SOC 2 in progress: what to tell customers while you wait
A buyer wants a report that does not exist yet. Say where you are, give a date, and offer what you already have.
With a SOC 2 in progress, you can say exactly that, but you cannot say you are compliant, certified or covered, because those words describe a report you do not have yet. The fix is simple: name your stage, give a date, label the date as an expectation, and share what already exists.
The pressure usually shows up mid deal, when a prospect's security team asks for the report and the work has started, so it feels fair to round up. Do not. Reviewers want to know two things: does a report exist, and if not, when will it. Precise answers to those two questions keep deals alive, while warm but vague ones come back to bite months later.
Match your words to your stage
In progress can mean four quite different things, and a reviewer knows that, so a fuzzy claim earns a follow up question you were hoping to avoid. Find your row and use its wording.
| Where you are | What you can say | What to hold back |
|---|---|---|
| Readiness work only | You are closing gaps and collecting evidence against the criteria | The word audit, and any report date. No firm is engaged to back one |
| Firm engaged, not started | A licensed CPA firm is engaged, the scope is agreed, and the planned start | Any claim that a date or period is already being examined |
| Fieldwork underway | The report type, the date or period being examined, and the expected issuance | Any hint about the outcome |
| Report issued | Send it, and state the period it covers | Nothing. You have a document now |
Fieldwork is the strongest spot short of a finished report, so state it precisely. Name the report type and the date or period under examination.1 That one detail answers most follow ups before they are asked.
A status note you can copy
Keep it short and factual. A reviewer will paste it straight into their vendor file, so write it to survive that. Here is a version for the fieldwork stage. Swap in your own dates.
Our SOC 2 Type 1 examination is underway with an independent licensed U.S. CPA firm. It covers the Security criteria for our production platform, as of a control date of 14 October 2026. We expect the report in November. That is an expectation and not a promise, since the firm decides when to issue. Until then we can share our control matrix, our written policies, and a call with our engineering lead. We will send the report the day it arrives.
The note answers five things in order: what is happening, who is doing it, what it covers, when it ends, and what the buyer can see today. Keep the line about the firm deciding the issue date, because it is the sentence that protects you if the schedule moves.
Phrases to swap before you hit send
Each line on the left describes a document that does not exist yet. Each line on the right is true today and still reads well to a reviewer.
| Avoid | Use |
|---|---|
| We are SOC 2 compliant | We are in a SOC 2 Type 1 examination with a control date of 14 October |
| We are SOC 2 certified | SOC 2 results in a report, not a certificate. Ours is expected in November |
| The audit is done, they are just writing it up | Fieldwork has finished and the report has not been issued |
| You will have it by the 30th | We expect it in November, and the firm sets the issue date |
| The auditors signed off | Testing is finished. Nothing is signed until issuance, and we will send it that day |
Certified is the word that gives people away. SOC 2 is an attestation, and what you receive is a report carrying an opinion.2 A reviewer who has read a few reports spots the word at once. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Readiness work is not a report
Readiness work matters, but it does not prove anything to a third party. It is you measuring your own controls against the Trust Services Criteria.3 It shows what exists, what is only written down, and what is missing. No independent firm has tested it, so it says nothing about whether a control actually ran.
Share it as a gap list and a plan if the buyer wants detail, but never present it as a stand in for a report. And if you have not measured yet, do that first, because without a measurement any date you give a buyer is a guess.
What that measurement costs
Outside firms charge real money for a readiness assessment. Two published figures:
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
You can do this step yourself for nothing. Our free readiness assessment scores your answers against the criteria an examination uses and returns the gap list. It takes about 15 minutes. That list is what turns a vague in progress line into one you can defend.
How soon a real report can exist
A Type 1 is an opinion on whether your controls were designed properly on one date, so no operating period has to pass first. The limit is how ready you are and when the firm can schedule you. Once your gaps are known, audit-ready starting at about a week of focused work is a reasonable planning figure.
A Type 2 is a different animal. It covers a window during which your controls actually ran, and that window has a minimum length. Urgency does not shorten it. That is the honest answer when a buyer wants a Type 2 inside one quarter. The SOC 2 timeline breaks down what each date depends on, and a customer asking for a report you do not have covers the contract side of that talk.
On cost: the software is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book, so a real report reaches the buyer without a separate platform contract.
Answer the questionnaire in the meantime
The report request often arrives with a spreadsheet attached. Fill it in. A completed questionnaire is an actual artifact, signed by you, and for a mid-market buyer it can carry the review on its own while the examination runs. It costs nothing but an afternoon.
Answer as if you were under examination. Where a control exists, say so and name the evidence you would produce, and where it does not, say that too, with the date you expect it. Three honest gaps with dates hold up in diligence. A sheet with zero gaps invites someone to go looking, and they will find the ones you left out.
No draft reports, sample reports or unsigned opinions, even watermarked. One circulated draft makes everything else you send look provisional, and the firm named on it has a fair objection to it existing.
The same question returns later
Issuance does not retire this problem. It comes back each time a report period ends and the next examination has not closed. The standard answer for that gap is a bridge letter, and it follows the same rule as everything above. Say what you know, date it, and assert nothing that was not examined.
Two low effort habits help. Keep the status note as a living document instead of rewriting it under pressure each time, and log every date you give a buyer so you can tell them yourself if one moves. Buyers forgive a slipped date they hear about early.
Your next step
If you cannot yet say which stage you are in, start with the free readiness assessment. You get a readiness assessment, score, gap list and one AI sample policy, which is enough to put a defensible date in your status note. When the buyer needs an actual report, compare the monthly and yearly plans on the pricing page.
Questions
Is it fine to say our SOC 2 is in progress?
What belongs in an email and what belongs on a call?
Is a readiness assessment the same as a SOC 2?
How soon can a buyer have a real report?
What if the buyer refuses to accept work in progress?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.