Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

How to Get SOC 2 for a B2B SaaS Company

Direct answer: A B2B SaaS company gets SOC 2 by first closing the readiness gap between how the product actually handles customer data and what the Trust Services Criteria require, then having an independent CPA firm audit the environment over an observation period. In practice that means five steps: (1) scope the report type and criteria to what your enterprise buyers are actually asking for, (2) run a fixed-scope gap analysis against your real infrastructure, (3) remediate the gaps, typically access controls, logging, vendor management, and incident response, (4) hold the controls steady through a Type I point-in-time check or a Type II observation window (usually three to twelve months), and (5) engage a licensed CPA firm to issue the attestation. Most B2B SaaS companies with a lean engineering team can realistically get from kickoff to Type I in six to ten weeks with focused remediation, and to Type II in four to nine months depending on the observation period chosen.

Why B2B SaaS Companies Get Asked for SOC 2 in the First Place

If you are reading this, the trigger has probably already happened: an enterprise prospect's security questionnaire landed in your inbox, procurement flagged that a deal cannot close without a SOC 2 report, or your board asked what compliance posture looks like before the next raise. For Canadian SaaS companies selling into the US market, this moment tends to arrive earlier than founders expect, often at the first six-figure contract, because US enterprise buyers treat SOC 2 as table stakes rather than a nice-to-have. The pressure is real: the deal is sitting in legal review with a checkbox unticked, and nobody on the founding team has run a SOC 2 process before. That is the exact moment a fixed-scope gap analysis pays for itself, because it tells you precisely how far you are from attestation before you commit to a remediation timeline you cannot hit.

Step 1: Decide What Buyers Actually Need (Type I vs Type II, and Which Criteria)

Every SOC 2 report is built on the Security criterion (the "common criteria") at minimum, and most B2B SaaS companies add Availability and Confidentiality since customers care about uptime and data handling. Processing Integrity and Privacy are less common unless you are in fintech or health tech. The bigger decision is Type I versus Type II. A Type I report attests that controls are designed appropriately as of a specific date, which is faster to obtain and often enough to unblock an initial enterprise deal. A Type II report attests that controls operated effectively over a period, usually three, six, or twelve months, and is what most procurement teams eventually want to see on renewal. Many Canadian SaaS companies start with Type I to close the deal in front of them, then roll straight into a Type II observation window.

Step 2: Run a Fixed-Scope Gap Analysis Before You Talk to an Auditor

The single biggest mistake founders make is engaging an audit firm before they know where the gaps are. Auditors are not supposed to help you build controls, and paying audit fees to discover you are not ready wastes both time and money. A proper gap analysis maps your actual environment, your cloud provider, your CI/CD pipeline, your access management, your vendor list, against the Trust Services Criteria and produces a prioritized punch list. This is where traztech's compliance readiness work fits: a fixed-scope engagement that tells you exactly what is missing and what it will take to close it, before you commit to remediation or book an auditor.

Step 3: Close the Gaps That Are Specific to SaaS Products

SaaS companies tend to hit the same recurring gaps, and knowing them in advance saves weeks:

  • Access control sprawl. Engineers with standing production database access, shared admin credentials, and no formal offboarding process are the most common finding in early-stage SaaS environments.
  • Missing change management evidence. Code ships fast, but auditors want to see that changes are reviewed, approved, and tracked, usually through pull request approvals and deployment logs tied to a ticketing system.
  • Vendor and subprocessor management. If your product touches customer data through AWS, a payment processor, an email provider, or an analytics tool, each subprocessor needs a documented risk review and, often, its own SOC 2 report on file.
  • Incident response that exists only in someone's head. A written, tested incident response plan with defined roles and a communication path is a control auditors check for directly, not something you can improvise during the audit.
  • Logging and monitoring gaps. Centralized, tamper-resistant logging with alerting on anomalous access is frequently absent in companies that scaled engineering before security.

Each of these is closable in weeks, not months, but only if remediation is scoped against the specific gaps found in step 2 rather than a generic checklist.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us. See SOC 2 in 75 Days

Step 4: Hold the Controls Through the Observation Period

For a Type II report, the clock does not start until controls are actually operating, not just documented. This is the phase where companies stumble: a control that looked good on paper during remediation quietly lapses because nobody assigned an owner to run it monthly. Building a lightweight internal cadence, quarterly access reviews, monthly vendor checks, logged incident response tabletop exercises, is what keeps the observation period clean and avoids exceptions showing up in the final report.

Step 5: Engage an Independent CPA Firm for the Attestation

SOC 2 is an attestation issued under AICPA standards, and it must be performed by a licensed CPA firm independent of whoever did your readiness work. This separation matters: a firm that built your controls cannot also be the one grading them, and enterprise buyers' security teams know to check for that conflict. traztech's role is the readiness side, the fixed-scope gap analysis and remediation coordination, not the attestation itself. Once your environment is audit-ready, we help coordinate the handoff to an independent CPA firm so the report carries the credibility your buyers expect.

Timeline: What to Actually Tell Your Sales Team

For a B2B SaaS company with reasonably modern infrastructure (cloud-hosted, CI/CD in place, no legacy on-prem systems), a realistic timeline looks like: two to three weeks for the gap analysis, four to eight weeks for remediation depending on team bandwidth, then either an immediate Type I audit (one to two weeks with the CPA firm) or a three-to-twelve month Type II observation window. If your enterprise deal has a hard deadline, say to your sales team: Type I first to unblock the signature, Type II in progress for the renewal conversation. Trying to compress a Type II observation period below three months is not credible to sophisticated buyers and most CPA firms will not attest to it.

The Canadian Angle: PIPEDA, Quebec Law 25, and Selling South of the Border

Canadian SaaS companies carry an extra layer that US-only competitors do not: PIPEDA obligations federally, and Quebec's Law 25 if you have Quebec users or are headquartered in the province. SOC 2 does not replace these obligations, but a well-run readiness process often surfaces the same gaps, data mapping, breach notification procedures, vendor agreements, that PIPEDA and Law 25 compliance also require. Companies based in Toronto, Waterloo, Ottawa, Vancouver, Calgary, or Montreal selling into the US should treat the SOC 2 process as an opportunity to close both the enterprise procurement gap and the domestic privacy gap in one pass, rather than running two separate projects a year apart.

What Enterprise Buyers Actually Ask to See

Beyond the report itself, sophisticated buyers' security teams typically want: the specific Trust Services Criteria covered, whether it is Type I or Type II, the observation period dates, any exceptions noted in the report, and a bridge letter if the report is more than a few months old. Being able to answer these questions precisely, rather than just forwarding a PDF, is often what actually moves a stalled deal through legal review.

Get a Clear Picture of Where You Stand

If a deal, a board, or a renewal deadline is putting SOC 2 on your roadmap, the fastest way to de-risk the timeline is to know exactly where your gaps are before you commit to a date. traztech runs a fixed-scope gap analysis for B2B SaaS companies, then scopes remediation and coordinates the independent CPA audit, so you are not guessing your way through your first attestation. Book a free readiness call to get a clear picture of your current gaps and a realistic timeline, or contact traztech to talk through your specific deal pressure and deadline.

What the Auditor's Evidence Request Actually Looks Like

Founders picture the audit as a conversation. It is closer to a document production exercise. The CPA firm sends a request list, usually somewhere between 60 and 150 line items depending on how many criteria you scoped, and each line names a specific artifact with a date range. You will be asked for a system description of your product and infrastructure, an org chart, your list of in-scope systems, a population of every code change deployed to production during the period, a population of every user with access to production, evidence of onboarding and offboarding for a sample of employees, your vendor list with supporting security reports, your risk assessment, your incident log even if it is empty, and screenshots or exports showing configuration settings such as MFA enforcement and encryption at rest.

The word that causes the most pain on that list is population. A population is the complete set of things that happened during the period, and the auditor selects samples from it. If you deployed 1,400 times in a six month window, the auditor does not want 1,400 pull requests, they want a clean export of all 1,400 so they can pick 25 of them and ask you to show the approval on each. Teams that cannot produce a complete, reconcilable population are the ones whose audits stall, because the auditor cannot sample from a list they do not trust. Before your observation period starts, prove you can export three populations on demand: production deployments, production access grants and revocations, and employee joiners and leavers. If any of those requires someone to piece a spreadsheet together by hand, fix it while it is cheap.

How Sampling and Exceptions Really Work

Sample sizes follow the frequency of the control rather than the size of your company. A control that runs daily typically draws a sample of around 25, weekly draws around 8, monthly draws 2 or 3, quarterly draws 2, and annual draws 1. That arithmetic has a practical consequence founders rarely think through: quarterly access reviews are far cheaper to pass than continuous ones, because there are only two items to evidence. Choose control frequencies you can actually sustain, then write the policy to match what you do. Writing "access is reviewed monthly" in a policy and then reviewing it twice a year is not a documentation problem, it is an exception.

An exception is what happens when the auditor tests a sample and finds one that does not hold up. One offboarded contractor whose GitHub access lingered for eleven days is enough. Exceptions are not automatically fatal, and a report with a small number of clearly described exceptions plus a management response is still a usable report. What matters to buyers is the pattern. A single access revocation missed once reads as human error. Three exceptions across access, change management, and monitoring reads as a company that does not operate its controls, and that is the version that gets escalated by the buyer's security team.

The other thing to understand before you sign is the subservice organization treatment. Your report will either carve out your infrastructure providers or include them. Nearly everyone carves out AWS, GCP, or Azure, which means your report explicitly states that the provider's controls are excluded and the buyer should read the provider's own report alongside yours. Related to this are complementary user entity controls, the list at the back of the report describing what your customers must do for your controls to work, such as configuring SSO or managing their own admin users. Buyers read that list, so keep it short and honest rather than using it as a place to offload your own responsibilities.

Cost Drivers Nobody Warns You About

The audit fee is usually the smallest line. The larger costs sit around it. Compliance automation platforms run in the low five figures annually and are worth it if you have a lot of employee endpoints and cloud accounts to track, and close to worthless if you have eight employees and one cloud account, because you will spend more time feeding the tool than the tool saves. An annual penetration test is not formally required by the AICPA, but most enterprise buyers ask for one and most auditors expect to see evidence that you assess vulnerabilities somehow; our own published penetration testing floor starts at $1,000 depending on scope, and application scope is what drives that number, not company size.

The costs that actually surprise people are internal. Engineering time is the big one, and it is concentrated in the remediation phase rather than spread evenly. Expect one senior engineer at roughly half time for four to six weeks. Then there is the tooling you add to satisfy a control and pay for forever: SSO seats priced per user, a log retention tier you did not previously need, endpoint management on every laptop. Finally there is the cost of scope creep. Every additional criterion you add, every product line you include, and every cloud account in scope multiplies the evidence you produce for the rest of the company's life, not just this year. Scope narrowly and honestly. You can widen next year.

Auditor selection is a real cost lever, and it is worth doing properly rather than taking the first referral from your compliance platform. Ask each firm how many SaaS clients of your size they attested last year, who actually performs the fieldwork, what their sampling approach looks like, and what happens if an exception appears mid-period. Ask for the fee split between the readiness-adjacent work and the attestation itself. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which is a reminder that auditors price uncertainty; the more precisely you can describe your control environment before the proposal, the less risk premium they build in. We wrote up how that vetting conversation ran in our auditor vetting case study.

When SOC 2 Is the Wrong Purchase

There are three situations where we tell SaaS founders to hold off, and we would rather say it here than on a sales call.

The first is when one prospect asked and you have not tested whether they will accept an alternative. Plenty of mid-market buyers will sign with a completed security questionnaire, a documented policy set, evidence of MFA and encryption, and a commitment in the contract to obtain SOC 2 within twelve months. Ask the buyer's security contact directly what would unblock signature today. If the answer is a questionnaire and a roadmap, spend $0 on attestation this quarter and put the money into the controls themselves.

The second is when your buyers are primarily European, British, or Australian, or when you sell into regulated sectors that name a different standard. In those markets ISO 27001, with its 93 Annex A controls plus clauses 4 to 10, is the more recognized certificate, and running both at once early is an expensive way to look thorough. Pick the one your pipeline actually asks for.

The third is when the product is still changing shape every month. Attesting to controls over a system you are about to rearchitect means re-describing the system, re-scoping, and often re-testing. If you are pre product-market fit and the enterprise deal is speculative rather than in contract, the honest answer is that a gap analysis and a handful of fixed basics will serve you better than a report.

A fourth, smaller case: if you have a competent security-minded engineer with spare capacity and no hard deadline, you can genuinely run readiness yourselves. The material is public and the controls are not exotic. What outside help buys is speed and the avoidance of rework, which matters when a deal has a date on it and not much otherwise. If the deadline is real, our fixed-scope track and ongoing retainer exist to hold the calendar rather than to teach you something you could read.

Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.

See SOC 2 in 75 DaysOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.