SOC 2, written down
Everything we have published, in one place. 46 pages on what SOC 2 costs, how long it takes, what the auditor actually asks for, and what to do when the answer is inconvenient. None of it is gated and none of it wants your email first.
Guides
The long pieces. Start here if SOC 2 is new and you want the shape of the whole thing before the detail.
SOC 2 Type 1 vs Type 2: which to start with, and when
A prospect just asked for your SOC 2. Type 1 in weeks, Type 2 in months, and the order matters more than founders realize.
cybersoftware vs Vanta, Drata, and Delve: an honest comparison
We are not a competitor to the big GRC platforms. We are the on-ramp before you need one. Here is the math.
Five SOC 2 control failures we see in almost every startup pre-audit
Patterns from real gap analyses. Every one of these is fixable in days, not weeks. None of them require new tooling.
What SOC 2 Type 1 actually requires for a sub-20-person SaaS
Demystifying the framework: the scope, the policies, the artifacts, and what a CPA actually tests.
AICPA Trust Service Criteria, explained: a founder's reading guide
CC1 through CC9, in plain language, with the engineering practice that satisfies each. Save this and reference it during your audit prep.
SOC 2
What it costs, how long it takes, who signs it, and what happens when something goes wrong. One question per page, answered in the first two sentences.
SOC 2 for AI companies: what a model provider changes
An AI product sits for the same SOC 2 as any other software. The model provider moves which criteria get tested hard, and what proves them.
ISO 27001 to SOC 2: reuse, retest or write new
Your ISMS already answers much of SOC 2. The certificate does not, and a few documents are new.
How much does a SOC 2 auditor charge?
The auditor is the half of a SOC 2 bill that almost nobody prints. Here is how the fee is built, and how a small team keeps it down.
SOC 2 bridge letter: an outline, plus the hard version
A signed note from you covering the months after your SOC 2 period ended. Easy when nothing changed, harder when something did.
SOC 2 certification cost, and why there is no certificate
You are really buying an audit report, not a certificate. Here is what each piece of it costs and what a buyer expects to receive.
Is an employer of record a subservice organization for SOC 2?
The provider employs the contractor, but you grant the access. That split decides which controls you still own.
How much does SOC 2 cost in 2026?
The usual SOC 2 bill is two contracts: a platform and a separate CPA firm. Here are both, sourced, next to the lower cost route where you do the work yourself.
Complementary user entity controls: writing ones that hold up
A CUEC is a condition on your own report. Written vaguely it transfers nothing, and written well it reads like a contract term.
Customer asking for SOC 2 report? Your next six weeks
A contract is waiting on one line in a security review. Here is how to answer it on time and at a sensible cost.
SOC 2 evidence checklist: 30 artifacts on a schedule
Thirty artifacts, sorted by when you produce them. Your calendar is what slips, not the criteria.
What happens if you fail a SOC 2 audit
Nobody fails a SOC 2 the way you fail an exam. You get an opinion, and sometimes exceptions, and both are fixable at a modest cost.
SOC 2 gap analysis: pay to close gaps, not to find them
A gap list is worth having and rarely worth buying. Here is what a good one holds and how to get it without a fee.
How many controls are in SOC 2, and what actually gets counted
SOC 2 counts criteria, not controls. Here is the full tally, the source of the stale 64, and why the control number is yours to keep small.
SOC 2 in progress: what to tell customers while you wait
A buyer wants a report that does not exist yet. Say where you are, give a date, and offer what you already have.
Is a low-priced SOC 2 audit legitimate?
A low price is a reason to check the firm, not proof of a fake. Here is what makes any report legitimate, and the red flags worth acting on.
SOC 2 log retention: working out how long to keep logs
The criteria never name a number of days. Your report calendar does, and several free tool defaults fall short of it.
The minimum SOC 2 Type 2 observation period, and when to go longer
Three months is the accepted floor for a first Type 2. The real constraint is how often your controls run before anyone samples them.
The SOC 2 PBC list: 26 requests and how to answer each
Here is the evidence request list itself, not a definition of it. Each item shows what to send and what gets it returned.
How many policies SOC 2 needs, and the thirteen we write
No standard sets a number, so the count is a choice you make. What gets tested is whether you do what the documents say.
What a SOC 2 readiness assessment covers, and what it costs
Firms sell this as a paid engagement. Try five real questions below, then see what the full version checks and returns.
SOC 2 report shelf life, and what year two costs
Nothing on the report expires, but buyers stop trusting it after about a year. That clock sets your renewal costs.
Switching SOC 2 audit firms without paying for the same months twice
Switch in the gap between reports and you lose almost nothing. Switch mid period and the new firm starts its own clock.
How long SOC 2 takes, and what each week costs you
For a small team, time is the larger bill. Here is where the weeks go and which of them you can get back.
SOC 2 for a small team: what to do, what to skip, what to spend
A team of two to ten has less to prove than it fears. Here is the short list, the skip list, and the bill.
Checking a vendor SOC 2 report before you approve it
Six checks, about twenty minutes, and no accountant needed. Start with the signature and the test results.
Who is allowed to sign a SOC 2 report, and which work you can do yourself
Only a licensed CPA firm can sign the opinion. Everything before that signature is preparation, and preparation is where you can save.
Templates
The artifacts an auditor asks for, printed in full on the page. No email wall and no file to download before you can read one.
A free user access review template you can fill in today
One sheet per system, one row per account, and a header that proves nothing was left out. Copy it free and run your first review this week.
Incident response plan template (SOC 2), free and sized for five people
Two or three pages you can follow at 2am beat twenty you cannot. Here is the short version, ready to copy.
SOC 2 management assertion: two letters you can copy
Section 2 is a one page letter, and a person at your company signs it. Here are both versions, free to copy.
A free employee offboarding checklist template, with owners and proof
Eighteen steps, each with an owner and the proof it leaves. Free to copy, no email required.
A free SOC 2 risk register template with real rows
A blank grid teaches nothing, so this one comes with six rows already written. Copy the columns, replace the rows, keep it current.
How to answer a security questionnaire before you have a SOC 2
Twelve questions come back on every form. Here are honest answers for today and for after your report, free to copy.
A free SOC 2 system description template, part by part
You write Section 3, not the auditor. Here is every part, a worked boundary, and the wording that comes back.
Vendor security assessment questionnaire template, free to send
Sort your vendors first, then send questions only to the few that can reach your data. All 24 are free to copy.
Tools
Answer a few questions, get a real number. Both show their arithmetic instead of asking you to book a call.
Comparisons
How we compare, and how to leave. Every figure about another company is quoted from that company and stamped with the date we read it.
Drata alternative: what a small team actually pays
A SOC 2 quote hides two separate fees. Split them and the choice gets easier.
How to leave a compliance platform before it renews
The renewal date sets your deadline. Export first, give notice second, and keep the evidence trail unbroken.
A Secureframe alternative for founders with no security hire
If nobody at your company does security full time, the tool has to do the explaining.
A Vanta alternative any team under fifty can afford
Vanta is built and priced for companies with a security team. This page is for those without one.
Can I get SOC 2 without a compliance platform?
You can. The real question is which of three routes fits your time and your money.
Ready to put it into practice?
The assessment is free. The software is $199 a month, and audits go through our preferred pricing program. No consultants and no platform-locked evidence.
Start free