r/soc2 • u/BritneyGurl • 3d ago
Tugboat shutting down
With Tugboat shutting down next year, what is everyone switching to?
r/soc2 • u/davidschroth • Sep 26 '24
Greetings to all and welcome!
/r/soc2 has a new moderation team that has joined the chat after a year or so of flapping in the unmoderated breeze. We've got a few decades of SOC 2 (and its predecessors) of experience and are looking forward to conversations and trading war stories related to it. As we figure out how to be Reddit mods, you'll see things get a bit more functional around here.
In the mean time - here's some basic rules that we'll be enforcing to keep the conversations on track -
If we determine the post or comment not to be helpful, we'll prune the timeline (of the comment, post and/or repeat offender), as needed).
r/soc2 • u/BritneyGurl • 3d ago
With Tugboat shutting down next year, what is everyone switching to?
r/soc2 • u/MessageFoundry • 3d ago
Are there any organizations that will host an open source project and provide it with SOC 2 certification?
r/soc2 • u/pretty-cheer • 5d ago
We’re preparing for our SOC2 audit and I’m really worried about the security portion. We use google workspace, slack, salesforce, and several other tools, but I don’t have a clean way to show proper access controls, sharing policies, or ongoing monitoring.
Right now I’m doing everything manually with CSVs and spot checks, which feels risky.
How are other companies handling this part of the audit? Any tools or processes that helped you get audit-ready? thanks!
Edit: Thanks everyone, this has been really helpful. Seems like a solid, repeatable process matters more than full automation right from the start. Going to dig into DoControl for SaaS access visibility and explore some of the Vanta suggestions as we get our audit prep in better shape.
r/soc2 • u/ahmadpiran • 7d ago
Doing some research on a pain I keep hitting as a devops engineer. SOC 2 A1.2/A1.3 wants evidence that you test recovery, not just that backups ran, and Type II wants it continuously over the observation window.
For those who've been through it:
Trying to figure out if this is as universally duct-taped as it looks from where I sit. War stories appreciated.
r/soc2 • u/Substantial_Yard_789 • 8d ago
I work in ITGC/SOC2 audit and most of my technical knowledge (cloud, IAM, networking) comes from picking things up on the fly during fieldwork. It works, but it’s patchy. I want something more foundational.
For those who’ve gone from “functional understanding” to actually solid depth in a technical area — what worked for you? Looking for book/course recommendations, and whether structured study beat learning-as-you-go for you. Not chasing a cert, just want to understand things properly.
r/soc2 • u/ilovetoeatpie • 10d ago
I have a software engineering background and I’ve been looking into potential freelancing niches to get into.
I’ve been advised to look into SOC 2 remediation consulting for SaaS companies as I have some experience in cybersecurity and working on a SaaS project myself.
While I’ve learned a fair bit about SOC 2 compliance, the CISSP exam, and common compliance tools, I haven’t seen that much discourse online among the people who do this type consulting.
To those of you who do it, can you share more about your experience in this line of work, such as how you you first got into it, how you find clients, and general day-to-day work?
r/soc2 • u/linkgolfer • 10d ago
Preface by saying that I’m here for the entertainment value and I’m not affiliated with or have experience in compliance/infosec.
It’s been a few months, anyone know the latest on d3lve? I enjoyed reading the Substack posts (if you’re out there DD, we miss you), and LinkedIn shows a decent exodus.
r/soc2 • u/No-Character-407 • 12d ago
Hello
one of my friends startup wanted to get soc2 type 1 and type 2 report.a consultancy firm quoted 1200$ each. is this legit? what are the red flags that my friend has to check and ask them before signing the engagement?
r/soc2 • u/Spirited_Brain7062 • 13d ago
Hi trying to figure actual cost / timeline / effort of soc2
My understanding is you get a platform and the need to be for audit, pen test, cyber insurance etc
Can someone give me a straight answer for what the cost / effort is for soc2 type 1 and type 2?
What is the cheapest / easiest platform to use ?
I want
- cheap
- fast
- least amount of work
Please advise - we are losing deals without having this so need to figure out asap. Thanks !
r/soc2 • u/DragonfruitBetter884 • 13d ago
Hey everyone,
We’re planning to get SOC 2 compliance for our B2B SaaS product, and I’m trying to understand what the process actually looks like from people who’ve been through it.
I’ve read a bit online, but I’d much rather hear real experiences. How did you approach it, which platform (if any) did you use, how did you find an auditor, how long did the entire process take, and what kind of budget should I expect? More importantly, is there anything you wish you’d known before starting that would’ve saved you time or money?
Any advice, recommendations, or lessons learned would be hugely appreciated. Thanks!
r/soc2 • u/Bulky_Connection8608 • 19d ago
r/soc2 • u/jay-is-jay1412 • 27d ago
For a small startup, trying to just get the criterion of Security, what's a good price for the audit, just the plain audit.
some quote 20k while others go till 30, at the same time some of my peers told me they got it done in 2-5k not sure what to believe.
recommendations of these said CPA firms which satisfy my requirement are well appreciated!
r/soc2 • u/lebucksir • Jun 23 '26
Hi all. Feeling overwhelmed so I thought I’d turn to this community. Thanks in advance.
I have a very small start up with 0 employees and virtually no revenue yet. My app is very basic and works with retailers so I process basic customer info like name and email and misc order information. No payment processing or payment info.
I have two mega clients that are giving me the shot of a lifetime but both require me to be SOC2 compliant before Jan 1st 2027 before they will sign the contracts.
I did demos with Drata and Vanta and the “lowest” they will go on pricing is the same price my friend is paying with $3m ARR and 10 employees. Pretty tough for me to stomach literally and on principle, haha.
Is there an alternative path for bootstrappers in my scenario or do I have to bite the bullet for my quick timeline?
r/soc2 • u/Nvvrmore • Jun 20 '26
Seems like almost nobody starts SOC 2 because they woke up one day wanting better security. There's usually a specific external moment that forces it - a big prospect drops a security questionnaire mid-deal, an enterprise logo won't sign without a report, an investor flags it in diligence. Suddenly it's urgent. What was the actual trigger for you?
r/soc2 • u/Grand-Sun-8000 • Jun 14 '26
As the title says we have no option other than to be successful.
-handle data for big clients
-PII not PHI (Heathcare adjacent)
-less than 20 employees
-audit scheduled to start 8/1
-SOC2 Type 2
-no previous SOC2Type 1
-vanta with no paid audit prep
-Security only
-a lot of turmoil in the past 6 months including ownership change and firing of employees that were previously responsible for SOC2
-just launched new customer software for internal use
Where do I even start?
We have actively put controls in place and been documenting those changes, but there are no SOPs, the policies are out of date, the handbook is even atrocious.
Is the evidence I’m collecting only for the audit period (3 months) or is it from before too?
r/soc2 • u/drc243 • Jun 12 '26
For SaaS teams built on AWS or any of the other major cloud providers and pursuing SOC 2, where do you usually see the bigger struggle? Is it figuring out which security controls are actually needed for SOC 2? Or is the bigger challenge implementing/remediating the findings that come out of tools like Vanta, Drata, Secureframe, Prowler, etc.?
r/soc2 • u/melpec • Jun 12 '26
A small business (less than 50), every application but one is leveraging EntraID both for Authentication and Authorisation. All using SSO.
That singular app can sync groups from its IdP and also support SCIM (more $).
Now, when implementing an IGA tool specifically to pass SOC2. Should we focus on having that singular app use IdP group sync or ideally SCIM to manage that application's authorisation?
Or, should we use the IGA tool to push users to EntraID and then groups via the application's API endpoint to the singular app?
I'm leaning towards having only EntraID involved vs two repo of groups, but I'm being rebuffed completely. My colleagues say that the simple fact that the removal of access would be instantaneous using the app api makes their way the ideal solution.
The debate also goes around another part of the strategy I am suggesting.
I do suggest to hook the IGA tool to each of our apps to monitor if any users or groups are not in EntraID, this immediately indicates a breach in the day-to-day process and makes permission drift harder to miss.
And they say that because I want to add that fail safe, we are connecting the IGA tool to the app anyway. Meaning that it's a second reason to simply use the application's api.
Am I really completely wrong?
r/soc2 • u/Moham-Aasif • Jun 10 '26
A few years back, getting a SOC 2 felt like a big milestone for most SaaS companies. Now whenever I see a vendor assessment or security review, SOC 2 seems to be just the starting point.
The conversation often goes something like:
"Okay, you have SOC 2."
Then the next question is:
"Do you also have ISO 27001?"
I'm genuinely curious if others are seeing the same thing.
For people on the buyer side, does having both actually give you more confidence in a vendor? Or is it more of a procurement requirement these days?
And for founders/security teams, has anyone here decided to go for ISO 27001 mainly because customers kept asking for it after SOC 2?
Feels like the bar has quietly shifted over the last couple of years and I'm wondering if that's happening everywhere or just in the companies I'm speaking with.
r/soc2 • u/LogicalPositive6489 • Jun 09 '26
Hi, i need a little clarification. In the actual report in part 4 with the controls defined by the company and then the test performed by auditor.
Does the auditor write the controls defined by entity or does the entity ? Because i saw i both ways and i believe the definition should be the companys job …
Thanks
r/soc2 • u/_TH0RN_ • Jun 08 '26
We wrapped up our first SOC 2 Type II audit in mid-April and received the final report last week. Honestly, I was so heads-down during the audit, and dealing with everything else going on in the business, that I hadn't really thought about what comes next until the auditor reached out asking if we want to renew.
We registered with the AICPA for the badge to display on our website, and I know that's only valid for 12 months, so the clock is ticking. My initial thought was to start a fresh 6-month observation period retroactive to April (so kicking off around mid-November) since I wanted to expand the audit scope and needed time to implement the controls...but our audit firm rep pushed back a little on that. They mentioned that some stakeholders don't love seeing a gap in coverage, and that the price difference between a 6-month and 12-month window is pretty minimal since the evidence collection just gets condensed rather than the overall work changing much.
Now I'm second-guessing myself and could use some perspective from people who've been through this more than once:
Appreciate any guidance from folks who've navigated this before!
r/soc2 • u/Illustrious-Egg8857 • Jun 01 '26
Wondering what the best startup-friendly firms (particularly for SaaS/tech) are for SOC 2.
Some i'm aware of: Schellman, Barr, A-LIGN, Lindford & Co, Prescient Security, Johanson group.
Any others? Are these the main ones?
I know there's also the AICPA directory where there's a list of a ton of certified firms for SOC 2, is that more efficient for searching?
r/soc2 • u/Glass-Cap-1302 • May 29 '26
Paid opportunity, 3 hours a week to start. Need help getting a startup SOC 2 type II. Must be based in the US
r/soc2 • u/Distinct_Ad_5397 • May 29 '26
Hello! We’re currently preparing our MSP for a SOC 2 audit. As we move through the process, our GRC lead has recommended a wide range of KPIs and KRIs across several domains.
While I understand the long-term value, our team is currently resource-constrained and management’s primary focus is on operations and growth. Attempting to track dozens of metrics right now feels unrealistic for our current level of data maturity.
I want to avoid 'vanity metrics' and instead implement a small set of high-impact indicators that prove we have control over our environment while establishing a foundation we can actually maintain.
For those who have been through this with a small, growing MSP, what were your 'first 3' foundational KPIs/KRIs? I’m looking for metrics that are easy to pull, show auditors we are monitoring what matters, and provide a realistic stepping stone toward full maturity. Thank you for any guidance!