Direct answer: A small business usually needs three things: somewhere to record which controls apply and whether they are in place, somewhere to keep policies with approval and acknowledgement history, and somewhere to hold evidence with dates. All three are available free. Paid platforms add continuous automated evidence collection, which earns its cost once you are maintaining a report across years rather than getting a first one.
What a small team actually needs
| Need | Why it matters | Free? |
|---|---|---|
| Control library and self-assessment | You cannot plan what you have not scoped | Yes |
| Policy set with approval history | Auditors sample the approval and the acknowledgement roster | Yes |
| Evidence register with dates | Undated evidence is close to useless | Yes |
| Risk register | Required outright by ISO 27001, expected by SOC 2 | Yes |
| Vendor records with the reports attached | Their SOC 2 becomes your problem in an audit | Yes |
| Continuous automated evidence | Saves real hours on Type II maintenance | No |
Where the money actually goes
For a first SOC 2 the three buckets are the licensed CPA auditor, tooling, and the readiness work. The readiness work is usually the largest and the most often left out of the plan. Tooling is the smallest of the three, which is why choosing a platform first is the wrong order.
A sensible sequence for a small team
- Find out which framework your buyer actually wants. Do not guess, ask them.
- Run the self-assessment free and get the real count of what is missing.
- Fix the cheap technical items yourself. MFA, logging, access reviews, backups.
- Decide whether the remainder is a people problem. If it is, get it scoped and priced.
- Buy tooling when recurring evidence collection is the bottleneck, not before.
The free option
traztech Workspace covers the first four items in the table: fourteen frameworks with every control in plain English, an evidence register that maps one artefact to every control needing it, a policy library with approval and acknowledgement tracking, a risk register, vendor records with the actual reports attached, and a security testing register. No card, no trial clock, no locked features. It does not do continuous automated evidence collection. We build it, so verify that for yourself rather than taking our word.
Frequently asked
Is free compliance software good enough for an audit?
The audit tests your controls and your evidence, not your tooling. Plenty of companies have passed with a document store and someone organised.
When should a small business buy a platform?
When manual evidence collection is genuinely costing more than the subscription, which usually means Type II maintenance rather than a first report.
What if we have no security person?
That is the normal case at this size. Somebody still has to own it. A fractional or part-time arrangement is the usual answer, and it is cheaper than a bad first audit.
What automated evidence collection actually collects
The paid tier of every compliance platform is sold on automation, and the word covers a narrower range of work than the demo implies. It is worth knowing exactly which of your evidence a platform can gather on its own, because that is the only part of the subscription you are really buying.
Platforms are good at things a read-only API can observe on a schedule: cloud configuration state, MFA enrolment across your identity provider, endpoint agent health, whether backups ran, whether encryption is on, open vulnerabilities from a connected scanner, and whether your list of employees in the HR system matches your list of accounts. These checks run daily, produce a timestamp automatically, and are exactly the evidence that is tedious to gather by hand across a twelve month observation window. That is a genuine saving and it is why Type II maintenance is the point where paying starts to make sense.
Platforms are poor at anything that involves judgement or a human artefact. Your risk assessment, your scope narrative, your system description, the reasoning behind an exception, a vendor review where somebody actually read the SOC 2 report, evidence that a change was approved by the right person for the right reason, board or management review minutes, and anything produced by a tool with no integration. In practice this is most of the work in a first report, which is why teams who buy a platform first are surprised at how much is still left.
The useful evaluation question is not how many integrations a vendor lists. It is which of your systems they connect to and what specifically they read from each. Ask for the field-level detail for your three most important systems before you sign. A vendor that connects to your cloud provider but not to the ticketing tool where all your change approvals live will automate a smaller share of your evidence than the marketing suggests.
The spreadsheet is fine until three specific things break
Running this on documents and a spreadsheet is a legitimate choice and we have watched small teams get clean reports that way. It stops working for reasons that are predictable, so you can watch for them rather than guessing.
Nobody can tell which version is current. The moment there are two copies of the control matrix and an argument about which one the auditor was sent, the tracking has failed. This is usually the first break and it usually happens when a second person joins the effort.
Evidence loses its date. A screenshot in a folder called Q3 is not evidence that a review happened in Q3. Auditors will accept a spreadsheet, but they will not accept an artefact whose date cannot be established from the artefact itself. Once you are collecting recurring evidence across a window, the date discipline is what fails first.
The ownership map lives in one person's head. When the person who has been driving the effort takes two weeks off and nobody else can say which controls are outstanding, you have a single point of failure on the thing that is meant to demonstrate you do not have single points of failure.
Any of those three is a reason to move to a structured tool. None of them is a reason to move to a paid one, which is the distinction the market blurs.
How to evaluate a platform demo without being sold to
Compliance platform demos are unusually well rehearsed. Four requests will tell you more than an hour of the standard walkthrough.
Ask them to connect to your actual environment on a trial rather than showing you their reference tenant. The gap between what the integration reads in a clean demo account and what it reads in a real company with legacy naming conventions is where the disappointment lives.
Ask what happens to a control that has no integration. Watch how manual evidence gets attached, dated, and re-requested next quarter, because that workflow is where most of your team's time will actually go.
Ask how you get everything out. Request a sample export of the evidence set, the policies with their approval history, and the control mapping, in a format that is usable without the product. A vendor that can only export a PDF summary has designed for retention rather than for you.
Ask what the renewal price is. Compliance tooling is commonly discounted heavily in year one against a list price that reappears at renewal, once your evidence history is inside the product and moving is painful. Get year two and year three pricing in writing before signing year one.
Lock-in is the cost nobody prices
The switching cost of a compliance platform is not the migration of documents. It is the history. Your second Type II report covers a window, and if the evidence for the first half of that window sits in a product you have left, you are reconstructing rather than exporting. This is why the practical time to change platforms is immediately after a report is issued and never mid-window.
Two habits reduce the exposure cheaply. Keep policies in a source you control, with the platform holding a copy rather than the original. And export the evidence register quarterly to your own storage as a matter of routine, so that leaving is a decision rather than a project. Neither costs anything and both are worth doing from the first week, including if you are using a free tool such as our own Workspace. We would rather you could walk away from it.
Where the platform does not help at all: the auditor relationship
A recurring assumption in the small business market is that buying the tool the auditor recommends will make the audit go faster. Partly true, and it hides the larger effect. What moves auditor effort, and therefore auditor cost, is how well defined your position is when the fieldwork starts: a settled scope, a control set that matches your actual environment, evidence that is dated and complete, and a written explanation for anything unusual.
That work is not a software feature. It is somebody sitting down and doing it. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we wrote up in the auditor vetting case study. The lesson small teams should take from it is about ordering rather than about the number. Preparation changes what the audit costs. Tooling mostly changes what the preparation feels like.
It is also worth knowing that auditors do not certify tools. Some firms have preferred platforms because their staff know where to click, and that familiarity can shave a little fieldwork time. None of them will accept a platform's internal pass or fail marker as evidence in place of the underlying artefact. If a vendor implies that their green ticks are the evidence, that is a misunderstanding of what the auditor's job is.
Do not overlook the security of the compliance tool itself
A compliance platform holds an unusual concentration of sensitive material: your architecture, your gaps, your risk register, your open findings, and read access into your identity provider and cloud account. It is a high-value target and it should go through your own vendor review rather than being waved through because it is a security product.
Ask for their own report, look at the permissions the integration requests rather than accepting the default install, and check whether the access is read-only. Then put the platform into your own access review, because the accounts created during an implementation project have a habit of outliving the people who created them.
When you should not buy any of this
Several situations that look like a tooling problem are not one, and buying software will make them worse by producing activity.
If nobody has asked you for a report yet, do not buy a platform in anticipation. Frameworks and scopes change with the buyer, and an annual subscription bought before you know which framework you need is money committed to a guess.
If you have fewer than about twenty employees, one cloud account, and no dedicated person, the honest configuration is free tooling plus a few days of expert time to define the scope and the control set correctly. The failure mode at this size is not disorganisation, it is scoping the wrong thing thoroughly.
If your real bottleneck is that nobody owns the work, a platform will not fix it. It will send reminders to a person who is already not doing the task, and you will renew a subscription against a half-finished implementation. Fix ownership first, with a part-time internal owner or a fractional arrangement, and buy the tool once there is somebody to operate it.
And if you are getting a first Type I report, the automation you are paying for barely applies, because there is no observation window to collect across. Get the report, then decide about tooling with a year of real evidence load to reason from. If you want a straight answer about which of these describes you, our compliance work starts with scoping precisely that, and the starting prices are published so you can compare it against a subscription before committing to either.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainer