SOC 2, written down.
Everything we have published, in one place. 49 pages on what SOC 2 costs, how long it takes, what the auditor actually asks for, and what to do when the answer is inconvenient. None of it is gated and none of it wants your email first.
Guides
The long pieces. Start here if SOC 2 is new and you want the shape of the whole thing before the detail.
SOC 2 Type 1 vs Type 2: which to start with, and when
A prospect just asked for your SOC 2. Type 1 in weeks, Type 2 in months, and the order matters more than founders realize.
Polara Labs vs Vanta, Drata, and Delve: an honest comparison
We are not a competitor to the big GRC platforms. We are the on-ramp before you need one. Here is the math.
Five SOC 2 control failures we see in almost every startup pre-audit
Patterns from real gap analyses. Every one of these is fixable in days, not weeks. None of them require new tooling.
What SOC 2 Type 1 actually requires for a sub-20-person SaaS
Demystifying the framework: the scope, the policies, the artifacts, and what a CPA actually tests.
AICPA Trust Service Criteria, explained: a founder's reading guide
CC1 through CC9, in plain language, with the engineering practice that satisfies each. Save this and reference it during your audit prep.
SOC 2
What it costs, how long it takes, who signs it, and what happens when something goes wrong. One question per page, answered in the first two sentences.
SOC 2 for AI companies: what actually changes
The Trust Services Criteria have no AI section. What moves is which existing criteria bite, and what evidence satisfies them once customer data leaves for a model provider.
ISO 27001 to SOC 2: what carries over
The four questions a certificate holder actually has, answered in order, with the crosswalk printed in full on the page.
What a SOC 2 auditor actually charges
A SOC 2 has two costs and they go to two different parties. This is the half almost nobody prices in public.
The bridge letter, including the version nobody writes
It covers the months since your report period ended, it is signed by you, and every template we have read assumes the easy case.
SOC 2 certification cost (and why it is not a certification)
Buyers ask for a certificate, and SOC 2 does not have one. Here is the price, and the document that actually arrives.
Is an employer of record a subservice organization?
The provider employs the person. You grant the access. That split decides which controls stay yours and what their paperwork is actually good for.
What SOC 2 actually costs
The vendors who sell SOC 2 publish what an audit costs and hide what they charge. Here is the whole invoice, line by line.
Complementary user entity controls, and how to word yours
The definition is one sentence. The wording is the part with consequences, because a vague CUEC transfers nothing and a precise one reads like a contract term.
Customer asking for SOC 2 report? Read the ask first
The deal is held on a single line in a security review. Here is what exists on your deadline, and the note to send while the examination runs.
The SOC 2 evidence checklist, by cadence
Thirty artifacts, grouped by how often you have to produce them rather than by control area, because the calendar is what actually breaks.
What happens when a SOC 2 audit finds exceptions
A SOC 2 has no pass mark, so there is nothing to fail. What founders mean by failing is an exception, and exceptions are normal, visible to buyers, and mechanical to clear.
What a SOC 2 gap analysis finds
Four different things get sold under three names. Here is what each one produces, who is allowed to run it, and which of them a buyer will actually accept.
How many controls are in SOC 2?
None. SOC 2 defines criteria and leaves the controls to you. There are 61 criteria, and a Security scoped report is measured against 33 of them.
Is a cheap SOC 2 audit legitimate?
A low price is a reason to check, not proof of a fake. What separates a real examination from a form report, and five checks that settle it on any vendor.
SOC 2 log retention: how long to keep logs
The Trust Services Criteria set no retention period. The floor falls out of your own calendar, and several tool defaults sit well underneath it.
How long the SOC 2 observation period has to be
Three months is the floor and six is common. Neither number comes from a rule. Both come from how many times your controls fire before anyone samples them.
The SOC 2 PBC list, request by request
Every page about evidence requests defines the term and stops. This one prints the list, in the wording an auditor uses, with the reason each item comes back.
The SOC 2 policy list, and why the count keeps changing
Published lists disagree because the standard never sets a number. Here is what the criteria actually ask for, and the thirteen documents that answer them.
How ready are you for SOC 2?
Five questions below, no account and no email box. The full assessment is free too, and it gives you a score and a written gap list rather than a brochure.
How long a SOC 2 report stays useful
It never expires, because it is not a certificate. What ages is the window it describes, and buyers enforce that line themselves.
Switching SOC 2 audit firms
Between periods it costs you a procurement cycle. Mid period it costs you months of coverage, because the new firm cannot report on time it never watched.
How long a SOC 2 actually takes
Every phase, the duration it actually takes, and the four things that reliably push your date out.
SOC 2 for a small team: what actually changes
Segregation of duties, access reviews, screening, change approval and incident response all assume more people than you have. Here is what stands in.
How to verify a SOC 2 report you were sent
The document arrives as a PDF and somebody has to decide whether it counts. Here is the read order, and the six checks a template cannot survive.
Who can perform a SOC 2 audit
The rule is one sentence long. Everything else sold in this market is preparation, which is a different job from signing.
Templates
The artifacts an auditor asks for, printed in full on the page. No email wall and no file to download before you can read one.
The user access review template, column by column
The review record itself, header first, then eleven columns, then a worked row for the account that should not have been there.
The incident response plan template SOC 2 auditors test
Written for a company that has never had an incident and will be tested on it anyway. Severity, roles, the clock, the review, the annual exercise.
The SOC 2 management assertion, printed in full
Section 2 is one page, and your name goes on it. Both variants are below, plus the four lines a gated template leaves out.
The employee offboarding checklist, in the order it gets tested
Eighteen steps, an owner on every line, and the artifact each one has to produce. The whole thing is on this page rather than behind a form.
The SOC 2 risk register, filled in
Most of these are an empty grid behind an email form. Here is the grid with rows in it, and the reasoning that decides what a row says.
How to answer a security questionnaire with no SOC 2
Twelve recurring questions, each with the answer that is true today and the answer that is true once a report exists, plus the four sentences that turn a delay into a misrepresentation.
The SOC 2 system description template, section by section
Section 3 is management’s document, not the auditor’s. What belongs in each part, and the wording that gets sent back.
The vendor security questionnaire, and who gets one
Twenty four questions, grouped and numbered, with the rule that decides who receives them and the reason the rest of your vendor list should never see a form.
Tools
Answer a few questions, get a real number. Both show their arithmetic instead of asking you to book a call.
Which Trust Services Criteria should I include?
Security is mandatory. The other four categories are a choice, and most first reports should not make it.
SOC 2 cost calculator
Pick an entry and a term, and every line shows its arithmetic. The numbers are published prices, so the total is an invoice rather than an estimate.
Comparisons
How we compare, and how to leave. Every figure about another company is quoted from that company and stamped with the date we read it.
A Drata alternative that publishes its price
One of these two companies will tell you what it charges before you book a call. At a ten person company, that is most of the difference.
How to leave a compliance platform
Evidence is usually portable. The control mapping and the test history rarely are, and that gap is the whole switching cost.
The Secureframe alternative that publishes its price
What Secureframe publishes on its pricing page, what a gated quote costs in calendar time, the two fees inside any SOC 2 number, and where each product fits.
A Vanta alternative with a published price
Vanta publishes no dollar figure for its own plans, and neither does the rest of the shortlist. Here is what you can still rank them on, and where Vanta is the right buy.
Can I get SOC 2 without a compliance platform?
The honest answer is yes. What the manual route costs you is attention, not eligibility and not the price of the examination.
For audit and readiness firms
The supply side. Engagement economics and practice mechanics, written for the firm doing the work rather than the client buying it.
What audit software costs a small firm
Almost nobody in this category publishes a price, so the comparison that matters is between licensing models rather than between numbers you were never shown.
Audit software security and where your evidence lives
Your client's evidence is your firm's data. This page names the third parties that touch it, the structure that constrains our AI, and the parts we have not built.
How much should a CPA firm charge for a SOC 2 audit?
Every page ranking for SOC 2 cost tells your client what to expect to pay, and none of them state what one engagement costs your practice to run. The platform line is $600 per engagement or $750 a month for unlimited engagements, and the crossover between them is worked out below.
How to start a SOC 2 practice at a small CPA firm
Every page ranking for this question sells SOC 2 to the company buying one. This is the firm side: what has to be true before you sign a first engagement letter.
Ready to put it into practice?
$4,000 one time for SOC 2 Type 1, examination included. No consultants and no platform-locked evidence.
Take the free assessment