Customer asking for SOC 2 report? Your next six weeks
A contract is waiting on one line in a security review. Here is how to answer it on time and at a sensible cost.
The email looks routine. Legal signed off, the order form is ready, and then one line from security: please send your SOC 2 report. You do not have one. On a six week deadline the answer is a Type 1, a report that can exist by then, and it clears a lot of procurement holds by itself.
Price the deal before you price the report. For a small company, one enterprise contract can be worth far more than a first SOC 2. The real risk is spending weeks on quotes and calls while the buyer’s patience runs out.
Two questions come first. Which report does this buyer actually need? And what can you physically have in hand on their date? Average timelines do not help you here. You need a plan against one specific day.
Find out which report they mean
Procurement often writes “SOC 2” with no type attached. The wording is a clue, and getting it right can save a three month wait you never needed. Here are the three shapes the request takes.
- “Please send your SOC 2.”
- No type named. A Type 1 usually clears it. The reviewer needs an independent CPA firm’s report with your name on it to tick a box.
- “Your latest SOC 2 Type II.”
- They know the difference and want proof the controls operated over time. Expect this from large security teams, financial counterparties and anyone handling regulated data.
- “Your report, or your plan and timeline.”
- The soft version. A Type 1 in progress plus a dated commitment to a Type 2 tends to settle it within a week.
Unsure? Ask. “Would a Type 1 satisfy your review for this contract?” is an ordinary question, and reviewers answer it. Type 1 versus Type 2 explains what each report actually tests.
What unblocking the deal costs
Speed of purchase is part of the cost. On a deadline you need a price today, and several vendors in this market do not publish one. These were read on the date shown.
- Vanta lists four plans on its pricing page and no dollar figure. The call to action is to request personalized pricing. Source, checked 2026-07-30.
- Secureframe lists three plans on its pricing page and no dollar figure. Each one links to a quote request. Source, checked 2026-07-30.
- Drata has no public pricing page. The URL serves the homepage, where the calls to action are to contact sales or book a demo. Source, checked 2026-07-30.
- Suralink publishes no price, stating that every company and team has different needs and inviting prospects to reach out. Source, checked 2026-07-30.
A demo, a discovery call, a quote and a contract review can eat a week of your six before any work begins. Our software prices are published, the audit price shows in your account before you book, and checkout is self-serve for that reason.
On a deadline, the yearly plan is the one to buy. It is $2,189 a year, pay for eleven months, get twelve, and it matters for timing: Audits unlock after four paid months on monthly, or right away on yearly. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. Monthly is $199 a month, cancel any time, which suits a team with no buyer waiting. See every plan side by side, or the cost breakdown for how each figure is built.
A six week plan against the contract date
This plan assumes one person can give the work about ten hours a week, and a common stack: AWS or Google Cloud, GitHub, Google Workspace. You do not need a consultant for any of it. Each block below ends with something you can tell the buyer.
- Week one: assess and scope. Take the readiness assessment, connect your cloud and source control, and get the gap list plus thirteen policies drafted from your answers. Keep scope to Security unless the contract names another category.2 You can now tell the buyer you have started.
- Week two: fix the settings. Multi-factor authentication, logging and retention, branch protection, an access review, incident contacts. First gaps are often settings rather than projects. By Friday you can name the date your controls will be examined as of.
- Weeks three and four: assemble the evidence. Attach proof to each control and map it to the criteria. Screenshots, exported settings, tickets, signed policy acknowledgments. The package then goes to the auditor.
- Weeks five and six: the examination. The CPA firm reviews the package, asks questions and issues the report. With the evidence complete, this typically takes one to two weeks. Send the report the day you receive it.
The software side gets you audit-ready starting at about a week. The rest of the six weeks is your own remediation and the examination. Two things stretch it: a control that was never running, and a scope wider than the contract needs. The same phases without a deadline are in how long SOC 2 takes.
What six weeks cannot buy
A Type 2. It rests on a 3-month observation window at minimum, because the auditor samples from a period that has to have happened.3 If the contract truly needs Type 2, say so in week one. Then negotiate the date, or sign with a clause committing to the report.
The note to send while you work
Never say a report exists before it does. That one stretch of the truth comes back two weeks later, when the reviewer asks for the PDF. A reviewer who has done this before can tell a company mid-examination from one that is improvising. Send this from the account owner:
We have started our SOC 2 Type 1. Our controls will be examined as of [date] by an independent partner auditor, a licensed U.S. CPA firm, and we will send you the report on the day it is issued. We will share the firm’s expected issue date once they confirm it. Until then we can send our control matrix mapped to the Trust Services Criteria, our security policies, and a walkthrough of how we collect evidence. We can also confirm our scope and examination date in writing today.
It gives a date, names the standard, and hands the reviewer something real to evaluate this week. Security reviews often have a conditional path for vendors mid-examination. What gets you onto it is evidence, not promises. If the wording is the harder part, what to say while SOC 2 is in progress goes further.
The questionnaire in the same thread
A security questionnaire tends to arrive alongside the request. Hundreds of rows, a portal, a due date. Answer it in parallel. Your new policies already hold most of the answers, so doing both at once costs less than doing them in turn. How to answer a security questionnaire has answer text for before and after the report exists.
Do not guess. A wrong yes becomes a problem later. An honest “not yet, here is the interim control and the date it lands” rarely loses a deal.
Promises to avoid
There is no SOC 2 certificate. There is a report with an opinion for a date or a period.1 People who review these for a living notice the wrong word at once, and the correction lands at the worst moment.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Two more. Never send a draft report, since a draft carries no opinion and the auditor has not finished with it. And never give an issue date the CPA firm has not agreed to. A missed date you made up hurts more than the original gap.
After the contract is signed
The Type 1 gets this deal done. The next large buyer, or this one at renewal, will ask for a Type 2, and its observation window can start the day after your Type 1 date. Keep collecting evidence and the second report is routine rather than a scramble.
A yearly plan covers that 3-month observation window and more. Monthly is $199 a month, cancel any time, and yearly is $2,189 a year, pay for eleven months, get twelve. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, including the Type 2. Plan it now, while security has your attention.
If the buyer’s email just landed, start with the number that decides your date. Take the free assessment. It takes about 15 minutes and tells you how many gaps stand between you and the examination.
Questions
The contract closes in six weeks. Can we have a SOC 2 report by then?
What should we send the buyer before the report exists?
The buyer asked for Type 2. Will a Type 1 do?
What does it cost to unblock the deal?
Can we share a draft report to keep the deal alive?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.