Every SaaS founder who has tried to close an enterprise deal has heard the same question from procurement: "Can you send us your SOC 2 report?" Technically, SOC 2 is an attestation, not a certification, but almost nobody searches it that way. Buyers say "SOC 2 certification," so we will too. What matters is what your customers actually want to see: proof, from an independent auditor, that you handle their data responsibly.
This guide walks through the real process, step by step, with the timelines you should actually expect rather than the ones vendors put in a sales deck.
Step 1: Decide Which Trust Services Criteria You Need
SOC 2 is built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory for every SOC 2 report, full stop. The other four are optional and should be chosen based on what your customers actually ask about and what your product does.
Most B2B SaaS companies start with Security only, sometimes adding Availability if uptime is a selling point or Confidentiality if you handle sensitive client data. Adding criteria you do not need just adds audit scope, cost, and evidence collection work without moving the needle for buyers. This is one of the first places a readiness partner earns their fee: telling you honestly that you do not need Privacy criteria yet, even though it sounds impressive.
Step 2: Choose Type I or Type II
A Type I report assesses whether your controls are designed properly at a single point in time. A Type II report assesses whether those controls actually operated effectively over a period, typically three to twelve months.
Type I is faster and cheaper, and it can unblock a deal in the short term, but most enterprise buyers and their security teams want Type II. If you have runway, skip Type I and go straight to Type II. If you have a deal on the table right now that needs something in writing, Type I can buy you time while your Type II observation window runs.
Step 3: Run a Readiness Assessment (Gap Analysis)
Before you ever talk to an auditor, you need to know where your gaps are. A readiness assessment maps your current security posture, policies, and technical controls against the criteria you selected in Step 1. Common gaps we see: no formal access review process, missing incident response documentation, vendor risk management that lives in someone's head instead of on paper, and logging that exists but is not centralized or reviewed.
This is where SOC 2 readiness work matters most. A structured, fixed-scope readiness engagement identifies every gap up front so you are not discovering missing controls three months into your audit window, which is the single most common cause of SOC 2 timelines blowing out.
Step 4: Remediate the Gaps
Once you know the gaps, you close them. This usually means writing or updating policies (access control, incident response, change management, vendor management), implementing technical controls (MFA everywhere, centralized logging, automated backups, encryption at rest and in transit), and assigning clear owners for ongoing control operation.
Realistic timeline: for a company with reasonably mature engineering practices, remediation typically takes four to eight weeks. For an earlier-stage company building security practices from scratch, expect eight to twelve weeks. This step is where most DIY SOC 2 attempts stall, not because the work is conceptually hard, but because it competes with product roadmap for engineering time and nobody owns it full time.
Step 5: Run Your Controls for the Observation Period
If you are pursuing Type II, your controls need to operate as documented for the full observation window, commonly three months for a first report and stretching to six or twelve months for renewals. This is not a passive waiting period. You need to be collecting evidence continuously: access review logs, ticket trails for change management, security awareness training completions, vendor assessments.
Missing evidence during this window is the second-biggest reason SOC 2 timelines slip. If a control lapses in month two and nobody notices until the auditor asks for evidence in month four, you may need to restart the clock.
Step 6: Select and Engage an Independent Auditor
SOC 2 reports must be issued by an independent, licensed CPA firm. This is a hard requirement, and it is also the one place readiness firms cannot substitute themselves in, by design. A readiness partner prepares you for the audit and can coordinate the relationship, but the actual attestation has to come from an independent party or the report has no credibility with your buyers.
At traztech, we act as the SOC 2 readiness expert and coordinate with an independent CPA auditor on your behalf. We are not the auditor. Keeping that line clear is what makes the report trustworthy to the people evaluating it.
Step 7: Complete the Audit
The auditor reviews your documentation, tests your controls, and interviews relevant staff. If your remediation and evidence collection in Steps 4 and 5 were thorough, this step is largely administrative: answering auditor questions and producing requested evidence. Audit fieldwork itself typically takes two to six weeks depending on scope and how organized your evidence is.
Companies that skip readiness work and go straight to an auditor often find this step turns into a second remediation cycle mid-audit, which is slower and more expensive than doing the prep work first.
Realistic Total Timeline
Putting it together, a first-time SOC 2 Type II engagement realistically runs four to nine months from kickoff to final report: readiness and remediation (one to three months), the observation period (three to twelve months, often run partially in parallel with remediation), and audit fieldwork (a few weeks at the end). Type I only, without an observation period, can land in six to ten weeks total.
Anyone promising a SOC 2 report in two weeks is either talking about Type I with almost no remediation needed, or setting an expectation they cannot meet.
Where a Partner Actually Helps
The parts of this process that benefit most from outside expertise are scoping (so you do not over-build), gap identification (so nothing surprises you mid-audit), and staying organized through the observation period (so evidence collection does not silently lapse). A fixed-scope readiness engagement gives you a defined cost and timeline instead of open-ended consulting hours, and it keeps the auditor relationship clean, with the CPA firm doing the attestation and the readiness partner doing the preparation.
If your team is also weighing broader security posture work alongside SOC 2, it is worth looking at how readiness fits into your overall security programme rather than treating it as an isolated checkbox exercise.
Ready to Start
If a deal is stalled on SOC 2 or you know it is coming in your next few sales cycles, the earlier you scope the work, the less it costs you in rushed remediation later. Get in touch and we will walk through where your gaps likely are and what a realistic timeline looks like for your team.
How to Vet an Auditor, and Why Quotes Vary So Widely
Three CPA firms will quote the same company three very different numbers, and the spread is rarely about quality. It is about how much unknown risk the firm is pricing in. A firm that cannot tell from your kickoff call whether your evidence exists will pad the estimate to cover the fieldwork it expects to spend chasing you. A firm that has seen a complete gap analysis, a control matrix, and a sample of your evidence knows how long the job takes.
Ask each firm the same five questions and compare the answers rather than the totals. How many clients of our size and stack do you issue reports for each year? Who actually performs the fieldwork, and are they in-house or subcontracted? What is your evidence request process, and do you work from a portal or from spreadsheets over email? What is your turnaround from the end of fieldwork to the draft report, and to the final signed report? And what happens to the fee if you find that a control was not operating, does the engagement continue at the same price or convert to hourly?
That last question separates firms more than any other. Also confirm peer review status and that the partner signing is licensed, because a buyer's security team occasionally checks. The commercial upside of arriving prepared is real: on one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we wrote up in detail in our auditor vetting case study.
The System Description Is the Document Buyers Actually Read
The report has four sections, and founders tend to focus on the auditor's opinion in Section I. The part that gets scrutinized in a vendor review is Section III, the system description, which you write, not the auditor. It describes your service, your infrastructure, your data flows, your people and processes, your subservice organizations, and the controls you claim to operate. Section IV then lists each control, the auditor's test procedure, and the result.
Write Section III yourself, early, and in plain language. Two failure modes recur. The first is describing the company you intend to be, listing a security operations capability that is in fact one engineer with alert emails, which will not survive the walkthrough. The second is a description so vague that a buyer's reviewer cannot tell whether the product they are purchasing is inside the boundary. If you sell three products and only one is audited, say so explicitly, because the alternative is answering that question in every deal for the next year.
Section III also carries the complementary user entity controls, the things your customers must do for your controls to work, such as managing their own administrative accounts and configuring single sign-on properly. Write them deliberately. They set the boundary of your responsibility, and a thoughtless copy-paste list is a contractual argument waiting to happen.
Subservice Organizations: Carve-Out or Inclusive
Your cloud provider, your payment processor, and your managed database vendor all perform functions relevant to your controls. You have two ways to handle them. The carve-out method excludes their controls from your report and states that they are the responsibility of the subservice organization. The inclusive method brings their controls into your report, which almost nobody does because it requires the vendor's cooperation.
Nearly every SaaS report uses carve-out, and the obligation that follows is vendor monitoring. You must obtain and review each subservice organization's own SOC 2 report annually, read the exceptions in it, and check the complementary user entity controls their report imposes on you. That last step is the one that gets skipped. Your cloud provider's report contains a list of things you are expected to configure, and an auditor who is paying attention will ask what you did with it. Keep the vendor reports, the review dates, and a short note per vendor recording what you found. That file takes an hour a quarter and closes a control that otherwise fails in year two.
How Auditors Sample, and Why Dates Matter More Than You Think
For a Type II report the auditor does not look at everything. They define a population, pick a sample size proportional to the control frequency, and test those items. A daily control might draw a sample of twenty-five, a quarterly control might draw two, and an annual control gets tested once. The mechanics have direct consequences for you.
First, the population has to be complete and provable. If the auditor asks for all production deployments in the period and your list is assembled by hand from memory, the sample is meaningless and the control fails on population integrity rather than on operation. Pull the population from the system of record, a CI pipeline, a ticket queue, an identity provider export, and keep the export itself.
Second, low-frequency controls are unforgiving. A quarterly access review with a sample of two means one late review is a fifty percent failure rate, and the auditor will note an exception. Third, dates must line up. An access review dated three days after the period ended does not count for that period. An onboarding record signed a month after the employee's start date proves the record exists, not that the control operated. Where the process allows, run controls more often than the minimum. Monthly access reviews cost slightly more time and give an auditor eleven chances to see the control working instead of three.
When a Control Lapses Mid-Window
Something will lapse. An access review gets missed in a hiring quarter, a hotfix ships without an approval record, a departing employee's account stays active for six weeks. The instinct is to backdate or to quietly recreate the record, which is the single worst decision available to you. It converts an exception, which is survivable, into a misrepresentation to an auditor, which is not.
The correct handling is procedural. Document the lapse when you find it, including the date it was discovered and how. Perform the control late and label it late. Write a short remediation note explaining the root cause and the change you made so it does not recur. Then raise it with the auditor before fieldwork rather than letting them find it. Reports do get issued with noted exceptions and management responses, and a buyer's security reviewer who reads a clear exception with a documented fix generally accepts it. What they do not accept is discovering a pattern of missing evidence with no acknowledgement anywhere in the report.
If the lapse is severe enough that the control cannot be said to have operated at all, discuss shortening or restarting the window with the auditor early. Losing six weeks is cheaper than issuing a report with a qualified opinion that you then have to explain in every sales cycle.
What the Whole Thing Costs
Budget in four buckets. The auditor's fee is the one people quote each other, and it is usually the smaller half of the total. Readiness work is the second, and ours starts at $3,000 for the gap analysis, which is deliberately published so you can plan against a number rather than a range. Tooling is the third, and it grows quietly: an identity platform tier that supports conditional access, log retention, endpoint management, a vulnerability scanner, and possibly a compliance automation subscription. The fourth and largest is internal time, and it is the one nobody costs. Expect the engineering hours for remediation plus a steady drip through the observation window for evidence collection and auditor questions.
Compliance automation platforms are worth a straight assessment. They genuinely reduce evidence collection effort where your stack matches their integrations, and they are close to useless for the judgement work: deciding scope, writing a defensible system description, and arguing a control position with an auditor. Buy one for the collection, not for the thinking. If you would rather not add another subscription while you are getting started, the free traztech Workspace holds the control matrix, the evidence register, and the refresh dates in one place.
When SOC 2 Is Not the Right Purchase
Some companies should not start this. If a single prospect asked for SOC 2 and no other deal in your pipeline has raised it, ask that prospect what they will accept in the interim. A completed security questionnaire, a current penetration test summary, published policies, and a contractual commitment to a report date closes a meaningful share of mid-market deals. That package takes weeks rather than months.
If your buyers are primarily European or your customers are asking about an information security management system rather than a report, ISO 27001 may be the better fit, and running both at once before either is embedded is a reliable way to do neither well. If you are pre-product-market-fit and the security requirement is speculative, the money is better spent on the underlying controls, since every one of them is reusable later and none of the audit fee is.
And if you have engineering discipline, a small stack, someone with genuine time to own the programme, and no deal-driven deadline, running readiness yourself is entirely feasible. The published criteria are not secret. Buy a short scoping review and an auditor introduction rather than a full engagement, and keep the difference. Our published pricing exists so you can make that comparison before you talk to anyone.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.
See SOC 2 in 75 DaysOr talk about a retainer