Can I get SOC 2 without a compliance platform?
The honest answer is yes. What the manual route costs you is attention, not eligibility and not the price of the examination.
Can I get SOC 2 without a compliance platform? Yes. Companies do it every year. No AICPA standard names a tool, a vendor or a dashboard,1 and the CPA firm that signs your report does not care where the evidence was stored as long as it holds up under testing.
What you trade is time and attention. Not eligibility, and not the price of the examination. Those two facts decide most of this.
Every page ranking for this question is published by somebody who sells compliance software, this one included. That does not make any of them dishonest. It does mean the answer arrives pre-shaped, because a plain yes costs the writer a sale. Weigh that however you like.
What the standard actually requires
Nothing about tooling. A SOC 2 report is an attestation engagement performed under AICPA standards by a licensed CPA firm. The firm evaluates how your controls are described and, for a Type 2, whether they operated across a period.2 Spreadsheets are evidence. Screenshots are evidence. A policy in a shared document, approved by a named person on a real date, is a policy.
Software is not what makes you eligible. It changes who assembles the package and how long that takes. That is a real benefit and a much weaker one to sell. If which report your buyer wants is still open, Type 1 versus Type 2 settles that first.
What a platform is actually replacing
A platform does three jobs. Two of them finish. The third never does, and that is the one that decides how this goes.
- The control list
- Which Trust Services Criteria you are in scope for, and a control against each one.3 You can build it by hand from the criteria. Scoping too wide is what makes it expensive.
- The policy set
- Around thirteen documents. Access control, change management, incident response, vendor management, the rest of the shelf. Templates are everywhere. Adapting one until it describes what your company genuinely does is the work, and an auditor spots an unadapted template immediately.
- The evidence cadence
- Access reviews, change tickets, scan output, joiner and leaver records, collected on a schedule and filed where somebody other than you can find them. This is the part that decays. It is also the part the auditor bills against.
What the manual path costs you
Not money, mostly. Attention, in uninterrupted blocks, from the one person who can answer questions about production access. That is usually your best engineer, and the real price of the manual route is whatever they were going to build instead.
The load lands in four places. Building the control list, then revising it when the auditor reads it differently. Writing the policies. Collecting evidence for as long as the window runs. Then keeping all of it organized enough that the auditor is not billing you to chase it. The first three are bounded. The fourth runs over, because it is the only one with no natural finish line.
The auditor fee does not move
A CPA firm prices an engagement on hours. That is the whole mechanism. Hours track how much chasing the evidence requires. Two companies with identical controls get quoted differently because one answers a request in an hour and the other takes nine days and sends the wrong screenshot twice.
Two published sources sit behind that. One puts the floor higher than founders expect. The other is a warning:
- One published practitioner breakdown puts a Security-only Type 2 at 60 to 80 auditor hours, at partner rates of $250 to $350 per hour and staff rates of $100 to $175, giving a stated floor near $9,000. Source, checked 2026-07-30.
- Linford and Company warns buyers to be careful when a compliance tool has a partner audit firm with a set fee far below other bids, citing a case where one firm issued the same form report to every client with only the names changed. Source, checked 2026-07-30.
Read the first one as what it is. An hours calculation. Hours are the variable you can move, and buying software is not what moves them. Organized evidence is, and a disciplined spreadsheet produces that as well as a tool does. Hand over a package that arrives complete, indexed and mapped to the criteria and the hours come down, no matter what produced it. Our auditor fee page pulls that number out on its own.
The second one describes our shape, so take it seriously here. A platform with a partner CPA firm on a set fee is the arrangement being warned about, and the checks that separate a real examination from a form report are not about price. Ask for the firm name in writing before you sign. Look it up in the license register of its state board.4 Read Section 4 for tests that name your systems rather than a template’s. Run those on us, and on anyone else quoting you a number. Whether a cheap audit can be legitimate walks through all five.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
What changes and what does not
Four questions separate the two routes. The answers agree on everything involving the report itself and diverge on everything involving your calendar. Any comparison that blurs that line is selling something.
| The question | Doing it yourself | Using a platform |
|---|---|---|
| Are you eligible for a SOC 2 report? | Yes. No standard requires software. | Yes. Same standard, same criteria. |
| Who examines and signs it? | A licensed U.S. CPA firm you hire. | A licensed U.S. CPA firm. Here, an independent partner auditor. |
| What moves the examination fee? | How organized your evidence is. | The same thing. The tool only helps to the extent it makes the package arrive complete. |
| How long until you are audit ready? | Unbounded. It tracks the free attention you have. | audit-ready starting at about a week here, with the gap engine and the policy pack doing the first pass. |
When doing it yourself is the right call
Three conditions. If all three hold, keep the money, because what you would be buying is speed you do not need.
- Your scope is genuinely small. One product, one cloud account, a handful of people, Security criteria only. The control list fits on a page.
- Someone has real capacity. Not enthusiasm. Capacity, meaning a standing block of hours each week that nothing else is allowed to take.
- No deal is waiting on it. You are working ahead of demand rather than against a paused contract. Nothing punishes a slipped week.
When it is not
Three conditions again, and here one is enough. These are not edge cases. They describe most of the companies that go looking for this answer.
- A live deal has a date on it. The date is not yours to move. Elapsed time is the whole problem, and elapsed time is what software genuinely sells. See what to do when a deal is waiting.
- Nobody has spare capacity. If the honest answer to who owns this is everyone a bit, it will stall at the policy set and restart from nothing three months later.
- You cannot describe your scope yet. If you cannot say in a paragraph which systems are in and which are out, the manual route lets you build the wrong thing for a month before anyone corrects you.
A third route we do not sell
Do the preparation yourself, then engage a licensed CPA firm directly and pay their fee. You build the control list, write the policies and collect the evidence at whatever pace your team sustains, with nobody billing you monthly while you do it. Then the firm examines what you built.
We cannot sell you that. Our examination opens to Type 2 subscribers once the 3-month observation window closes, because we have to have watched the window to attest to it. Engage a CPA firm directly instead, and what a SOC 2 auditor actually charges shows you what that fee is made of.
If you would rather the software do the first pass, Type 1 is $4,000 one time with the first examination and the auditor engagement fee inside that number, and the Type 2 subscription runs $600 per month on a 12-month term. Those numbers sit below the practitioner floor quoted above. The reason is the hours, not the auditor, and the cheap audit question is where we take that apart. Every line is on the cost page, and the calculator totals it for your case.
Why the search results all say yes, but
Search this and you get vendor domains, ours now among them. Each one has to say yes, because no is false. Each one then follows the yes with a reason to buy anyway. The companies writing that advice have something else in common.
- Vanta lists four plans on its pricing page and no dollar figure. The call to action is to request personalized pricing. Source, checked 2026-07-30.
- Secureframe lists three plans on its pricing page and no dollar figure. Each one links to a quote request. Source, checked 2026-07-30.
- Drata has no public pricing page. The URL serves the homepage, where the calls to action are to contact sales or book a demo. Source, checked 2026-07-30.
- Suralink publishes no price, stating that every company and team has different needs and inviting prospects to reach out. Source, checked 2026-07-30.
That is a description rather than an accusation. Gated pricing is an ordinary enterprise motion. It does change what the advice is worth: a page recommending software without disclosing what the software costs is arguing one side of a trade while holding back half the numbers. Our Vanta comparison runs the same questions with our column filled in, including where the incumbent is the better buy.
Decide it in four questions
Answer these in writing, today, before you price anything. Most people know by the third one, and the fourth catches the expensive mistake.
- Is there a date? A real deal with a real deadline changes the answer more than headcount, budget or scope does.
- Name the person. One name, hours already blocked. If you cannot name them, the choice is not between two routes. It is between buying and not starting.
- Write the scope in a paragraph. Systems in, systems out, criteria selected. If that paragraph is hard, the manual route will be harder.
- Ask an auditor what shortens their hours. Ask before you buy anything. The answer will be about how the evidence arrives, not about which tool produced it.
If you finish this page and decide to do it yourself, that is the right answer, and you do not owe us a follow-up. How the flow runs here is documented either way, and a control list you built by hand is yours regardless of who examines it.
Questions
Can I get SOC 2 without a compliance platform?
Does doing it manually make the audit cheaper?
How long does the manual route take?
Can I do the work myself and buy only the examination?
When should I buy a platform instead?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.