Readiness has four ingredients, and teams reliably overweight the first. Controls: implemented and running at their stated frequency. Evidence: existing for the whole period, not just recent weeks — a control that ran but left no artifact will test as if it never ran. People: owners who can walk an auditor through their process without contradicting the policy. Documentation: policies, the system description, and the risk assessment matching present-day reality rather than the version of the company that wrote them. Miss any one and the audit finds it; auditors are professionally good at locating the ingredient you skipped.
The formal version is a readiness assessment — a dry run where someone fluent in audit testing samples your evidence and interviews your owners, then reports what would fail. The lightweight version is a structured self-check; our SOC 2 readiness checklist covers the questions an assessor would ask. Either way, the useful output is a punch list with time to act on it.
Readiness also decays: it is a snapshot, and controls drift the week after you verify them. Programs that hold the state year-round are practicing continuous compliance; everyone else is scheduling their next scramble.
Before a first audit, readiness is mostly a construction question — do the controls and policies exist at all, and has evidence accumulated long enough to test? Before a renewal, it becomes a maintenance question: did anything drift while attention moved elsewhere, and did every recurring ritual actually recur? Renewal failures are quieter and more embarrassing, because the program passed once — which is exactly why teams check the state deliberately instead of assuming last year’s pass still holds.