Gap analysis and compliance monitoring are essential practices for identifying where an organization falls short of required security standards before undergoing formal third-party audits. SOC 2 attestations, performed by CPA firms, provide external validation of a company's compliance posture but come with significant cost.
Compliance Monitoring & Gap Analysis
There are certain things that we need to comply with, a set of standards that we need to meet, and what the company is doing hopefully goes beyond those standards. But that's not usually the case. There are usually things within a company that go unnoticed. Unless you have a huge security department that makes sure that you're covering everything that you need to do, you probably have a little bit of a gap. But how big is that gap? How much standards do we have, and how much lower are we operating at? What we may need to do is a gap analysis to determine what that gap is and how we can fill in that gap.
When it comes to compliance monitoring, what we're doing is we're taking the compliance standards, whatever we've determined we need to follow, and we're taking action on that, and then we're monitoring to make sure we're doing all of that.
Let's generate a little scenario here. Let's say we work for a company and we are doing compliance monitoring to make sure that we're in compliance, and we have generated reports off that and we're turning those over to customers. But we have a few clients that require us to take the next step and get a third-party auditor to come in and make sure that we are doing exactly what we're saying we're going to do. So they're going to perform an attestation. Specifically, they want a SOC 2 attestation.
That's going to be done by a CPA firm, so that's a specific type of firm. It's a financial firm that's going to come in, and usually they do financial documents, but they have a team of people that do just SOC 2 attestations. SOC 2 Type 1 is going to just look at the standards and make sure that you have the right standards for the size and type of company that you are. But the other thing that they're going to do, if you're doing a Type 2, is they're going to take a look and see if you're following through with those: are you taking the proper actions? So this is going to be an attestation that's going to happen by this financial firm.
At the end of the attestation, what the CPA firm is going to do is generate a report, and the report is going to show us whether we're complying with everything, whether it is to the level that we need to have as far as the standards are concerned, or if we're deficient in any certain area. Then we can take this report and they'll label us as being SOC 2 compliant, and then we can turn this report over to our customers that are asking for it.
The reason why I bring this up is because this is a very expensive process. Even the more basic ones are tens of thousands of dollars to come and do a more simple SOC attestation. Since it can be so expensive, what we probably want to do ahead of time is a gap analysis. This is going to be where we're going to analyze to see where we're deficient. In the end, what we might find is that we don't have the proper standards, or we're not implementing the proper standards. Now what we can do is take corrective action to fix this before we go through a really expensive SOC audit only to fail that SOC audit. Now we can be successful in that audit and not waste our money.
Now, in my experience, you don't really want to do the gap analysis internally. I mean, you're really already doing that internally as part of your processes. So really what you want to do is hire a third party to come in and do the gap analysis. And what I've actually done is hired whoever is going to do the SOC attestation; I hire them to do the gap analysis as well. So in this scenario right here, it would still cost quite a bit of money to do the gap analysis, but not nearly as much as it would cost to do the full SOC.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →