The frustrating part: 80% of their "assessment" was just a standardized checklist mapped to SOC 2 Trust Service Criteria. Could've been automated.
So I built this: https://soc.tools.ssojet.com/
It's a free assessment tool that: - Maps your current setup against SOC 2 requirements - Shows gaps in security, availability, confidentiality, etc. - Gives you the actual TSC reference points
Not trying to replace audit firms (you still need them for certification), but this gives you a realistic readiness score before you spend $$$$ on consultants.
Would love feedback from anyone who's been through SOC 2. What am I missing? What would make this actually useful?