Compliance checkups
What the SOC 2 readiness review is and — importantly — what it is not.
A readiness review, not an audit
The SOC 2 readiness review is a readiness and evidence-collection exercise. It is not an audit and not a certification. It produces no opinion, it confers no status, and nothing in its output may be described as SOC 2 compliance. Triagic does not audit or certify anything. Only a licensed CPA firm can perform a SOC 2 examination and issue a report.
What it actually does
The checkup walks the Trust Services Criteria common criteria — CC1 through CC9 — and, for each control, records one of three outcomes:
- Evidence found, quoted, with the system it came from named.
- A gap, with what is missing and what would close it.
- Not assessable from here, with the exact artifact your organization would need to produce.
That third outcome is the honest one and it is common. Evidence for a great many controls lives in an HR system, a signed policy PDF, a board minute or a vendor contract — places this run cannot see. The review records those as unassessed and asks for them. It never infers that a control is satisfied because it found nothing against it: absence of evidence is the finding, not a pass.
Every run states its own scope explicitly — which integrations were connected, which Triagic data it read — because that scope statement is the boundary of what the review can claim.
What it is good for
Running it a few months before a real audit, and again on a monthly cadence, gets you three things an auditor's first request list otherwise gets you the hard way:
- A gap list you can work through while there is still time.
- An evidence request list — the documents somebody will have to go and find.
- A record over time. Findings are tracked like any other, so a control you closed and that later regresses shows up as a regression rather than being quietly lost.
Findings from this checkup carry a controlRef — the criterion they map to, like
CC6.3 — so the remediation list can be sorted the way your auditor will read it.
The rest of the compliance-adjacent library
Access review, Credential and integration hygiene and PII exposure sweep overlap with what an audit will look at, and they are more actionable per run than the full walkthrough. If a finding is really about a credential or an account rather than a control, it belongs in one of those and the readiness review will say so rather than force a mapping.
None of them are audits either. They are the same thing the rest of the library is: a procedure that looks, reports, and changes nothing.