Your SOC 2 in progress, and what to tell customers

A buyer wants a report you do not have yet. There is a truthful answer that keeps the deal moving, and there is the version that costs you the account later.

You can say the examination is in progress. You cannot say the company is compliant, certified or covered. The gap between those two sentences is where deals are lost, usually months later, when somebody rereads an email you sent in a hurry.

Name the state you are in, give a date, mark the date as an expectation, and offer the artifacts that do exist. That is the whole play.

A prospect asks for your report. You do not have one. The work has started, which feels like it should count for something, and the temptation is to describe it in the warmest language that is technically defensible. Resist that. A security reviewer is reading for one thing: whether a report exists, and if not, when.

The four states, and which ones you may describe

Saying a SOC 2 in progress means four quite different things depending on where you actually are. Reviewers know this, and a vague claim invites the follow-up question you were hoping to avoid. Say which one is true.

Readiness work, no firm engaged
You are closing gaps and collecting evidence. Nothing is under examination. Describe it as readiness work, never as an audit, and do not name a report date you have no engagement to support.
Engaged, examination not started
A licensed CPA firm has been engaged and the scope is agreed. You may say an examination is engaged and give the planned start. You may not describe a period as being examined until it is.
Fieldwork running
The firm is testing. This is the strongest honest position short of a report, and it is the one worth stating precisely: the report type, the date or period under examination,1 and the expected issuance.
Report issued
Now you have a document. Everything above stops being necessary, and the only questions left are distribution and the period it covers.

The note to send

Short. Factual. Built so a reviewer can paste it into their file without editing it, which is what actually happens to it.

Status note

We are currently under a SOC 2 Type 1 examination performed by an independent licensed U.S. CPA firm, covering the Security criteria for our production platform, as of a control date of 14 October 2026. We expect the report to be issued in November. That is our expectation rather than a commitment, because issuance is the firm’s decision and not ours. In the meantime we can share our control matrix, our written policies and a walkthrough call with our engineering lead, and we will send the report the day we receive it.

Five facts, in order: what is happening, who is doing it, what it covers, when, and what you can offer today. The sentence about issuance being the firm’s decision is the one founders cut, and it is the one that protects you if the date slips.

What readiness work proves, and what it does not

Readiness work is real work. It is not evidence to a third party, and the distinction matters more to your buyer than it does to you.

A readiness assessment is your own measurement of your own controls against the Trust Services Criteria.3 It tells you which controls exist, which are only described, and which have nothing behind them. It carries no opinion from an independent firm, so it proves nothing about whether a control operated. Share it as a gap list and a plan if the buyer wants detail. Do not present it as a substitute for a report, and do not let a slide deck call it one.

If you have not measured yet, that is the first thing to fix, because you cannot give a date without it. The free readiness assessment scores your answers against the same criteria an examination uses and returns the gap list, which is what turns a vague in-progress claim into a defensible one.

A date you cannot support is worse than no date at all.

Five sentences that are not true yet

Each of these gets written every week by somebody who means well. Each is a claim about a document that does not exist. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Do not writeWrite instead
We are SOC 2 compliantWe are under a SOC 2 Type 1 examination, with a control date of 14 October
We are SOC 2 certifiedSOC 2 produces an examination report rather than a certificate, and ours is expected in November
Our SOC 2 is done, the report is just being writtenFieldwork is complete and the report has not been issued
We will have the report by the 30thWe expect the report in November, and issuance is the firm’s decision
Our auditors have signed offTesting is complete. Nothing is signed until the report is issued, and we will send it that day

The second row catches more people than the rest combined. SOC 2 is an attestation engagement and the deliverable is a report carrying an opinion,2 so there is no certificate to hold up. Buyers who have read a few reports notice the word immediately, and it reads as a company that has not been through this before.

When you can first hand over a real report

A Type 1 is an opinion on whether your controls were suitably designed as of a single date. No period of operation has to elapse first, so the constraint is your own readiness and the firm’s schedule rather than the calendar. audit-ready starting at about a week of focused work is a fair planning assumption once you know your gaps.

A Type 2 is different in kind. It covers a window during which controls actually operated, and the window has a floor, so no amount of urgency compresses it. That is the honest answer to a buyer pressing for a Type 2 inside a quarter, and the SOC 2 timeline lays out what each date really depends on. When a contract date is the real constraint rather than the report, a customer asking for a report you do not have is the page for that conversation.

The questionnaire that arrives with it

Nine times out of ten the report request comes attached to a spreadsheet. Answer it. A completed questionnaire is a real artifact, it is signed by you, and for a mid-market buyer it often carries the review on its own while the examination runs.

Answer it the way you would answer under examination. Where a control is in place, say so and name the evidence you would produce. Where it is not, say that too, with the date you expect it. A questionnaire with three honest gaps and dates against them survives diligence. One with no gaps at all invites somebody to go looking, and they will find the same gaps you just claimed were absent.

The one that comes back

Never send a draft report, a sample report or an unsigned opinion, even with a watermark. A reader who has seen one circulated draft treats everything else you send as provisional, and the firm whose name is on it has a legitimate objection to it existing at all.

After the report lands

The in-progress problem does not end at issuance. It comes back every time your report period ends and the next examination has not closed, which is a narrower version of the same question with a standard answer attached to it. That answer is the bridge letter, and the rule underneath it is the one on this page: say what you know, date it, and do not assert anything nobody examined.

Two habits are worth building now. Keep the status note as a living document rather than rewriting it under pressure each time, and log every date you give a buyer so you can tell them yourself when one moves. Founders who do the second one keep deals through a slipped date. The ones who wait to be asked usually do not.

Questions

Can I tell customers my SOC 2 is in progress?
Yes, as long as the engagement really has started. Name the state you are actually in: readiness work underway, an examination engaged with a CPA firm, or fieldwork running. Give the date you expect a report and say it is an expectation rather than a commitment. What you cannot do is describe the company as compliant, certified or covered before a report exists.
What should I put in writing versus say on a call?
Put the status, the scope and the expected date in writing, because a security reviewer has to paste something into their file. Keep speculation about the outcome to the call. Anything you write will be read again months later by somebody who was not on the call, and it will be read literally.
Does a readiness assessment count as a SOC 2?
No. A readiness assessment is your own view of where you stand against the criteria. It has no opinion from an independent CPA firm behind it, and it is not an examination. It is useful to share as a gap list and a plan, and it is not evidence that any control operated.
When can I first hand a buyer an actual report?
A Type 1 report can be issued once the examination of your control design as of a single date is finished, so there is no waiting period built into it. A Type 2 covers a window of operation, which is why it cannot be produced quickly no matter how ready you are.
What if the customer will not accept work in progress?
Ask what would satisfy the review instead. Usually it is a Type 1, a written commitment to a Type 2 date, a signed questionnaire, or a contract clause. All four are things you can produce this week, and knowing which one they need is worth more than another status email.

Sources

  1. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.