Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

How SOC 2 Renewal Actually Works

Direct answer: Start roughly three months before your current observation window closes. Renewal is not a new audit, it is the next observation period, and the main risk is a gap in coverage between one report ending and the next being issued.

The timeline

Three months out, confirm scope with your auditor and flag any material change. One month out, run an internal check that every control has a complete evidence record for the period. Window closes. Fieldwork runs for a few weeks. The report is issued some weeks after that.

That last stretch is the gap. Your previous report has expired in the eyes of a strict reviewer and the new one has not landed. This is exactly what a bridge letter covers, and knowing the dates in advance means you can send one before a customer asks.

What your auditor will want

An updated system description reflecting any change to infrastructure, subprocessors or scope. Evidence covering the full period rather than a snapshot. Remediation status for any prior-period exception. Updated policies with review dates inside the window.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild. See how a retainer works

Where renewals slip

Evidence gaps in months three to eight. Nobody notices at the time because nobody is looking, and it cannot be recreated afterwards. If your access reviews were quarterly and you have three of four, that is an exception you cannot fix retroactively.

The other one is scope creep. A product launched during the period that handles customer data is either in scope, in which case its controls needed to operate all year, or explicitly out, in which case the system description has to say so.

Changing auditors at renewal

Possible and sometimes sensible, but it adds time. A new firm has to understand the environment and will usually want more evidence in the first cycle. If you are moving because of price, get the readiness position clean first, because a well-prepared client is cheaper to audit and that is where the quote actually moves.

We coordinate renewals as part of auditor management, including running the internal check before the window closes rather than after.

Working backwards from the report date

Most teams plan forward from today and end up surprised. Plan backwards from the date a customer will ask for the current report instead.

Report issued is the date you care about. Fieldwork typically runs two to four weeks, and the report follows two to six weeks after that, depending on the firm and how clean the evidence is. So the report lands roughly one to two and a half months after your window closes. If you need a current report in hand for a renewal in March, the window needs to have closed in January at the latest, which means the whole preceding period was the audit.

That arithmetic is why renewal planning is really window planning. By the time you are thinking about renewal, the evidence that will be sampled has mostly already been produced or missed.

Changing scope at renewal

Renewal is the natural point to change what the report covers, and there are usually two pressures. Buyers asking for an additional trust services criterion, most often Availability or Confidentiality. And products or environments launched during the year that customers now assume are covered.

Adding a criterion is not free. Availability brings recovery infrastructure and recovery testing into sampling. Confidentiality brings data classification and handling. Each addition is a set of controls somebody operates every week for the life of the report, so add the ones your buyers actually ask about and no more.

Bringing a new product into scope needs the controls to have been operating across the period, not just at the point you decided to include it. This is the same trap as the observation window start date, one level up.

Changing auditors at renewal

Renewal is also when firms get switched, usually over price or responsiveness. It is worth doing carefully. A new firm will re-examine your system description and may take a different view on scope, sampling, or what evidence satisfies a control, which can surface work you thought was settled.

If you are considering it, get quotes on identical written scope and compare the assumptions rather than the totals. Across four firms quoting one scope on a recent engagement, the highest number was 2.1 times the lowest, and most of that spread was assumptions rather than quality.

What to do in the last month before the window closes

Run an internal check per control: is there evidence covering the whole period, is it dated, is it filed against the control it proves, and would somebody outside your company understand what it demonstrates. Fix what you can honestly fix, and document what you cannot rather than hoping it goes unsampled.

Confirm the system description is current. Confirm every prior-period exception has closure evidence. Confirm the people named in the description still work there and still hold those roles, because auditors do check.

Handling the gap

Between your previous report expiring in a reviewer's eyes and the new one being issued, expect questions. Prepare a bridge letter before anyone asks, keep it with the report, and make sure whoever answers security questionnaires has both. Being able to send the pair within an hour of a request is the difference between a procurement delay and a non-event.

Teams that run this well do not experience renewal as an event at all. The evidence is current, the window closes, fieldwork is a review, and the report arrives on a date they predicted six months earlier. That state is the whole point of operating the programme continuously rather than reassembling it each year.

Renewal when something went wrong during the year

The clean case is easy. The interesting cases are the ones where the year did not go to plan, and they are more common than the guidance usually admits.

You had an incident. Disclose it and be ready to show what happened, what you did, and what changed afterwards. Auditors are not scandalised by incidents; they are scandalised by incidents that produced no corrective action. An incident with a documented response, a root cause and a control improvement often strengthens the report rather than weakening it.

A control lapsed for part of the period. Document the gap with dates and cause, and raise it early. An exception you brought forward reads very differently from one the auditor found. In some cases the scope of the exception can be limited by evidence showing the compensating controls that were operating.

You lost the person who ran it. Reconstruct what you can, write down what you cannot, and expect fieldwork to be longer. This is also the moment to fix the structural problem, because the same thing will happen again otherwise.

The environment changed substantially. A migration or a re-platform mid-period is a description problem more than a control problem. Get the description right, be clear about which controls operated on which infrastructure and when, and let the auditor scope the sampling accordingly.

What renewal costs

Audit fees are driven by scope, headcount, criteria count and the auditor's assessment of how much work your evidence will require. That last factor is the one you control, and it is not small: disorganised clients take longer to audit and firms price the uncertainty in.

The readiness side usually drops sharply in renewal years, because you are maintaining rather than building. Where it does not drop is when the programme went dark for nine months, at which point renewal preparation looks a lot like a second readiness project and costs accordingly.

Coordinating renewal with other frameworks

If you also hold ISO 27001, the two cycles are separate obligations with separate dates and heavily overlapping evidence. Running them from one calendar, with evidence collected once and mapped to both control sets, removes most of the duplicated work. What does not overlap is the ISO management system: internal audit and management review have no SOC 2 equivalent and are frequently the source of surveillance findings.

Where companies get into difficulty is running the two programmes from different owners in different systems, which produces two sets of evidence that disagree in small ways. Auditors notice disagreement.

A renewal checklist

Three months out: confirm scope and criteria with the auditor, flag material changes, confirm the fieldwork dates, and check the report issuance estimate against any customer commitment.

Two months out: internal evidence review per control across the full period, remediate what can honestly be remediated, and update the system description.

One month out: prior-period exception closure evidence assembled, walkthrough participants briefed, access for the audit team arranged, and the bridge letter drafted for the coming gap.

Window closes: stop changing things you do not have to change, and hand over a complete evidence package rather than a folder.

After the report: read the exceptions, assign owners with dates, and start the next period deliberately rather than drifting into it.

Bridge Letters, and What They Cannot Do

The bridge letter, sometimes called a gap letter, is widely misunderstood. It is written and signed by you, not by your auditor. It says that between the end of the report period and the date of the letter, management is not aware of any material change to the control environment, and it lists any changes that did occur. It is a management assertion, and its credibility rests entirely on your organisation rather than on the audit firm.

That means two things. A bridge letter cannot extend assurance, so a reviewer who insists on a report covering the current date is not going to be satisfied by one, and arguing the point wastes goodwill. And it should not cover an unreasonable stretch. Three months is normal, four is defensible, and beyond that most vendor risk teams stop accepting it, which is exactly when your gap arithmetic starts costing you deals.

Write it before anyone asks, have it signed by whoever signs your management assertion, store it with the report, and refresh the date on a schedule rather than on request. If a material change did happen, say so. A letter that quietly omits a migration or a new subprocessor is worse than none, because a diligent reviewer may later compare it against your next system description.

Subservice Organisations and the Carve-Out Decision

Every report treats the providers you depend on in one of two ways. The carve-out method excludes their controls from your scope and states that your report does not cover them. The inclusive method brings them inside, which almost nobody does because it requires the provider's cooperation. Nearly all startup reports are carve-out, and that is fine.

The part teams forget at renewal is the obligation that comes with it. Carving out a subservice organisation means you are relying on their controls, and you are expected to monitor that reliance: obtain their current report, read it, check the opinion, and act on any exceptions relevant to you. Auditors sample this. The evidence is a dated record showing you reviewed each provider's report during the period, with a note of what you concluded, not a folder of PDFs downloaded the week before fieldwork.

The provider list also changes without anyone telling compliance: an analytics tool that receives customer data, an AI vendor added by a product team, a payment provider swapped mid-year. Each is a system description change and possibly a customer notification obligation under your own contracts. Reconciling the vendor register against actual spend once a quarter catches most of it and feeds the wider compliance programme rather than only the audit.

Watch the complementary user entity controls section in each provider's report too. That is the list of things the provider assumes you are doing, and mapping it to your own controls is a short exercise that removes an entire class of fieldwork questions.

Reading Your Own Report Like a Buyer Does

Most teams file the report and never read section four, which is the part your customers' security reviewers read first. Learn to read it the way they do.

An exception is a specific instance where a control did not operate as described. A qualified opinion is the auditor concluding that controls were not suitably designed or did not operate effectively for one or more criteria. These are very different in commercial effect. A handful of exceptions with clear management responses is normal and rarely blocks a deal. A qualification prompts questions from every reviewer for the life of the report.

A good reviewer checks the period covered, the opinion, exceptions and whether management responses describe a fix with a date, the subservice organisations listed, the criteria included, and whether the system description matches the product they are buying. Where reports fail commercially is almost never the security engineering. It is a description of an architecture the company no longer runs, or an exception whose management response says the issue is under review with no owner and no date.

Write your management responses as though a procurement analyst will read them without you in the room, because that is what happens. State what happened, what changed, and when it was completed. Vagueness generates questionnaires.

Window Length and the Type I Trap at Renewal

Companies that unblocked a deal with a Type I sometimes plan the following year as another Type I, usually because it is cheaper. Buyers treat a second Type I as a signal that the controls never actually operated, and it is a hard signal to argue with. If you issued a Type I, plan the Type II window to start immediately rather than a few months later, since the months you leave uncovered are months you cannot retroactively evidence.

Window length is the other lever. A first Type II often covers three or six months, which is a reasonable way to get a report in hand sooner. From renewal onward, twelve months is the norm, and buyers increasingly expect it. Moving from six to twelve is not just a longer wait: it doubles the population from which the auditor samples, which means a control you operated diligently in the last quarter and sporadically in the first will now show that.

The controls that expose this most reliably are the periodic ones: access reviews, vendor reviews, policy acknowledgements, awareness training, backup restoration tests, risk assessment. Each is scheduled, each leaves a dated artefact, each is trivial to sample. Put them on a calendar with named owners and let the calendar be the control. That is the difference between a renewal that is a review and one that is a rebuild, which is what continuous retainer work exists to prevent, and it is the same drift pattern we wrote about in control drift between audits.

When You Should Not Renew

Renewal is treated as automatic, and for some companies it should not be. It is worth asking the question honestly once a year, before the spend is committed.

If nobody asked for the report during the period, that is data. Check your CRM: how many deals named SOC 2 as a requirement, and how many were won or lost on it. Companies that bought a report speculatively for a market that never demanded it pay a five-figure annual cost for a document sitting in a folder. Selling to small businesses, to consumers, or to buyers who accept a questionnaire and a contractual security addendum are all cases where letting it lapse and revisiting when demand appears is the honest answer.

If the report is the wrong artefact for your market, switch rather than renew. Selling into UK and European enterprises frequently produces demand for ISO 27001 instead, and running both because you started with SOC 2 doubles the cost for buyers who only ever ask for one. Regulated healthcare and payments buyers often want something else again, and a certificate nobody asked for is not credibility, it is overhead.

If the company has fundamentally changed, pause instead of renewing badly. A re-platform, an acquisition, or a pivot mid-period can make the coming report describe a system that no longer exists. Sometimes the better move is a short window starting after the change lands, accepting a coverage gap you explain to customers directly, rather than a twelve month report full of exceptions from an environment you abandoned.

And if the only reason you are renewing is that you renewed last year, cut the criteria back to what buyers ask for. Availability and Confidentiality added speculatively cost real operational work every week for the life of the report. Dropping one at renewal is allowed and is not a black mark. Our readiness prices are published precisely so this arithmetic can be done without a sales call.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild.

See how a retainer worksOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.