Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Best SOC 2 Compliance Tools in 2026

Direct answer: There is no single best SOC 2 tool, because SOC 2 is four different jobs. Evidence automation (Vanta, Drata, Secureframe, Sprinto, Scrut) proves technical controls on a schedule. Policy management is usually the same platforms or a document store. Self-assessment, which is understanding what the criteria ask of you, is where most first-timers actually get stuck and is available free. The audit itself is a licensed CPA firm and cannot be bought as software. Pick per job, not per brand.

Job 1: understanding what SOC 2 asks for

Before anything is automated, somebody has to decide which trust services criteria are in scope, which systems are in scope, and what "in place" means for each control at your company. Buy automation before this and you pay to automate the wrong control set.

This job needs a control library in plain English and somewhere to record your answers. traztech Workspace does it free: all 61 SOC 2 criteria explained, an evidence register, a policy library, and a readiness score that moves as you answer. We build it, so verify that yourself. It does not do continuous evidence collection.

Job 2: collecting evidence on a schedule

This is what the paid platforms are genuinely good at. They connect to your cloud, identity provider, and code hosting, check controls continuously, and keep dated records.

  • Vanta. Widest integration catalogue, most familiar to auditors, strong trust page. Opinionated control set.
  • Drata. Comparable, better control customisation and multi-framework overlap.
  • Secureframe. Comparable, positioned on more included human support. Check what the tier actually covers.
  • Sprinto. Cheaper, aimed at smaller teams on a straightforward cloud stack.
  • Scrut. Broad framework coverage for the price.

Expect roughly $7,000 to $25,000 a year depending on headcount and framework count.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Job 3: the work the tools do not do

Writing policies that match how you actually operate, fixing broken change management, running the risk assessment, getting a penetration test done, and handling auditor pushback. This is where a first SOC 2 spends most of its time and budget, and no platform does it. It is people, whether that is your team or a prep partner.

Job 4: the audit

A licensed CPA firm issues the report. By the rules of the standard it must be independent of whoever built your controls, so your prep partner cannot also be your auditor. Choose a firm your buyers will recognise and budget it separately.

Choosing in one table

If this is your situationStart here
You do not yet know what SOC 2 involvesA free self-assessment. Understand scope before spending.
First SOC 2, small cloud stack, tight budgetSprinto or Scrut, or free self-assessment plus a prep partner.
Enterprise buyers already in security reviewVanta, mostly for auditor familiarity and the trust page.
SOC 2 plus ISO 27001 or moreDrata or Scrut, for overlap handling.
You bought a platform and are still not readyThe gap is remediation, not tooling.

Frequently asked

Do I need a tool to get SOC 2?

No. The standard does not require one and no auditor asks which you bought. Tools reduce manual evidence collection, particularly for Type II.

What is the cheapest path?

Run a free self-assessment, see the real scope, then decide between tooling, help, or both.

Will a tool get me through the audit?

It will get you through the evidence collection. Remediation, policy accuracy, and auditor questions are human work.

What "integration coverage" actually buys you

Every vendor in this category leads with the size of its integration catalogue. The number is close to meaningless on its own, because the question is not how many systems a platform can read, it is what share of your control population it can read without a human touching it. For a company running AWS, Okta, GitHub, Jamf and Google Workspace, a good platform will automate somewhere around half to two thirds of the technical controls in a Security-only SOC 2. The rest stays manual whatever you buy.

The manual remainder is predictable, so you can price it before you sign anything. Vendor due diligence records, the annual risk assessment, board or management oversight minutes, background check records, security awareness training completion for contractors who are not in your HR system, physical access for any office you actually control, disaster recovery test results, and the penetration test itself all arrive as documents a person uploads. If your stack includes anything self-hosted, anything on a second cloud you acquired with a company, or a legacy VM estate nobody wants to touch, add those too. Teams that sign expecting near-total automation and then discover half their production runs on a colocated cluster with no API end up doing far more manual collection than the demo suggested, so count your own systems before you believe a coverage figure.

Ask for the control-level mapping before purchase, not the integration count. A serious vendor will give you a spreadsheet listing each control in their SOC 2 library, marked automated, semi-automated or manual, and which integration covers it. Take that spreadsheet, cross out every integration you do not run, and count what is left. That number is what you are buying.

Evidence a platform will never produce

There is a category of SOC 2 evidence that is not a configuration state at all, and no amount of API access reaches it. Change management is the clearest example. A platform can prove that your repository requires pull request approval and that a given commit had a reviewer. It cannot prove that the reviewer understood the change, that emergency changes followed a documented break-glass path, or that the four deployments made from a laptop during last October's incident were retroactively ticketed. Auditors ask about all three.

The same gap shows up in access reviews. The platform will generate a user list per system and ask a manager to tick names. What the auditor tests is whether the reviewer had enough information to make a real decision, whether removals actually happened within your stated window, and whether service accounts and third-party integrations were in the population at all. A ticked box with no downstream removal ticket is a finding, and it is a finding produced by a tool that reported the control as green.

Incident response is the third. Automation can show you have a policy and that people acknowledged it. Only a tabletop exercise with dated notes, named participants and a list of things you changed afterwards demonstrates the control operating. If you want a starting structure for that, our walkthrough of building an incident response plan from scratch covers what the document needs to contain to survive review.

What auditors actually do with platform output

A common misreading is that the audit firm logs into your platform, sees green, and issues a report. That is not how the testing works. The auditor selects a sample, usually from a population you provide, then re-performs or inspects each item. The platform makes the population easier to produce and the artefacts easier to retrieve. It does not remove the sampling.

Two things reliably go wrong here. The first is population completeness. If the auditor is testing onboarding across the observation window and your platform only knows about employees added after you installed it, your population is short, and a short population is worse than no population because it looks like you are hiding people. Before your window opens, reconcile the platform's employee roster against payroll for the full period.

The second is the timestamp problem. A platform check that runs today proves the control is in place today. A Type II covers three to twelve months. If you turned on the platform in month four of a six-month window, months one to three have no continuous evidence and you will be filling that in from screenshots, ticket exports and cloud audit logs. Everyone who has done this once starts the tool before the window rather than during it. Our note on operating a Type II observation window goes through the timing in more detail.

The cost drivers nobody quotes upfront

The $7,000 to $25,000 range is the platform subscription. The line items that surprise people sit next to it.

Headcount tiers. Pricing is banded by employee count, and the bands are narrow at the bottom. A company sitting near the top of its band that hires through the ceiling mid-contract gets renegotiated into the next one at renewal, and the step between bands is a step, not a slope. Ask where the next two bands sit before signing, and ask whether contractors, advisors and offboarded staff count.

Framework add-ons. The first framework is bundled. The second is usually a paid module, and the discount for overlap is smaller than the actual control overlap. If ISO 27001 is on your roadmap within eighteen months, price both now. The mapping question matters as much as the price: ISO 27001 is 93 Annex A controls plus clauses 4 to 10, and platforms differ wildly in how honestly they represent the clause work, which is management system documentation rather than technical configuration.

Implementation and onboarding fees. Some vendors charge a one-time onboarding fee in the low thousands. Some include a fixed number of hours of a compliance success manager and then meter beyond it. Read what "unlimited support" means in your tier, because it usually means unlimited tickets rather than unlimited advisory.

Bundled services. Platforms increasingly resell penetration testing, security awareness training and background checks through partners. The convenience is real. The pricing is rarely competitive, and the penetration test is often a scan-heavy engagement priced as a manual test. Buy the test on its own terms. Our guide to vetting a penetration testing firm lists the questions that separate the two, and penetration testing from us starts at $1,000.

The auditor. Independent line, always. The audit fee is not affected by which platform you bought, though which platform you bought can affect how many hours the auditor bills, because a tidy evidence room genuinely reduces their fieldwork. Going into the scoping call with a documented readiness position, rather than letting the firm assume the worst about your evidence, is what moves that number, and it has nothing to do with which tool you bought.

Failure modes we see repeatedly

The dashboard that is green because the scope is wrong. A platform monitors what you connect. Connect one of three AWS accounts and it will happily report full coverage of the account it can see. Reconcile the connected accounts, repositories and identity providers against your own asset inventory quarterly, not just at the start.

Agent coverage that quietly decays. Endpoint controls depend on an agent being installed and reporting. New starters get it during onboarding. Contractors, personal machines used "just for a week", and anyone who reimaged their laptop often do not. This is the single most common source of exceptions in a first Type II, because the failure is invisible until the auditor pulls the population.

Policies accepted but not true. The platform ships template policies, everyone clicks accept, and the document now says you perform quarterly access reviews and annual penetration testing. If you do neither, you have manufactured evidence of a control you do not operate, which is a worse position than having no policy. Edit the templates down to what you actually do before anyone signs them, then raise the bar deliberately.

Ownership evaporating after the report. The platform keeps running, the alerts keep firing, and by month four nobody is triaging them because the person who ran the project moved on. This is drift, and it is the reason year two audits often go worse than year one. We wrote about the pattern in control drift between audits.

Switching platforms, and what does not come with you

Migration is more painful than the sales conversation implies. Your control mappings, custom control text, evidence annotations and reviewer sign-offs are structured differently in each product, and export usually means a bulk file dump of artefacts without the metadata that made them useful. Historical continuous-monitoring results, the thing you paid for, generally do not transfer in a form a new platform will treat as its own evidence.

The practical rule is to switch between audit cycles, never inside an observation window, and to keep your own copy of the evidence outside the platform as you go. A dated folder structure in your own storage costs nothing and means a vendor change is an inconvenience rather than a lost audit. If you want somewhere neutral to hold the register and the criteria mapping while you decide, the free traztech Workspace does that job and we do not charge for it.

How to run a useful evaluation in two weeks

Demos are optimised for a stack that looks nothing like yours. Give each vendor the same three tasks instead. First, connect to a sandbox or a low-risk production account and show you the actual evidence artefact produced for change management, access review and endpoint encryption, not the dashboard tile. Second, hand you the control-level automation mapping described above, in writing. Third, name two audit firms who have worked with their output in the last year and let you speak to one.

Then ask the questions vendors dislike: what happens to my data and evidence if I cancel, what is your renewal uplift policy, which controls in your library have you changed in the last twelve months and how were customers notified, and what exactly is included in support at my tier. Written answers, not verbal ones.

What year two looks like on each option

The tooling decision looks different once the first report is on the shelf. In year two the evidence volume is larger, because you are proving twelve months rather than three, and the population of employees, vendors and systems has grown. The manual path that was tolerable at fifteen people and one cloud account gets genuinely unpleasant at forty people, two clouds and a subprocessor list that changed four times.

That is the honest argument for buying a platform, and it is a year-two argument rather than a year-one one. What the platform will not fix in year two is the thing that actually bites, which is that nobody owns the programme any more. Access reviews slip a quarter, the risk assessment is a year stale, three exceptions from last year were never remediated, and the vendor list still contains a tool you stopped paying for in March. Every one of those is a person problem with a calendar attached.

Whoever owns it needs named authority, a recurring slot, and enough seniority to tell a team to stop and fix something. That can be an internal hire, an existing engineering lead with protected time, or a fractional CISO, which we run from $3,000 a month. What it cannot be is a dashboard.

When you should not buy a platform, and when you should not buy from us

Skip the platform entirely if you are under roughly fifteen people on a single cloud account and you are doing a Type I to unblock one deal. The manual evidence burden at that size is a few hours a month and the subscription is real money you could spend on the remediation that is actually blocking you. Do the self-assessment, fix what it surfaces, buy the platform when the Type II window opens.

Skip it also if you already know the blocker is not evidence. If your problem is that you have no formal change management, no risk assessment and three engineers sharing a root account, a platform will faithfully document that you are not ready. Fix the controls first. Tooling makes a working programme cheaper to prove; it does not make a broken one pass.

And do not hire us if the honest answer is that you need one more quarter of engineering focus on the product. Compliance done as a deal unblocker has a real return. Compliance done because it feels like the responsible thing to do at seed stage usually does not, and we would rather tell you that than sell you a readiness engagement you will resent. If a deal is genuinely on the line, our fixed-scope work starts at a $3,000 gap analysis and the terms are published on the pricing page before you speak to anyone. If the timing is wrong, come back when it is not.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.