Writing

What SOC 2 actually costs a ten-person SaaS company

A founder usually asks me about SOC 2 the week after a prospect’s security team sends a questionnaire. The question is almost always “how much and how long,” and the honest answer has four parts: the money you pay other people, the time you pay yourself, the calendar, and the shortcuts that look cheap in month one and are not.

The line items

There are three vendors in a normal SOC 2 program. A compliance platform (the category Vanta and Drata created) collects evidence from your cloud accounts, your identity provider and your laptops, and gives the auditor a place to look. An audit firm issues the report. A penetration tester, usually required by the auditor and always asked for by the buyer, tests the application once a year. For a company your size the platform and the audit are each a low five-figure annual cost and the penetration test is a low-to-mid four-figure one; the platforms publish list prices, and the auditors will quote in a day. The number that matters more is the fourth line: the hours your engineers and you will spend, which for a ten-person company is real and is where most of the delay comes from.

The calendar

A Type 1 report describes your controls at a point in time; a Type 2 report shows they operated over a period, normally three to twelve months. Buyers who know what they are looking at want the Type 2. From a standing start, the sequence is: scope and gap analysis in the first two or three weeks, controls and policies in place by the end of month two or three, the observation window running from then, and the audit fieldwork at the end of it. I have taken a company from nothing to a Type 2 attestation in under eight months, and that pace came from three decisions made early: a small scope, one named owner for every control, and an evidence routine that ran every week instead of in a panic before the audit.

What buyers actually check

Very few security reviewers read the whole report. They look at whether it is a Type 2, the period it covers, whether there are exceptions and what you said about them, and whether the scope includes the product they are buying. A clean report with a narrow, honest scope beats a broad one with exceptions.

The three shortcuts that cost more later

The first is writing policies you do not follow. The auditor tests what the policy says, so a policy that promises quarterly access reviews you never do creates an exception you could have avoided by promising less. The second is scoping in systems you do not need to; every extra system is more evidence to collect for the whole observation window. The third is leaving the program with no owner after the report arrives. The second audit starts the day the first one ends, and a company that treats the report as a one-time project spends the same money again the following year.

When you do not need SOC 2 yet

If the questionnaire in front of you is from a mid-market customer and you have not been asked for a report, a shorter list often satisfies them: multi-factor authentication, access control, tested backups, secrets out of the code, a vendor inventory, an incident plan and a few written policies. That is what I call Security Foundations, it takes about three weeks, and it is most of the groundwork for SOC 2 if you do need it later.

I work with at most four companies at a time.

Book a 30-minute call

The call ends with three concrete recommendations whether or not we work together.