← All posts
September 29, 2026· The cybersoftware team

SOC 2 in progress: answering 'are you SOC 2 compliant?'

How to answer 'are you SOC 2 compliant?' honestly while your SOC 2 is in progress, what to share with buyers, and wording that keeps deals moving.

Sooner or later a buyer asks the question, usually on a security questionnaire or in the last week of a deal: "Are you SOC 2 compliant?" If your report is not issued yet, it can feel like there is no good answer. There is. Buyers deal with vendors whose SOC 2 is in progress all the time. What they need is an honest status, a credible plan and enough evidence to keep going. This guide covers how to answer, what to share and what never to say.

What the buyer is really asking

"SOC 2 compliant" is shorthand. There is no SOC 2 certificate and no official compliant status. What a buyer actually wants to know is one of three things:

  1. Do you have a current SOC 2 report from an independent CPA firm that they can read under NDA?
  2. If not, when will you, and is the date credible?
  3. In the meantime, are your security practices good enough for them to start working with you?

Answer those three, and most security reviews can move forward.

Never say you have a report you do not have

This is the one rule. Do not say "yes" to "are you SOC 2 compliant?" if no report exists, and do not call a readiness score, a policy set or a software subscription a SOC 2. The buyer's security team will ask for the report. When it does not exist, the deal and your credibility suffer together. Only an independent licensed CPA firm can issue a SOC 2 report.

Honest wording that works

Here are answers you can adapt, depending on where you are.

| Where you are | What to say | |---|---| | Just starting | "We are preparing for SOC 2. We have completed a readiness assessment and are closing the gaps it found. We can share our security policies and answer your questionnaire today." | | Gaps mostly closed | "Our SOC 2 is in progress. Our controls are in place, and we are collecting evidence for a Type 1 examination by an independent CPA firm." | | Audit booked | "We have engaged an independent CPA firm for our SOC 2 Type 1. We expect the report around [month] and will share it under NDA when it is issued." | | Type 1 issued, Type 2 running | "We have a SOC 2 Type 1 report, available under NDA. Our Type 2 observation period is underway." |

Only give a date you believe. An estimate labeled as an estimate is fine. A promise you miss is not.

What to share while SOC 2 is in progress

A buyer's security team wants evidence, not adjectives. While your SOC 2 is in progress, you can usually share:

  • Your security policies, or a summary of them.
  • A completed security questionnaire, answered accurately.
  • A short security overview: how you handle access, encryption, logging, backups, vendors and incidents.
  • Your subprocessor list, with which vendors hold customer data.
  • Your plan: report type, target timeline and who will perform the examination, if engaged.
  • Your vendors' SOC 2 reports, where relevant, such as your cloud provider's.

Some audit firms will confirm in writing that an engagement is underway. If a buyer asks for that, ask your firm whether it provides one.

Keeping the deal moving

Buyers rarely say no because SOC 2 is in progress. They say no when the answer is vague. A few habits help.

  1. Answer the questionnaire fully. A blank or evasive answer invites more questions.
  2. Offer a call with whoever owns security. Ten minutes with an engineer often settles more than a document.
  3. Propose a contract clause. Some buyers accept a commitment to deliver the report by a date, or a right to review it when issued.
  4. Ask what they will accept now. Some will start a pilot with a Type 1, or with your policies and a questionnaire.
  5. Keep your promise. Send the report when it is issued, without being asked.

For more on this situation, see what to tell a buyer when SOC 2 is in progress and SOC 2 on a deal deadline.

Getting from in progress to issued

The faster your status changes from in progress to issued, the fewer of these conversations you have. The path for a small team:

  1. Readiness. Take a free readiness assessment and get your gap list.
  2. Remediation. Close the gaps, starting with MFA, access and written processes.
  3. Policies and evidence. Write policies from how you work and collect evidence mapped to the criteria.
  4. Type 1. An independent CPA firm examines your controls as of a date.
  5. Type 2. Controls keep running through an observation period, usually three to twelve months, then the firm examines that period.

cybersoftware is one plan for all of it: $199 a month, cancel any time, or $2,189 a year, which is one month free. On yearly, audits can be booked as soon as evidence is ready, which is often the better choice when a buyer is waiting. Audits come with access to our preferred pricing program: the best negotiated audit rates on the market, because we negotiate on your behalf. The full price list is on our pricing page. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Frequently asked questions

Can we say we are SOC 2 compliant before the report is issued?

No. Say your SOC 2 is in progress and describe where you are. Only a report from an independent CPA firm backs a SOC 2 claim.

Will a buyer sign with us while SOC 2 is in progress?

Many will, especially with complete questionnaire answers, shared policies and a credible date. Ask what they need to move forward.

What is a bridge letter, and do we need one now?

A bridge letter covers the gap between the end of an issued report's period and today. It applies after you have a report, not before.

Should we put SOC 2 in progress on our website?

Only if it is true and you keep it current. State the report type you are working toward, and never display a SOC 2 badge before the report exists.

Start with a free readiness assessment. It takes about fifteen minutes and needs no card.

← Back to all posts