SOC 2 vendors tell you it takes "6-8 weeks." That is the time for the audit itself. The actual end-to-end process, from deciding to pursue SOC 2 to holding a clean report in your hands, takes 4-9 months for most startups. Here is the week-by-week breakdown, including the two places the schedule usually slips. If you are working backwards from a customer deadline, the SOC 2 readiness checklist will show you how much of this you have already done.
Phase 1: Foundation (Weeks 1-4)
Week 1: Choose your compliance automation platform (Vanta, Drata, Secureframe, or Sprinto). They all do approximately the same thing. Pick based on price and integration support for your stack. Budget $10,000-$20,000/year.
Week 2: Connect the platform to your systems: AWS/GCP, GitHub, HR tools, identity provider, endpoint management. The platform will scan everything and generate a gap report. This report is your roadmap.
Week 3-4: Write your policies. You need 10-15 policies covering information security, access control, change management, incident response, risk assessment, vendor management, data classification, business continuity, and human resources security. Most compliance platforms provide templates. Customize them for your company. Do not just fill in the company name and call it done. Auditors will ask questions about your policies, and your answers need to reflect reality.
Phase 2: Control Implementation (Weeks 5-12)
This is the hardest phase. Your gap report will list 50-100 controls that need to be implemented or improved. Prioritize them by effort and risk.
Quick wins (Weeks 5-6):
- Enable MFA on all systems (1-2 days)
- Enable disk encryption on all employee devices (1 day)
- Set up centralized logging (2-3 days)
- Configure automated vulnerability scanning (1 day)
- Enable encryption at rest for all databases (1-2 days)
Medium effort (Weeks 7-9):
- Deploy endpoint detection and response (EDR) like CrowdStrike or SentinelOne (1 week)
- Implement SSO for all internal tools (1-2 weeks depending on tool count)
- Set up a change management workflow: all code changes require PR review (1 week)
- Build and test your incident response plan (1 week)
- Conduct initial access reviews for all systems (2-3 days)
Significant effort (Weeks 10-12):
- Implement a vendor management process and review all critical vendors (2 weeks)
- Set up business continuity and disaster recovery procedures (2 weeks)
- Conduct background checks for all employees (2-3 weeks, mostly waiting)
- Implement a security awareness training program (1 week)
Phase 3: Evidence Collection (Weeks 13-16)
For Type I, you need to demonstrate that controls exist at a point in time. Your compliance platform collects most evidence automatically: screenshots of MFA settings, logs of access reviews, code review approvals, encryption configurations.
For Type II, you need to demonstrate that controls are operating effectively over a period of time (minimum 3 months, typically 6). This means your controls need to be running for 3-6 months before the observation period ends. Plan accordingly.
Phase 4: Audit (Weeks 17-22)
Select an auditor. Costs range from $15,000 to $40,000. Smaller firms charge less but may take longer. Name-brand firms (Schellman, A-LIGN, Prescient Assurance) charge more but are recognized by enterprise buyers.
The audit itself takes 2-4 weeks. The auditor reviews evidence, interviews key personnel, and tests a sample of controls. They will ask your engineering lead about change management, your HR lead about onboarding, and your security lead about incident response.
Total timeline: Type I = 4-6 months. Type II = 6-9 months (including observation period).
Need help with SOC 2 compliance?
We run the whole readiness programme, from gap assessment through to handing your auditor evidence they can test, so your team stays focused on building product.
Book a free strategy callThe Two Places the Schedule Actually Slips
The first is human latency on things engineering cannot fix. Background checks sit in a vendor queue. Vendor security agreements sit in someone else's legal review. Your auditor's next available start date is set by their capacity, not your urgency. None of these respond to effort, and all of them are usually discovered in week nine when the plan assumed they were instant. Every one of them can be started in week one at almost no cost. If you do only one thing differently from the plan above, start the waiting items before you start the building items.
The second is evidence that cannot be created retroactively. A quarterly access review performed in month five proves nothing about month two. Change management evidence only exists if the pull request approvals were happening while the code shipped. Security awareness training completed the week before fieldwork gives the auditor a completion date that sits inside the observation window by three days. This is why the calendar drives the audit rather than the other way around: once you decide the window starts on the first of a month, every control inside it needs to be running by that date, and controls you turn on in week four of the window produce a partial-period sample that the auditor will either qualify or exclude.
Working Backwards From a Customer Deadline
Most people reading a timeline article have a date, not a curiosity. Build the plan backwards from it. Take the date the buyer needs a report in hand, subtract three to five weeks for the auditor to complete fieldwork and issue, and that gives you the date your observation window must close. For a Type II with a three month window, subtract another three months, and that is the date every control must already be running. Subtract remediation, and you have your real start date. Run that arithmetic before your first vendor call, because it usually reveals that the honest answer for a deadline inside ninety days is Type I now and Type II later, not a compressed Type II.
Be direct with the buyer about that split. Enterprise security reviewers deal with staged reports constantly and most will accept a Type I plus a written commitment to a Type II window with a stated end date. What they will not accept is a vague assurance that you are working on it. A one-page memo naming the criteria in scope, the auditor engaged, the window dates, and the expected issue date does more to keep a deal alive than three more weeks of remediation.
Book the Auditor Earlier Than Feels Necessary
Companies treat auditor selection as a late step because the audit is the last phase. That is backwards for two reasons. Lead times for a reputable firm run four to eight weeks and stretch further in the fourth quarter when everyone with a December window is scheduling at once. More importantly, the quote you get depends heavily on how prepared you look when you ask for it. Auditors price uncertainty. A vague inquiry describing a company that has not started gets priced with padding for the rework the audit firm expects. The same company, presenting a defined scope, a system description draft, a control matrix, and a named internal owner, gets priced as a predictable job. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we wrote up in our auditor vetting case study.
Ask every auditor you shortlist three questions: how many clients on your stack and size they issue for annually, who specifically will run fieldwork and how many concurrent engagements that person carries, and what their turnaround is between the last evidence request and the issued report. The third answer varies from two weeks to two months and nobody volunteers it.
Picking the Window Start Date
The observation window start date is a real decision and most teams default into it. Starting on the first of a month makes every monthly and quarterly control land cleanly inside the period, which simplifies sampling. Starting mid-month means your first quarterly access review may fall awkwardly and you end up performing an extra one to have coverage. Avoid a window that spans a planned migration, a major re-architecture, or the holiday period when half the team is away and the access review will be late.
Also decide early whether you want the window to end on a date that produces a report you can reuse. A report covering January through June, issued in July, ages through the rest of the year and the buyer in November is going to want a bridge letter. Aligning the window so the report issues shortly before your heaviest sales quarter is a small choice that saves real friction later.
What Actually Compresses the Timeline, and What Only Looks Like It Does
Real compression comes from a small number of things. Running remediation as a tracked engineering project with named owners and weekly review rather than a side task. Choosing a tight scope so you are evidencing one product and one environment instead of everything the company does. Assigning one person as the single point of contact for the auditor, because fragmented responses generate follow-up cycles that add days each time. Starting the waiting items on day one.
False compression comes from buying more tooling. A second platform does not shorten a three month observation window, and neither does paying for an expedited audit if the evidence underneath is thin. The other false economy is skipping the readiness review before fieldwork. Findings discovered by your own team in week eleven cost hours. The same findings discovered by the auditor in week nineteen cost a re-test, a schedule change, and sometimes an exception in the report. Our fixed-scope SOC 2 gap analysis starts at $3,000, and the whole point of it is to move discovery earlier in the calendar rather than later.
When the Date Is Already Impossible
Sometimes the arithmetic does not work and no amount of planning saves it. The options then, in order of how well they hold up: a Type I with a committed Type II window; a completed security questionnaire plus a current penetration test and your policy set, which satisfies a surprising number of mid-market buyers; or a written readiness statement from your prep firm describing scope, controls in place, and the audit schedule. What does not hold up is telling the buyer you are SOC 2 compliant because you use a compliance platform. Vendor risk reviewers ask for the report, and the answer that there is not one yet arrives late and damages the rest of the review.
When Not To Start This At All
If nobody has asked for SOC 2 and you are doing it because it seems like the responsible next step, wait. A first report costs tens of thousands of dollars across tooling, remediation, and audit fees by the time it is done, and the audit fee recurs annually. That money buys more security if spent on fixing what a threat model and a penetration test tell you is actually broken. If exactly one customer is asking and they are small, ask whether a questionnaire and evidence will close it, because often it will.
If you are a team of four with no dedicated security owner and a product still changing weekly, the controls will not hold through an observation window and you will pay for an audit that documents instability. Get the basics running for a couple of quarters first. We would rather scope you a fractional CISO arrangement for a few months and start the audit when the environment stops moving than sell you a readiness program that produces a report full of exceptions.
Doing this for a deal? SOC 2 in 75 Days is our fixed-scope readiness track, with the price and the timeline published before you call us.
See SOC 2 in 75 DaysOr talk about a retainer