SOC 2 in progress: what to tell customers while you wait

A buyer wants a report that does not exist yet. Say where you are, give a date, and offer what you already have.

With a SOC 2 in progress, you can say exactly that, but you cannot say you are compliant, certified or covered, because those words describe a report you do not have yet. The fix is simple: name your stage, give a date, label the date as an expectation, and share what already exists.

The pressure usually shows up mid deal, when a prospect's security team asks for the report and the work has started, so it feels fair to round up. Do not. Reviewers want to know two things: does a report exist, and if not, when will it. Precise answers to those two questions keep deals alive, while warm but vague ones come back to bite months later.

Match your words to your stage

In progress can mean four quite different things, and a reviewer knows that, so a fuzzy claim earns a follow up question you were hoping to avoid. Find your row and use its wording.

Where you areWhat you can sayWhat to hold back
Readiness work onlyYou are closing gaps and collecting evidence against the criteriaThe word audit, and any report date. No firm is engaged to back one
Firm engaged, not startedA licensed CPA firm is engaged, the scope is agreed, and the planned startAny claim that a date or period is already being examined
Fieldwork underwayThe report type, the date or period being examined, and the expected issuanceAny hint about the outcome
Report issuedSend it, and state the period it coversNothing. You have a document now

Fieldwork is the strongest spot short of a finished report, so state it precisely. Name the report type and the date or period under examination.1 That one detail answers most follow ups before they are asked.

A status note you can copy

Keep it short and factual. A reviewer will paste it straight into their vendor file, so write it to survive that. Here is a version for the fieldwork stage. Swap in your own dates.

Copyable status note

Our SOC 2 Type 1 examination is underway with an independent licensed U.S. CPA firm. It covers the Security criteria for our production platform, as of a control date of 14 October 2026. We expect the report in November. That is an expectation and not a promise, since the firm decides when to issue. Until then we can share our control matrix, our written policies, and a call with our engineering lead. We will send the report the day it arrives.

The note answers five things in order: what is happening, who is doing it, what it covers, when it ends, and what the buyer can see today. Keep the line about the firm deciding the issue date, because it is the sentence that protects you if the schedule moves.

Phrases to swap before you hit send

Each line on the left describes a document that does not exist yet. Each line on the right is true today and still reads well to a reviewer.

AvoidUse
We are SOC 2 compliantWe are in a SOC 2 Type 1 examination with a control date of 14 October
We are SOC 2 certifiedSOC 2 results in a report, not a certificate. Ours is expected in November
The audit is done, they are just writing it upFieldwork has finished and the report has not been issued
You will have it by the 30thWe expect it in November, and the firm sets the issue date
The auditors signed offTesting is finished. Nothing is signed until issuance, and we will send it that day

Certified is the word that gives people away. SOC 2 is an attestation, and what you receive is a report carrying an opinion.2 A reviewer who has read a few reports spots the word at once. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Readiness work is not a report

Readiness work matters, but it does not prove anything to a third party. It is you measuring your own controls against the Trust Services Criteria.3 It shows what exists, what is only written down, and what is missing. No independent firm has tested it, so it says nothing about whether a control actually ran.

Share it as a gap list and a plan if the buyer wants detail, but never present it as a stand in for a report. And if you have not measured yet, do that first, because without a measurement any date you give a buyer is a guess.

What that measurement costs

Outside firms charge real money for a readiness assessment. Two published figures:

  • Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
  • IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.

You can do this step yourself for nothing. Our free readiness assessment scores your answers against the criteria an examination uses and returns the gap list. It takes about 15 minutes. That list is what turns a vague in progress line into one you can defend.

A date you cannot back up does more harm than no date.

How soon a real report can exist

A Type 1 is an opinion on whether your controls were designed properly on one date, so no operating period has to pass first. The limit is how ready you are and when the firm can schedule you. Once your gaps are known, audit-ready starting at about a week of focused work is a reasonable planning figure.

A Type 2 is a different animal. It covers a window during which your controls actually ran, and that window has a minimum length. Urgency does not shorten it. That is the honest answer when a buyer wants a Type 2 inside one quarter. The SOC 2 timeline breaks down what each date depends on, and a customer asking for a report you do not have covers the contract side of that talk.

On cost: the software is $199 a month, cancel any time, or $2,189 a year, pay for eleven months, get twelve. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book, so a real report reaches the buyer without a separate platform contract.

Answer the questionnaire in the meantime

The report request often arrives with a spreadsheet attached. Fill it in. A completed questionnaire is an actual artifact, signed by you, and for a mid-market buyer it can carry the review on its own while the examination runs. It costs nothing but an afternoon.

Answer as if you were under examination. Where a control exists, say so and name the evidence you would produce, and where it does not, say that too, with the date you expect it. Three honest gaps with dates hold up in diligence. A sheet with zero gaps invites someone to go looking, and they will find the ones you left out.

Never send a draft

No draft reports, sample reports or unsigned opinions, even watermarked. One circulated draft makes everything else you send look provisional, and the firm named on it has a fair objection to it existing.

The same question returns later

Issuance does not retire this problem. It comes back each time a report period ends and the next examination has not closed. The standard answer for that gap is a bridge letter, and it follows the same rule as everything above. Say what you know, date it, and assert nothing that was not examined.

Two low effort habits help. Keep the status note as a living document instead of rewriting it under pressure each time, and log every date you give a buyer so you can tell them yourself if one moves. Buyers forgive a slipped date they hear about early.

Your next step

If you cannot yet say which stage you are in, start with the free readiness assessment. You get a readiness assessment, score, gap list and one AI sample policy, which is enough to put a defensible date in your status note. When the buyer needs an actual report, compare the monthly and yearly plans on the pricing page.

Questions

Is it fine to say our SOC 2 is in progress?
Yes, if something has genuinely started. Say which stage you are in: readiness work, an examination engaged with a CPA firm, or fieldwork underway. Add the date you expect a report and call it an expectation. Do not call the company compliant, certified or covered until a report is issued.
What belongs in an email and what belongs on a call?
Put the stage, the scope and the expected date in writing, since the reviewer needs something to file. Keep guesses about the outcome for the call. A written line will be reread months later by someone who was not there, and they will take it literally.
Is a readiness assessment the same as a SOC 2?
No. It is your own measurement against the criteria, with no independent CPA opinion behind it. It is useful to share as a gap list and a plan. It does not show that any control operated.
How soon can a buyer have a real report?
A Type 1 looks at design on one date, so it has no waiting period built in and can be issued once the examination is done. A Type 2 covers a window of operation, which sets a floor on how fast it can arrive.
What if the buyer refuses to accept work in progress?
Ask what would close the review instead. It is often a Type 1, a written Type 2 date, a completed questionnaire, or a contract clause. Knowing which one they want saves weeks of status emails.

Sources

  1. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.