SOC 2: cost, timeline and evidence

What it costs, how long it takes, what the auditor actually asks for, and what happens when something goes wrong.

SOC 2 for AI companies: what a model provider changesAn AI product sits for the same SOC 2 as any other software. The model provider moves which criteria get tested hard, and what proves them.8 min readISO 27001 to SOC 2: reuse, retest or write newYour ISMS already answers much of SOC 2. The certificate does not, and a few documents are new.9 min readHow much does a SOC 2 auditor charge?The auditor is the half of a SOC 2 bill that almost nobody prints. Here is how the fee is built, and how a small team keeps it down.7 min readSOC 2 bridge letter: an outline, plus the hard versionA signed note from you covering the months after your SOC 2 period ended. Easy when nothing changed, harder when something did.7 min readSOC 2 certification cost, and why there is no certificateYou are really buying an audit report, not a certificate. Here is what each piece of it costs and what a buyer expects to receive.6 min readIs an employer of record a subservice organization for SOC 2?The provider employs the contractor, but you grant the access. That split decides which controls you still own.8 min readHow much does SOC 2 cost in 2026?The usual SOC 2 bill is two contracts: a platform and a separate CPA firm. Here are both, sourced, next to the lower cost route where you do the work yourself.9 min readComplementary user entity controls: writing ones that hold upA CUEC is a condition on your own report. Written vaguely it transfers nothing, and written well it reads like a contract term.8 min readCustomer asking for SOC 2 report? Your next six weeksA contract is waiting on one line in a security review. Here is how to answer it on time and at a sensible cost.7 min readSOC 2 evidence checklist: 30 artifacts on a scheduleThirty artifacts, sorted by when you produce them. Your calendar is what slips, not the criteria.9 min readWhat happens if you fail a SOC 2 auditNobody fails a SOC 2 the way you fail an exam. You get an opinion, and sometimes exceptions, and both are fixable at a modest cost.8 min readSOC 2 gap analysis: pay to close gaps, not to find themA gap list is worth having and rarely worth buying. Here is what a good one holds and how to get it without a fee.7 min readHow many controls are in SOC 2, and what actually gets countedSOC 2 counts criteria, not controls. Here is the full tally, the source of the stale 64, and why the control number is yours to keep small.6 min readSOC 2 in progress: what to tell customers while you waitA buyer wants a report that does not exist yet. Say where you are, give a date, and offer what you already have.6 min readIs a low-priced SOC 2 audit legitimate?A low price is a reason to check the firm, not proof of a fake. Here is what makes any report legitimate, and the red flags worth acting on.8 min readSOC 2 log retention: working out how long to keep logsThe criteria never name a number of days. Your report calendar does, and several free tool defaults fall short of it.8 min readThe minimum SOC 2 Type 2 observation period, and when to go longerThree months is the accepted floor for a first Type 2. The real constraint is how often your controls run before anyone samples them.7 min readThe SOC 2 PBC list: 26 requests and how to answer eachHere is the evidence request list itself, not a definition of it. Each item shows what to send and what gets it returned.9 min readHow many policies SOC 2 needs, and the thirteen we writeNo standard sets a number, so the count is a choice you make. What gets tested is whether you do what the documents say.6 min readWhat a SOC 2 readiness assessment covers, and what it costsFirms sell this as a paid engagement. Try five real questions below, then see what the full version checks and returns.7 min readSOC 2 report shelf life, and what year two costsNothing on the report expires, but buyers stop trusting it after about a year. That clock sets your renewal costs.7 min readSwitching SOC 2 audit firms without paying for the same months twiceSwitch in the gap between reports and you lose almost nothing. Switch mid period and the new firm starts its own clock.7 min readHow long SOC 2 takes, and what each week costs youFor a small team, time is the larger bill. Here is where the weeks go and which of them you can get back.7 min readSOC 2 for a small team: what to do, what to skip, what to spendA team of two to ten has less to prove than it fears. Here is the short list, the skip list, and the bill.8 min readChecking a vendor SOC 2 report before you approve itSix checks, about twenty minutes, and no accountant needed. Start with the signature and the test results.7 min readWho is allowed to sign a SOC 2 report, and which work you can do yourselfOnly a licensed CPA firm can sign the opinion. Everything before that signature is preparation, and preparation is where you can save.7 min read

Get audit-ready without a compliance team

The readiness assessment is free, and every price on this site is the price. No quote gate.

Start free