It usually arrives as a single line inside a longer, friendly email. The deal is going well, your champion is excited, and then their security or procurement team attaches a questionnaire with a sentence that stops everything: we will need to see your SOC 2 report before we can move forward.
If that just happened to you, take a breath. Do not reply with a vague promise, and do not go quiet while you figure it out. You have more control over this moment than it feels like, and a large buyer would rather work with a vendor who has a credible plan than one who panics. Here is a realistic 30-day plan to keep the deal warm and start SOC 2 the right way.
Days 1 to 5: understand what is actually being asked
SOC 2 is not one thing. There is Type I, which says your controls are designed correctly at a single point in time, and Type II, which says those controls actually operated over a period of months. The two have very different timelines and costs, and buyers do not always specify which they want.
So go back to your champion with three questions. Do they need a Type I or a Type II. Is there a hard deadline tied to the contract. And would a signed engagement plus a Type I in progress be enough to keep things moving while the full report is produced. Most reasonable buyers accept evidence that you are seriously underway, especially when you can name a date. That one conversation often buys you the room you need, and it signals that you understand their world.
Days 5 to 15: scope the work and close the fast gaps
Now get concrete about what is in scope. For most SaaS companies the security criteria and the production systems that handle customer data are the core. A gap assessment tells you where you stand against what an auditor expects.
While that runs, knock out the quick wins that move you a long way with little drama:
- Turn on multi-factor authentication everywhere, with no exceptions
- Remove shared logins and rotate any credentials that were passed around
- Enable centralized logging with sensible retention
- Confirm backups exist and can actually be restored
- Write down who has access to what, and remove access nobody needs
None of these require a big project, and all of them are things a buyer would expect a serious vendor to already have. Doing them first also makes the rest of the program calmer.
Days 15 to 30: policies, evidence, and an auditor
With the fast gaps closed, the work shifts to documentation and proof. You need a set of security policies that reflect how you actually operate, not generic templates copied from the internet. You need to start collecting evidence in the way an auditor will ask for it. And you need to choose your independent auditor, because the SOC 2 report has to be signed by a licensed CPA firm that is separate from whoever helps you prepare.
If you want tooling, a compliance platform like Vanta or Drata can automate a lot of the evidence collection. It is useful but optional, and it does not replace the judgment of deciding what is in scope or how to close a control that keeps failing.
What not to do
Do not promise a date you cannot hit, because missing it does more damage than a longer honest timeline. Do not buy a compliance tool and assume it does the work for you. And do not go silent on the buyer while you scramble. A short, confident update that says here is our plan and here is when keeps the deal alive far better than radio silence.
Where we come in
We are the prep partner, not the auditor, and we are unusually technical about it. Our founder is a published security researcher with five CVEs, so the controls we build hold up when a buyer starts asking hard questions. We get most startups audit-ready in 8 to 12 weeks with a fixed scope, so you know the number and the date before you commit. If you want the full picture for a Canadian SaaS, read our guide on SOC 2 for Canadian SaaS, or see how the whole program works on our compliance page.
If a deal is waiting on your SOC 2 right now, tell us who is asking and when they need it and we will come back with a straight plan.
What to actually say to the buyer, in words
The advice to keep the buyer informed is only useful if you know what a credible update sounds like. Vagueness reads as risk to a security reviewer, so the update needs three things: a named framework and report type, a date, and a way for them to verify progress. Something close to this works: we are pursuing SOC 2 Type II covering security and availability for our production platform, our readiness engagement started on the fifteenth, our observation period opens on the first of next month, and our auditor is engaged. Here is our security overview and our latest penetration test summary under NDA in the meantime.
That message does two jobs. It gives the champion something to forward internally without editing, which matters more than founders realize, because your champion is the one who has to defend the exception. And it converts an open-ended risk into a dated one, which is the form a risk committee can approve. Ask your champion directly what their security team needs to grant a conditional approval, since most enterprises have a documented exception process with a compensating-control path. Common compensating controls that get accepted: a recent independent penetration test with remediation evidence, a contractual commitment to deliver the report by a date with a termination right attached, a security addendum with breach notification timelines, and a right to audit clause. Offering those before being asked signals that you have done this before.
The observation period is the constraint, and it cannot be bought
Almost everyone underestimates this. A Type II report describes how controls operated over a period, typically three to twelve months. The report cannot be issued until that period has closed and the auditor has finished fieldwork, which adds another three to six weeks. So the shortest honest path from a standing start to a Type II report in hand is around four to five months, and that assumes a three month period, controls already operating, and no remediation surprises. No amount of money compresses that, because it is calendar time by construction.
The lever you do have is the start date of the period. Every week you delay closing gaps is a week the period cannot begin. That is why the first thirty days matter so much and why the gap assessment should be the first check you write, from $3,000. A second lever is the report type: a Type I attests to control design at a point in time and can be issued within weeks of controls being in place, which is why so many companies deliver a Type I to unblock the contract and commit to a Type II at the next reporting date. Buyers who understand the standard usually accept that. Buyers whose procurement checklist just says SOC 2 usually do too, once your champion explains the difference. The one thing that damages you is promising a Type II date that assumes a period which has not started.
Scope decisions that quietly set your cost
SOC 2 has five trust services criteria and only security is mandatory. Every additional criterion adds controls, evidence, and audit hours. Availability adds capacity monitoring, backup, and recovery testing. Confidentiality adds data classification and disposal. Processing integrity is genuinely demanding and is rarely needed outside transaction processing. Privacy is the heaviest and overlaps with your PIPEDA and Law 25 obligations rather than replacing them. Add criteria because a customer contract requires them, not because more sounds better on a website. Adding availability to a first report is common and reasonable. Adding all five is a mistake we watch companies make once.
The other scope decision is systems. Your report covers a defined system boundary, and everything inside it is subject to testing. A corporate laptop fleet, a marketing site, and a staging environment do not need to be in scope if they do not touch customer data. Excluding them cleanly, with a written rationale, is legitimate and it removes whole categories of evidence. What you cannot do is exclude something the buyer cares about, so check the boundary against the questions in their questionnaire before you finalize it. Subservice organizations are the third decision: you will either carve out your cloud provider, which is standard, or include them inclusively, which nobody does. Carve-out means your report says the provider's controls are excluded and you are responsible for monitoring them, which in practice means you need a documented review of their SOC 2 report each year.
Choosing the auditor without wasting three weeks
Auditor selection stalls more first-time programs than any technical gap. Get quotes from three firms and compare on four dimensions rather than price alone. Availability: can they start fieldwork on your date, because a firm that is booked out to the next quarter has just moved your delivery date. Experience with your stack and company size, since a firm that mostly audits banks will apply banking expectations to a twelve person startup and you will spend the engagement arguing. Their evidence expectations, which vary more than people expect, so ask for a sample request list before signing. And whether they will accept your compliance platform's automated evidence, because some firms discount it and re-request manually.
Ask each firm three specific questions. How many rounds of evidence requests should we expect and what is your turnaround on each. What proportion of your first-time clients receive a qualified opinion or exceptions, and what causes them. And who is actually on the engagement, since the partner who sells is rarely the senior who tests. Price ranges widely, and a low quote from a firm that is drowning in work costs you more in delay than the difference. One thing worth doing before you sign: a documented readiness position, produced properly, reduces the discovery the auditor has to perform. We had a client take $11,000 off an audit quote on the strength of one, because the firm could see how much of the work was already done and priced accordingly.
The exceptions that end up in the report
A SOC 2 report is not pass or fail. It is an opinion with, potentially, a list of exceptions where a control did not operate as described. Buyers read those exceptions. The four that recur in first reports are all preventable. Access reviews performed late or not at all in one quarter, because nobody owned the calendar. Terminated employees whose access was removed days after their last day, which the auditor catches by reconciling your HR list against your identity provider. Deploys that went to production without the documented approval, usually a hotfix at two in the morning that nobody retroactively documented. And a vulnerability that sat past your own stated remediation window, because your policy promised thirty days and reality took ninety.
Notice the pattern: three of the four are cases where the company wrote a policy stricter than its actual practice, then got tested against the policy. So write policies you will actually meet. If you patch criticals in sixty days, say sixty, not fifteen. If you review access twice a year, say twice, not quarterly. Auditors test against what you claim, and the cheapest way to avoid an exception is to claim something true. When an exception is unavoidable, the response matters: a documented root cause, a corrective action, and evidence the control operated correctly afterwards turns a red flag into an acceptable footnote. Buyers forgive an exception with a remediation note. They do not forgive a pattern of them with no management response.
What this costs your engineering team, in hours
Founders budget the audit fee and the consultant, then get surprised by the internal cost. For a company of ten to thirty people, expect the technical lead to spend two to four hours a week for the readiness phase, more in the first two weeks while scope and architecture questions are answered. Expect a one-off block of engineering work, usually one to three weeks, for the gaps that need code: audit logging, session handling, encryption of a field that should have been encrypted, removing a shared service account. Expect every employee to lose an hour to security awareness training and policy acknowledgement. And expect the person who owns the program to spend roughly a day a week for the duration on evidence, chasing, and coordination.
That last line is the one that gets underestimated and it is the strongest argument for outside help, since the coordination work is unrewarding and it is exactly what gets dropped when a release slips. During fieldwork the load spikes: auditors send evidence requests in batches with short turnarounds, and a delayed response from your side extends the engagement in ways the auditor will not absorb. Assign one named owner with the authority to interrupt engineers, and make sure their manager knows the commitment. Programs run by a committee of volunteers take twice as long as programs run by one accountable person. If you would rather that person be external for the duration, that is what a fixed-scope readiness track from $3,000 for the gap analysis buys, laid out on our pricing page.
Common ways the 30-day plan goes wrong
Buying the platform first. Compliance automation tools onboard fast and produce a dashboard full of red items within a day, which feels like progress. It is not progress until someone decides which of those items apply to you, which controls you are actually claiming, and what your boundary is. Teams that start with tooling frequently spend three weeks configuring integrations, then discover the scope conversation still has to happen.
Writing policies nobody reads. Generic templates get through some audits and fail others, but the real cost shows up later when a buyer's security team reads your access control policy and asks a question your engineers cannot answer, because the policy describes a company that does not exist. Write policies from your actual practice and change the practice where it is genuinely inadequate.
Letting the deal deadline set the audit scope. A buyer asking in March for a report before their fiscal year end in June will pull you toward a Type I with a scope so narrow it satisfies nobody twelve months later. Serve the deadline, but plan the second report at the same time so you are not rebuilding scope every year.
Treating the penetration test as an afterthought. It is not strictly required by the standard, but most auditors expect one and every buyer asks for it. Booking it in the last week means findings arrive with no time to remediate, and a report with unremediated criticals is worse to hand over than no report at all. Book it early enough to fix and retest, which our security testing work is usually scheduled around.
When SOC 2 is the wrong answer to this request
Sometimes the honest answer is that you should not start a SOC 2 program at all this quarter, and we would rather say so than take the engagement. If the deal in question is small, the buyer is one enterprise among a pipeline of mid-market customers who have never asked, and cash is tight, a full program is a poor trade. Ask your champion whether a security questionnaire, a documented policy set, and an independent penetration test will clear their review. For a great many mid-sized buyers it will, and that package costs a fraction of an audit.
If your buyer is European, they may actually want ISO 27001 and be asking for SOC 2 because their procurement template is American. Those are different standards with different evidence and a different certificate, and doing the wrong one is an expensive detour. If you are selling into health care in the US, a HIPAA posture and a business associate agreement may be the real blocker with SOC 2 as a secondary ask. Establish which artifact actually unblocks the contract before you spend a dollar, which is the first thing we do on any compliance conversation.
And if you are pre-revenue with one prospect dangling a logo, be careful. A SOC 2 program is a permanent annual obligation, not a one-time purchase, and the second year costs real money again. Winning one deal that funds it is fine. Starting it on the hope of a deal that has not been signed is how companies end up maintaining a report nobody asked to see. Get the contract, or at least a written commitment contingent on the report, then start. If you want a second opinion on whether the request in front of you justifies the program, tell us who is asking and what they said and we will give you a straight read even when the answer is that you do not need us yet.
Stuck on a buyer review? We answer SIG, CAIQ and bespoke security questionnaires, and set up the trust center that stops most of them arriving.
Talk to usOr talk about a retainer