SOC 2, written down

Everything we have published, in one place. 46 pages on what SOC 2 costs, how long it takes, what the auditor actually asks for, and what to do when the answer is inconvenient. None of it is gated and none of it wants your email first.

Guides

The long pieces. Start here if SOC 2 is new and you want the shape of the whole thing before the detail.

SOC 2

What it costs, how long it takes, who signs it, and what happens when something goes wrong. One question per page, answered in the first two sentences.

SOC 2 for AI companies: what a model provider changes

An AI product sits for the same SOC 2 as any other software. The model provider moves which criteria get tested hard, and what proves them.

8 min

ISO 27001 to SOC 2: reuse, retest or write new

Your ISMS already answers much of SOC 2. The certificate does not, and a few documents are new.

9 min

How much does a SOC 2 auditor charge?

The auditor is the half of a SOC 2 bill that almost nobody prints. Here is how the fee is built, and how a small team keeps it down.

7 min

SOC 2 bridge letter: an outline, plus the hard version

A signed note from you covering the months after your SOC 2 period ended. Easy when nothing changed, harder when something did.

7 min

SOC 2 certification cost, and why there is no certificate

You are really buying an audit report, not a certificate. Here is what each piece of it costs and what a buyer expects to receive.

6 min

Is an employer of record a subservice organization for SOC 2?

The provider employs the contractor, but you grant the access. That split decides which controls you still own.

8 min

How much does SOC 2 cost in 2026?

The usual SOC 2 bill is two contracts: a platform and a separate CPA firm. Here are both, sourced, next to the lower cost route where you do the work yourself.

9 min

Complementary user entity controls: writing ones that hold up

A CUEC is a condition on your own report. Written vaguely it transfers nothing, and written well it reads like a contract term.

8 min

Customer asking for SOC 2 report? Your next six weeks

A contract is waiting on one line in a security review. Here is how to answer it on time and at a sensible cost.

7 min

SOC 2 evidence checklist: 30 artifacts on a schedule

Thirty artifacts, sorted by when you produce them. Your calendar is what slips, not the criteria.

9 min

What happens if you fail a SOC 2 audit

Nobody fails a SOC 2 the way you fail an exam. You get an opinion, and sometimes exceptions, and both are fixable at a modest cost.

8 min

SOC 2 gap analysis: pay to close gaps, not to find them

A gap list is worth having and rarely worth buying. Here is what a good one holds and how to get it without a fee.

7 min

How many controls are in SOC 2, and what actually gets counted

SOC 2 counts criteria, not controls. Here is the full tally, the source of the stale 64, and why the control number is yours to keep small.

6 min

SOC 2 in progress: what to tell customers while you wait

A buyer wants a report that does not exist yet. Say where you are, give a date, and offer what you already have.

6 min

Is a low-priced SOC 2 audit legitimate?

A low price is a reason to check the firm, not proof of a fake. Here is what makes any report legitimate, and the red flags worth acting on.

8 min

SOC 2 log retention: working out how long to keep logs

The criteria never name a number of days. Your report calendar does, and several free tool defaults fall short of it.

8 min

The minimum SOC 2 Type 2 observation period, and when to go longer

Three months is the accepted floor for a first Type 2. The real constraint is how often your controls run before anyone samples them.

7 min

The SOC 2 PBC list: 26 requests and how to answer each

Here is the evidence request list itself, not a definition of it. Each item shows what to send and what gets it returned.

9 min

How many policies SOC 2 needs, and the thirteen we write

No standard sets a number, so the count is a choice you make. What gets tested is whether you do what the documents say.

6 min

What a SOC 2 readiness assessment covers, and what it costs

Firms sell this as a paid engagement. Try five real questions below, then see what the full version checks and returns.

7 min

SOC 2 report shelf life, and what year two costs

Nothing on the report expires, but buyers stop trusting it after about a year. That clock sets your renewal costs.

7 min

Switching SOC 2 audit firms without paying for the same months twice

Switch in the gap between reports and you lose almost nothing. Switch mid period and the new firm starts its own clock.

7 min

How long SOC 2 takes, and what each week costs you

For a small team, time is the larger bill. Here is where the weeks go and which of them you can get back.

7 min

SOC 2 for a small team: what to do, what to skip, what to spend

A team of two to ten has less to prove than it fears. Here is the short list, the skip list, and the bill.

8 min

Checking a vendor SOC 2 report before you approve it

Six checks, about twenty minutes, and no accountant needed. Start with the signature and the test results.

7 min

Who is allowed to sign a SOC 2 report, and which work you can do yourself

Only a licensed CPA firm can sign the opinion. Everything before that signature is preparation, and preparation is where you can save.

7 min

Templates

The artifacts an auditor asks for, printed in full on the page. No email wall and no file to download before you can read one.

Tools

Answer a few questions, get a real number. Both show their arithmetic instead of asking you to book a call.

Comparisons

How we compare, and how to leave. Every figure about another company is quoted from that company and stamped with the date we read it.

Ready to put it into practice?

The assessment is free. The software is $199 a month, and audits go through our preferred pricing program. No consultants and no platform-locked evidence.

Start free