SOC 2: cost, timeline and evidence.

What it costs, how long it takes, what the auditor actually asks for, and what happens when something goes wrong.

SOC 2 for AI companies: what actually changesThe Trust Services Criteria have no AI section. What moves is which existing criteria bite, and what evidence satisfies them once customer data leaves for a model provider.8 min readISO 27001 to SOC 2: what carries overThe four questions a certificate holder actually has, answered in order, with the crosswalk printed in full on the page.9 min readWhat a SOC 2 auditor actually chargesA SOC 2 has two costs and they go to two different parties. This is the half almost nobody prices in public.7 min readThe bridge letter, including the version nobody writesIt covers the months since your report period ended, it is signed by you, and every template we have read assumes the easy case.7 min readSOC 2 certification cost (and why it is not a certification)Buyers ask for a certificate, and SOC 2 does not have one. Here is the price, and the document that actually arrives.5 min readIs an employer of record a subservice organization?The provider employs the person. You grant the access. That split decides which controls stay yours and what their paperwork is actually good for.8 min readWhat SOC 2 actually costsThe vendors who sell SOC 2 publish what an audit costs and hide what they charge. Here is the whole invoice, line by line.8 min readComplementary user entity controls, and how to word yoursThe definition is one sentence. The wording is the part with consequences, because a vague CUEC transfers nothing and a precise one reads like a contract term.8 min readCustomer asking for SOC 2 report? Read the ask firstThe deal is held on a single line in a security review. Here is what exists on your deadline, and the note to send while the examination runs.7 min readThe SOC 2 evidence checklist, by cadenceThirty artifacts, grouped by how often you have to produce them rather than by control area, because the calendar is what actually breaks.9 min readWhat happens when a SOC 2 audit finds exceptionsA SOC 2 has no pass mark, so there is nothing to fail. What founders mean by failing is an exception, and exceptions are normal, visible to buyers, and mechanical to clear.8 min readHow many controls are in SOC 2?None. SOC 2 defines criteria and leaves the controls to you. There are 61 criteria, and a Security scoped report is measured against 33 of them.6 min readIs a cheap SOC 2 audit legitimate?A low price is a reason to check, not proof of a fake. What separates a real examination from a form report, and five checks that settle it on any vendor.7 min readSOC 2 log retention: how long to keep logsThe Trust Services Criteria set no retention period. The floor falls out of your own calendar, and several tool defaults sit well underneath it.8 min readHow long the SOC 2 observation period has to beThree months is the floor and six is common. Neither number comes from a rule. Both come from how many times your controls fire before anyone samples them.7 min readThe SOC 2 PBC list, request by requestEvery page about evidence requests defines the term and stops. This one prints the list, in the wording an auditor uses, with the reason each item comes back.9 min readThe SOC 2 policy list, and why the count keeps changingPublished lists disagree because the standard never sets a number. Here is what the criteria actually ask for, and the thirteen documents that answer them.7 min readHow long a SOC 2 report stays usefulIt never expires, because it is not a certificate. What ages is the window it describes, and buyers enforce that line themselves.7 min readSwitching SOC 2 audit firmsBetween periods it costs you a procurement cycle. Mid period it costs you months of coverage, because the new firm cannot report on time it never watched.7 min readHow long a SOC 2 actually takesEvery phase, the duration it actually takes, and the four things that reliably push your date out.7 min readSOC 2 for a small team: what actually changesSegregation of duties, access reviews, screening, change approval and incident response all assume more people than you have. Here is what stands in.8 min readHow to verify a SOC 2 report you were sentThe document arrives as a PDF and somebody has to decide whether it counts. Here is the read order, and the six checks a template cannot survive.7 min readWho can perform a SOC 2 auditThe rule is one sentence long. Everything else sold in this market is preparation, which is a different job from signing.7 min read

Get audit-ready without a compliance team.

Every price on this site is the price. No quote gate.

Get started
polara labs

Polara Labs builds both sides of the SOC 2 audit: the readiness platform startups use to earn their report, and the practice OS audit firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.