Customer asking for SOC 2 report? Read the ask first

The deal is held on a single line in a security review. Here is what exists on your deadline, and the note to send while the examination runs.

Six weeks out, the answer is a Type 1. You cannot have a Type 2 by then, and nobody can sell you one. A Type 1 is a signed opinion from an independent partner auditor, a licensed U.S. CPA firm that your controls were suitably designed as of a single date,1 and it clears most procurement holds on its own. Through Polara Labs it is $4,000 one time, examination and auditor engagement fee included.

Before that date arrives you still have something to send: a scoped control set, thirteen written policies, and an evidence binder mapped to criteria that a security reviewer can be walked through on a call. That is what the reviewer can evaluate before a report exists.

It shows up as one line in a long email. Legal is done, the order form is sitting in somebody’s inbox, and the security review needs your SOC 2 before anything moves. Nobody at your company has seen a SOC 2 report. The customer’s date does not move.

Two questions matter now, in this order. What will physically exist on the deadline, and will this particular buyer accept it? Every timeline article answers a third question instead, the one about average phase durations, which is no use to you at all while a contract sits unsigned.

Read the ask before you buy anything

Procurement teams write “SOC 2” without saying which one. The wording tells you which product you actually need, and the gap between the two is months of calendar time. Three phrasings cover most asks.

  • “Send us your SOC 2.” No further detail, no version named. A Type 1 clears this. The reviewer is closing a checklist item and wants to see a signed opinion from a licensed CPA firm with your company name on it.
  • “Your most recent SOC 2 Type II report.” They know the difference and they want the operating effectiveness assertion. Common from enterprise security teams, fintech counterparties, and anyone touching regulated data. A Type 1 alone will not finish this conversation.
  • “Your SOC 2, or your plan and timeline.” This is a soft ask, and it is the easiest of the three. A Type 1 in flight plus a dated written commitment to Type 2 usually clears it inside a week.

Ask, if you are unsure. “Will a Type 1 satisfy your review for this contract?” is a normal question, security reviewers answer it, and a five minute reply can save you a three-month observation window you did not need. The mechanical difference between the two reports is covered in Type 1 versus Type 2.

Six weeks, week by week

This is a calendar against a real date, not an average. It assumes one person can give the work ten hours a week and that your stack is the ordinary one: AWS or Google Cloud, GitHub, Google Workspace. Nothing here needs a consultant.

  1. Week one: scope, gaps, policies. You answer a readiness questionnaire, connect your cloud and source control, and get back a deterministic gap list plus thirteen policies written against your actual stack rather than a template pack. Scope to Security only unless a contract names another category.2 This is the week you can already tell the customer something true.
  2. Week two: close what is configuration. Enforce multi-factor authentication, turn on logging and retention, protect the main branch, run the access review, write the incident response contacts down. Most first-time gaps are settings, not projects. By the end of this week you can name your observation date to the buyer.
  3. Weeks three and four: build the binder. Every control gets its evidence attached and mapped to the criteria it satisfies. Screenshots, exported configuration, ticket links, signed policy acknowledgements. The package then goes to the independent partner auditor with the observation date fixed.
  4. Weeks five and six: the examination. The CPA firm reviews the package, comes back with questions, and issues the report. An examination of this size typically runs one to two weeks once the evidence is complete. You forward the report the day it is issued.

Two things move that calendar, and neither is the software. Evidence you cannot produce because the control was never operating, and a scope you set wider than the contract requires. On the platform side you are audit-ready starting at about a week; the rest of the six weeks is your own remediation and the examination itself. The same phases without a deal date attached to them are broken out in how long a SOC 2 actually takes, and how it works covers the sequence from the product side.

What is genuinely out of reach

You cannot compress a Type 2.

It rests on a 3-month observation window at minimum, because the auditor tests samples from a period that has to have actually happened.3 Nobody sells a shortcut around that, and any vendor implying otherwise is telling you something you can check. If the contract truly requires Type 2, say so in week one and negotiate the date, or sign with a commitment clause instead.

A sales cycle costs a week you do not have

Buying fast is its own line item. On a deadline you need a number today, and most of this market will not give you one without a call first. These were opened and read on the date shown.

  • Vanta lists four plans on its pricing page and no dollar figure. The call to action is to request personalized pricing. Source, checked 2026-07-30.
  • Secureframe lists three plans on its pricing page and no dollar figure. Each one links to a quote request. Source, checked 2026-07-30.
  • Drata has no public pricing page. The URL serves the homepage, where the calls to action are to contact sales or book a demo. Source, checked 2026-07-30.
  • Suralink publishes no price, stating that every company and team has different needs and inviting prospects to reach out. Source, checked 2026-07-30.

A demo, a discovery call, a quote and a redline is a week of your six spent before any work starts. Our price is on the page and the checkout is self-serve for that reason. The full breakdown, with the auditor fee separated out, is on the cost page.

What to send while the examination is in progress

Never say a report exists before it does. One sentence of stretch here is what kills the deal two weeks later, when the reviewer asks for the PDF and there is not one. A buyer who has run vendor reviews before can tell a company mid-examination from a company improvising.

This is the note that works. Send it from the account owner, not from a shared inbox.

Copy this, change the bracketed parts

We are in a SOC 2 Type 1 examination now. Our controls are being examined as of [date], and the examination is being performed by an independent partner auditor, a licensed U.S. CPA firm. I will send the report the day it is issued, and I will give you the firm’s expected issue date as soon as they confirm it. In the meantime I can share our control matrix mapped to the Trust Services Criteria, our written security policies, and a walkthrough of how evidence is collected. If it helps your file, I can also put our scope and observation date in writing on letterhead today.

It names a date, it names the standard, and it hands the reviewer something to evaluate this week instead of a promise. That last part is the one that moves. Most security reviews have a conditional path for vendors mid-examination, and reviewers use it when the evidence in front of them is real.

The questionnaire that arrives with it

A security questionnaire usually lands in the same thread. Two hundred rows in a spreadsheet, sometimes a portal, always a due date. Answer it in parallel, not after.

Most of the answers are already sitting in the policies you are writing for the examination, which is why doing both at once costs less than doing them in sequence. Do not guess. A wrong yes becomes a finding later, and an honest “not yet, here is the compensating control and the date it lands” is almost never the answer that loses a deal. The gaps that show up most often on a first pass are listed in five common control failures, and they are the ones worth fixing before the questionnaire goes back.

What not to promise

There is no SOC 2 certificate. There is a report, and it carries an opinion for a named date or a named period.1 Anyone who reviews these documents for a living notices the difference immediately, and the correction lands at the worst possible moment in the deal.

Say this accurately, every time

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Two more to avoid. Do not send a draft report to a customer; a draft carries no opinion and the auditor has not finished with it. And never name an issue date the CPA firm has not agreed to. A missed date you invented is worse than the original gap.

After this deal closes

The Type 1 gets you through this one. The next enterprise buyer, or this same buyer at renewal, will ask for the Type 2, and the observation window can start the day after your Type 1 date. Keep collecting evidence rather than stopping, and the second report costs you attention instead of a scramble.

Type 2 monitoring is $600 per month on a 12-month term, or $6,000 on one invoice for the first year, two months free versus paying monthly. Each examination is $5,000, including the first, and it becomes available once the 3-month observation window completes. Plan that now, while somebody is paying attention to security at your company. Once the contract is signed, that attention goes somewhere else.

Questions

My contract closes in six weeks. Can I have a SOC 2 report by then?
A SOC 2 Type 1, yes. Type 1 is an opinion on whether your controls were designed properly as of a single date, so it needs no observation period. A Type 2 covers a period of at least three months of operation, so six weeks cannot produce one. Most buyers who ask without specifying will accept the Type 1.
What do I send the customer while the examination is still running?
Tell them the examination is in progress, name the date your controls are being examined as of, and offer your control matrix, your written policies and a walkthrough call. Never say a report exists before it has been issued. Offer to share it the day it is.
Will the buyer accept a Type 1 if they asked for a Type 2?
Often, with a written commitment to a Type 2 within twelve months. Ask the reviewer directly whether a Type 1 satisfies their review for this contract. If the data is regulated or the counterparty is a bank, plan for the Type 2 and negotiate the contract date instead.
What does it cost to unblock the deal?
A SOC 2 Type 1 is $4,000 one time, and that covers the first examination and the engagement fee for the independent partner auditor. Type 2 monitoring afterwards is $600 per month on a 12-month term, and each examination is $5,000.
Can I show the customer a draft report to hold the deal?
No. A draft carries no opinion, and circulating one costs you credibility with the security reviewer and with the auditor. Send the control matrix and the policies instead, then put the issued report in front of them the day it exists.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  3. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty