conducts Phase 1 gap assessments in 3 to 4 weeks for a typical SMB or mid-market technology company. Larger organizations with more complex environments, multiple systems in scope, or more stakeholders to interview may require 4 to 6 weeks. The assessment is scoped based on the number of Trust Service Criteria in scope and the size and complexity of the organization. For how the assessment fits the full journey, see how long the gap assessment takes within the overall SOC 2 timeline.

What if we already have a security program? Do we still need a gap assessment?

Yes. Organizations with mature security programs benefit from a gap assessment because SOC 2 has specific evidence and documentation requirements that are distinct from general security good practice. An organization that has implemented strong security controls but has not documented them in the way auditors require will have policy and evidence gaps even with a mature security posture. The gap assessment identifies exactly what is missing and what can be credited, which avoids over-remediation.

Who needs to be involved in the gap assessment from our side?

The gap assessment requires access to representatives from engineering or IT who can describe the technical environment and system configurations, HR who can speak to the people security controls including hiring, termination, and training, legal who can address data handling and vendor contract terms, finance or operations for business continuity questions, and a senior leader who can speak to the organization’s risk management approach and overall security governance. The time commitment per stakeholder is typically a two to three hour interview plus time to gather documentation.

What is the difference between a gap assessment and a penetration test?

A gap assessment evaluates security controls against a compliance framework requirement. It answers whether the right controls are in place and operating. A penetration testing engagement attempts to exploit vulnerabilities in the environment to determine whether an attacker could gain unauthorized access. Both are valuable and SOC 2 may require evidence of penetration testing as part of the Security criterion controls. They are complementary, not substitutes. The gap assessment identifies what controls exist and what is missing. The penetration test validates whether the controls that exist are actually effective against a real attack.

The Bottom Line

A SOC 2 gap assessment rarely tells an organization that it has no security. It tells them where the security they already have is informal, inconsistent, or invisible to an auditor, and access reviews, written policies, vendor risk, change approvals, tested recovery are the categories where that shows up again and again. The value is not the list of gaps; it is the prioritized roadmap that turns each one into an owned task with an effort estimate and a definition of done, so remediation is a plan rather than a scramble. Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the ones that certify smoothly are almost always the ones that treated the gap assessment as the real start of the work rather than a formality before it. Armour Cybersecurity’s integrated compliance audit program begins with exactly that structured assessment and the readiness score behind it, so you enter remediation knowing the full scope, the cost, and the order of operations before the audit clock starts.

Leave the first comment