The road to a SOC 2 report
What the year actually looks like, where the time really goes, and the five ways companies turn a four-month project into a fourteen-month one.
Type I says the controls were designed properly on one date. Type II says they actually operated over a window, usually three to twelve months. Enterprise buyers want Type II. Type I is worth doing only when you need something to show a buyer within weeks and you are committed to the Type II immediately after. Doing Type I as an end in itself buys you a document most procurement teams will not accept.
SOC 2 is an attestation, not a certification. A CPA firm examines whether the controls you described were designed properly and, for a Type II, whether they operated over a period of time. Nobody grants you a certificate. You get a report, and your customers read it.
Read this if
- A customer contract or a security review is gating on it, with a date attached
- You sell software or a service that holds someone else's data
- You are between roughly 20 and 500 people and this is your first time
- You have bought a compliance automation platform and the percentage is not moving
What the program actually looks like.
Durations assume a first attempt with a team that has other work to do. They are the numbers we would give you on a call, not the ones in a sales deck.
Scope the audit
2 to 4 weeksDecide which systems, which trust services criteria and which entity are in scope. This single decision drives cost, effort and duration more than anything else you will do. Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are each optional and each adds real work.
Gap assessment
2 to 3 weeksCompare current practice against the criteria in scope. Split findings three ways: audit-blocking, deal-blocking, and neither. Only the first two earn engineering time before the audit.
Remediate and design controls
4 to 12 weeksBuild the controls that are missing and redesign the ones that exist but would not survive fieldwork. Design them around how your team already works, or you will be fighting them every quarter for years.
Operate through the observation window
3 to 12 monthsThis is the part nobody can compress. For a Type II, the auditor examines evidence across a period. Three months is the shortest window most auditors will accept; six to twelve is what enterprise buyers prefer to see. The window starts when the controls genuinely operate, not when you decide it starts.
Auditor fieldwork
3 to 6 weeksThe auditor samples evidence, interviews control owners and tests operating effectiveness. Your job here is logistics and fast, accurate answers. Engineers should be involved only where they are genuinely needed.
Report and sustain
2 to 4 weeks, then annualThe report issues. Then the real question: will year two be a repeat of year one, or a routine? That is decided by whether evidence is produced by working normally or by a quarterly scramble.
The five things that consume the calendar.
None of these are the parts people budget for, and all of them are the parts that slip.
- The observation window. It is calendar time and no amount of money shortens it.
- Access reviews across every in-scope system, done properly rather than as a signature on a CSV export.
- Vendor management, because SOC 2 asks about your subservice organizations and most companies have never listed them.
- The system description, a narrative document that auditors judge and customers read, and that no platform generates for you.
- Waiting for an auditor with capacity, which in Q4 can be six weeks on its own.
What moves the number.
Two organizations of the same size can differ several-fold on price. This is usually why.
- Number of trust services criteria beyond Security
- Number of in-scope systems and cloud environments
- Length of the observation window
- Whether you have any control ownership internally, or none
- Headcount, because auditors price partly on the size of the population they sample
What you have to produce.
Every one of these will be asked for. Missing any of them is a finding.
| Artifact | What it has to contain |
|---|---|
| Scope and boundary document | What is in, what is out, and the reasoning for both |
| Policy set | Written to match reality, not a downloaded template library |
| Risk assessment | Documented, dated, and revisited, because the auditor will ask when you last did it |
| System description | The narrative at the front of the report describing your service and its controls |
| Evidence repository | Organized so an auditor can walk it without a guide |
| Vendor inventory | Subservice organizations, what they do, and their own reports |
| Management assertion | Your formal statement that the description is fair and controls operated |
Five failures we see repeatedly.
Each of these turns a manageable program into an expensive one. All five are avoidable at the start and very hard to fix in the middle.
Scoping by accident
Nobody makes a deliberate decision about the boundary, so the whole corporate estate ends up in scope. The control surface roughly doubles, the evidence load doubles with it, and the customer gets no additional assurance for any of it.
Believing the platform is the program
Vanta, Drata and Secureframe collect evidence continuously and that is genuinely useful. None of them can scope an audit, design a control, write the system description or argue with an auditor. The dashboard goes green while the program underneath is not defensible.
Starting the window too early
The observation period begins and the controls are not really operating yet. Three months later the sample comes back with gaps, and the choice is a qualified report or restarting the clock.
Treating the system description as boilerplate
It is the part of the report your customers actually read. A vague or inaccurate one undermines an otherwise clean opinion, and a customer who spots the gap between the description and reality will ask about it.
Choosing the auditor on price alone
The cheapest quote is often a firm that will sample lightly and issue quickly. That feels efficient until an enterprise buyer's security team recognizes the name and discounts the report.
What people ask us about SOC 2.
How long does it really take, start to finish?
Do we need a compliance platform?
What does it cost?
Can we reuse this for ISO 27001?
Keep reading
The road to ISO/IEC 27001:2022 certification
A management system, not a control checklist. What the standard actually requires, why Stage 1 audits fail, and the records auditors ask for that nobody thinks to keep.
The road to CMMC, and what the Phase 2 suspension changed
The certification timeline moved. The obligations did not. What defense contractors actually have to do right now, and why pausing your program would be the expensive reading of the news.
Want this run for you?
We run these programs end to end: scoping, control design, evidence, auditor management, and the operating rhythm that keeps year two boring.