SOC 2 for a small team: what to do, what to skip, what to spend
A team of two to ten has less to prove than it fears. Here is the short list, the skip list, and the bill.
SOC 2 for a small team is a smaller job than the sales pages suggest. A company of two to ten people has a handful of accounts, one production system and a short vendor list. The standard is the same one a large company meets. The bill does not have to be.
Plan for three things. A short list of controls you actually run, the records that prove you ran them, and one examination by an independent CPA firm. Most of the rest is optional at your size, and optional is where the money leaks out.
Headcount does not change the criteria.1 Nobody grades a five person company on a curve. What headcount changes is the size of the surface you have to cover, and that is where a small team saves. Fewer systems means fewer screenshots to collect, and fewer people means an access review that takes minutes instead of days. The trick is to spend on the parts a buyer reads and skip the parts built for companies fifty times your size.
The short list a team of two to ten needs
Scope first. Security is the category every SOC 2 report contains,2 and for a first report it is usually the only one worth paying for. Add Availability or Confidentiality only when a contract names it. The scoping tool settles that in four questions. Inside that scope, a small team needs these:
- Multi-factor authentication everywhere. Cloud console, source control, email, the password manager. It is a setting you turn on once, and it costs nothing.
- Written access reviews. A dated list of every account on each system, with a keep, change or remove decision beside each one.
- Change control a machine enforces. Branch protection, required checks, and a named reviewer for sensitive code.
- Offboarding records. The date access ended for each person who left. The offboarding checklist gives you the fields.
- An incident plan and one exercise. A one page plan, a thirty minute tabletop inside the period, and a written note of what you would change.
- A vendor list with a review date. Your cloud provider and the handful of tools that touch customer data.
- Policies that match your week. Written for the company you are, not the one a template imagines.
That is the core. None of it needs a purchase beyond the tools you already pay for, because most of it is configuration plus a steady habit of writing things down with a date on it.
What you can leave out
This is where a small team keeps SOC 2 affordable. Every item below costs money or weeks, and none of them is required for a first report at your size.
- Categories nobody asked for
- Each extra Trust Services Category widens the examination and the evidence. If no contract names Processing Integrity or Privacy, leave them out.
- A Type 2 as your first report
- A Type 2 needs a 3-month observation window before anyone can examine it. A Type 1 comes first anyway, and it clears a lot of security reviews on its own.
- A paid readiness engagement
- Firms bill for the gap list. You can produce the same list yourself, free, and spend the money on closing gaps instead of finding them.
- A security hire or a consultant
- One owner with a backup satisfies the assignment of responsibility. A consultant can speed things up. It is a choice, not a requirement.
- Process borrowed from a bigger company
- A change advisory board, a paging rotation, two party approval on every commit. Write them into a policy and the examiner will test you against them.
The last one deserves a second look. An examiner tests you against your own stated procedure.3 A borrowed policy turns an ordinary week into a list of exceptions. Delete the clauses you never perform and the same week passes.
Controls that assume more people than you have
Four controls are written with a bigger company in mind. Each has a substitute that an examiner can test, and each substitute costs little. None of them lowers the standard. They meet it with the people you actually have, and they leave a record an examiner can sample from, which is the part that matters when the request list arrives.
Separation of duties with one engineer
You cannot review your own deploy. You can make the tooling refuse direct pushes, send each deploy to a channel a cofounder reads, and have that cofounder sign off on the production change log every month. Then name the conflict in the policy. A documented limit with a mitigation is a control. A hidden one is a finding.
Access reviews over six accounts
Twenty minutes a quarter, and the review itself is easy. The risk is that it happens in your head and leaves no record. Write the date, the reviewer, each account, its role and the decision. Service accounts belong on the list too.
Contractors in the screening and training controls
Anyone with access falls under both. For a contractor, that means a check you ran, a record from their agency, or a written risk acceptance naming the person. Security obligations go in the contractor agreement, since a handbook does not bind them. For people abroad, the employer of record page covers what changes.
Incident response without a pager rotation
The criteria ask for detection, triage, a record and closure. They do not ask for a rotation. An alert that reaches a named person and a named backup does the job. So does a log of every incident, small ones included, because a quiet period with no records looks the same as a period where nobody wrote anything down.
What the other routes cost
Two paths get quoted to small companies. One is a consultant who runs the preparation. The other is a large compliance platform. Both publish or have published figures, and these were read on the date shown.
- Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.
- Vendr reports a median annual contract value of $20,000 for Vanta, based on purchases completed through its marketplace. Source, checked 2026-07-30.
- Vendr reports a median annual contract value of $24,601 for Drata, based on purchases completed through its marketplace. Source, checked 2026-07-30.
- Vendr reports a median annual contract value of $20,000 for Secureframe, based on purchases completed through its marketplace. Source, checked 2026-07-30.
The platform figures cover the subscription only, and the audit arrives as a separate bill. For a team of five, either route can cost more than a year of someone’s salary. That is the gap we built for.
What doing it yourself costs
Two costs matter here, money and hours, and the money side is the short one. The hours side is where a small team actually pays, so plan it like a real line item.
The readiness assessment is free and takes about 15 minutes. The software is the same full platform at every size. If a buyer needs a report, audits go through our preferred pricing program, and we negotiate the fee on your behalf, Type 1 and Type 2 alike. The software does most of the work, so the auditor only has to verify evidence that arrives prepared. We negotiate the fee on your behalf, and the price is shown in your account before you book. Audits unlock after four paid months on monthly, or right away on yearly.
Now the hours. One owner, a few afternoons a week, and an engineer for a day or two of configuration. With that, the software gets you audit-ready starting at about a week. Without a named owner, the same work drifts for months. That drift is the most expensive thing on this page. It costs nothing on an invoice and a lot in stalled deals.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Your examiner is an independent partner auditor, a licensed U.S. CPA firm. You can look up any U.S. firm on its state board register4 before you sign. The examination is the same for a five person company as for anyone else.
A first quarter that spends little
Here is a sequence that spends as little as possible before a buyer is actually waiting. Each step only happens when the one before it justifies it.
- Take the assessment. It is free, and you get a score and a gap list that tell you how far away you are before you spend anything.
- Close the configuration gaps. Multi-factor authentication, branch protection, log retention. These cost an afternoon, not a subscription.
- Start the software when you start writing. Monthly if you want to test the fit, yearly if you already know. Policies, evidence and the binder live there.
- Book the audit when a buyer asks. It goes through our preferred pricing program, and you see the price in your account before you book, so a deal deadline does not start a second procurement.
For the wider picture, SOC 2 for startups covers the decisions a young company makes in order, and the small SaaS guide walks the Type 1 requirements one by one. Every plan is on the pricing page.
Start with the free number
You do not need a spending meeting to find out where you stand. The free readiness assessment grades your answers against the criteria and hands back the gaps, counted. Then you decide what to spend, knowing what it buys. Small teams win this by being honest about what they do. That part is free too.
Questions
Is SOC 2 realistic for a company of five people?
What can a small team leave out of a first SOC 2?
How do you separate duties when one engineer ships everything?
Do we need to hire a security person first?
What does doing SOC 2 yourself cost?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.