SOC 2, written down.

Everything we have published, in one place. 49 pages on what SOC 2 costs, how long it takes, what the auditor actually asks for, and what to do when the answer is inconvenient. None of it is gated and none of it wants your email first.

Guides

The long pieces. Start here if SOC 2 is new and you want the shape of the whole thing before the detail.

SOC 2

What it costs, how long it takes, who signs it, and what happens when something goes wrong. One question per page, answered in the first two sentences.

SOC 2 for AI companies: what actually changes

The Trust Services Criteria have no AI section. What moves is which existing criteria bite, and what evidence satisfies them once customer data leaves for a model provider.

8 min

ISO 27001 to SOC 2: what carries over

The four questions a certificate holder actually has, answered in order, with the crosswalk printed in full on the page.

9 min

What a SOC 2 auditor actually charges

A SOC 2 has two costs and they go to two different parties. This is the half almost nobody prices in public.

7 min

The bridge letter, including the version nobody writes

It covers the months since your report period ended, it is signed by you, and every template we have read assumes the easy case.

7 min

SOC 2 certification cost (and why it is not a certification)

Buyers ask for a certificate, and SOC 2 does not have one. Here is the price, and the document that actually arrives.

5 min

Is an employer of record a subservice organization?

The provider employs the person. You grant the access. That split decides which controls stay yours and what their paperwork is actually good for.

8 min

What SOC 2 actually costs

The vendors who sell SOC 2 publish what an audit costs and hide what they charge. Here is the whole invoice, line by line.

8 min

Complementary user entity controls, and how to word yours

The definition is one sentence. The wording is the part with consequences, because a vague CUEC transfers nothing and a precise one reads like a contract term.

8 min

Customer asking for SOC 2 report? Read the ask first

The deal is held on a single line in a security review. Here is what exists on your deadline, and the note to send while the examination runs.

7 min

The SOC 2 evidence checklist, by cadence

Thirty artifacts, grouped by how often you have to produce them rather than by control area, because the calendar is what actually breaks.

9 min

What happens when a SOC 2 audit finds exceptions

A SOC 2 has no pass mark, so there is nothing to fail. What founders mean by failing is an exception, and exceptions are normal, visible to buyers, and mechanical to clear.

8 min

What a SOC 2 gap analysis finds

Four different things get sold under three names. Here is what each one produces, who is allowed to run it, and which of them a buyer will actually accept.

7 min

How many controls are in SOC 2?

None. SOC 2 defines criteria and leaves the controls to you. There are 61 criteria, and a Security scoped report is measured against 33 of them.

6 min

Is a cheap SOC 2 audit legitimate?

A low price is a reason to check, not proof of a fake. What separates a real examination from a form report, and five checks that settle it on any vendor.

7 min

SOC 2 log retention: how long to keep logs

The Trust Services Criteria set no retention period. The floor falls out of your own calendar, and several tool defaults sit well underneath it.

8 min

How long the SOC 2 observation period has to be

Three months is the floor and six is common. Neither number comes from a rule. Both come from how many times your controls fire before anyone samples them.

7 min

The SOC 2 PBC list, request by request

Every page about evidence requests defines the term and stops. This one prints the list, in the wording an auditor uses, with the reason each item comes back.

9 min

The SOC 2 policy list, and why the count keeps changing

Published lists disagree because the standard never sets a number. Here is what the criteria actually ask for, and the thirteen documents that answer them.

7 min

How ready are you for SOC 2?

Five questions below, no account and no email box. The full assessment is free too, and it gives you a score and a written gap list rather than a brochure.

7 min

How long a SOC 2 report stays useful

It never expires, because it is not a certificate. What ages is the window it describes, and buyers enforce that line themselves.

7 min

Switching SOC 2 audit firms

Between periods it costs you a procurement cycle. Mid period it costs you months of coverage, because the new firm cannot report on time it never watched.

7 min

How long a SOC 2 actually takes

Every phase, the duration it actually takes, and the four things that reliably push your date out.

7 min

SOC 2 for a small team: what actually changes

Segregation of duties, access reviews, screening, change approval and incident response all assume more people than you have. Here is what stands in.

8 min

How to verify a SOC 2 report you were sent

The document arrives as a PDF and somebody has to decide whether it counts. Here is the read order, and the six checks a template cannot survive.

7 min

Who can perform a SOC 2 audit

The rule is one sentence long. Everything else sold in this market is preparation, which is a different job from signing.

7 min

Templates

The artifacts an auditor asks for, printed in full on the page. No email wall and no file to download before you can read one.

The user access review template, column by column

The review record itself, header first, then eleven columns, then a worked row for the account that should not have been there.

5 min

The incident response plan template SOC 2 auditors test

Written for a company that has never had an incident and will be tested on it anyway. Severity, roles, the clock, the review, the annual exercise.

6 min

The SOC 2 management assertion, printed in full

Section 2 is one page, and your name goes on it. Both variants are below, plus the four lines a gated template leaves out.

6 min

The employee offboarding checklist, in the order it gets tested

Eighteen steps, an owner on every line, and the artifact each one has to produce. The whole thing is on this page rather than behind a form.

5 min

The SOC 2 risk register, filled in

Most of these are an empty grid behind an email form. Here is the grid with rows in it, and the reasoning that decides what a row says.

5 min

How to answer a security questionnaire with no SOC 2

Twelve recurring questions, each with the answer that is true today and the answer that is true once a report exists, plus the four sentences that turn a delay into a misrepresentation.

6 min

The SOC 2 system description template, section by section

Section 3 is management’s document, not the auditor’s. What belongs in each part, and the wording that gets sent back.

6 min

The vendor security questionnaire, and who gets one

Twenty four questions, grouped and numbered, with the rule that decides who receives them and the reason the rest of your vendor list should never see a form.

5 min

Tools

Answer a few questions, get a real number. Both show their arithmetic instead of asking you to book a call.

Comparisons

How we compare, and how to leave. Every figure about another company is quoted from that company and stamped with the date we read it.

For audit and readiness firms

The supply side. Engagement economics and practice mechanics, written for the firm doing the work rather than the client buying it.

Ready to put it into practice?

$4,000 one time for SOC 2 Type 1, examination included. No consultants and no platform-locked evidence.

Take the free assessment
polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report or an ISO 27001 certificate, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.