Guide · SOC 2

How to get SOC 2 certified in 90 days

SOC 2 Type I is achievable in 90 days for most early-stage SaaS companies. This guide covers the full process: scoping, policy writing, control implementation, evidence collection, auditor selection, and report delivery. No fluff — just what you actually need to do and in what order.

Week 1–2

Scope your SOC 2

  • 1.Define which Trust Service Criteria you're pursuing. Security (CC) is required. Availability, Confidentiality, Processing Integrity, and Privacy are optional — pick based on what your customers ask for.
  • 2.Define your system in scope. Most startups scope: production infrastructure, code deployment pipeline, and the tools that access customer data (identity provider, cloud console, support tools).
  • 3.Identify your service commitments — what have you promised customers in your MSAs and DPAs? These drive your applicable criteria.
  • 4.Choose Type I (point-in-time) or Type II (6–12 month observation period). For a first audit and investor due diligence, Type I is acceptable and faster.
Week 2–4

Write your policies

  • 1.You need at minimum: Information Security Policy, Access Control Policy, Acceptable Use Policy, Incident Response Plan, Change Management Policy, Vendor Management Policy, and a Business Continuity Plan.
  • 2.Policies don't need to be long — a 1-page Information Security Policy is better than a 30-page one nobody reads. Write what you actually do, not what you aspire to do.
  • 3.Assign a policy owner and review date. Auditors will ask who owns each policy and when it was last reviewed.
  • 4.Have legal review your privacy-related policies (Privacy Policy, Data Retention Policy) before finalizing.
Week 4–6

Implement missing controls

  • 1.Run a gap assessment (use our free SOC 2 Readiness Checklist) to find what's missing. Prioritize: MFA across all systems, centralized access management, vulnerability scanning, and automated backups.
  • 2.Enable MFA on every system: SSO/identity provider, cloud consoles (AWS, GCP, Azure), GitHub, Slack, support tools. This is the single most-checked control.
  • 3.Set up centralized logging. CloudTrail (AWS) or Cloud Audit Logs (GCP) count. You need to show logs from production systems are being collected and retained.
  • 4.Schedule a vulnerability scan. Automated scanning tools (Tenable, Qualys, or even GitHub Dependabot) generate evidence. Run one and document the findings and remediation plan.
Week 6–8

Collect evidence

  • 1.Evidence is documentation that your controls were operating. Start collecting now: screenshots of MFA settings, access review logs, backup configuration screens, security training completion records.
  • 2.For Type I, you need to show controls were in place at a point in time. For Type II, you need evidence over a period. Either way, more is better — auditors want breadth.
  • 3.Create a shared folder (Google Drive, SharePoint) organized by Trust Service Criterion. Label everything clearly.
  • 4.Complete a security awareness training for all employees and document who completed it and when. Many platforms have free options (KnowBe4 free tier, Google security training).
Week 8–10

Select and engage an auditor

  • 1.Get quotes from 3–5 auditors. Price range for Type I: $15,000–$40,000. Faster turnaround and more complex scopes cost more. For Type II, budget $25,000–$60,000.
  • 2.Ask specifically: What's the report delivery timeline? Will they do a readiness review before the formal audit? What format is evidence collection (portal vs. email vs. shared drive)?
  • 3.Avoid the largest firms for first SOC 2s — they're slower and more expensive. Mid-tier firms (Schellman, Dansa D'Arata, Prescient Security, Sensiba San Filippo) are faster for startups.
  • 4.Sign the engagement letter and schedule the kickoff. Auditors typically need 4–6 weeks from kickoff to report for Type I.
Week 10–12

Audit execution and report

  • 1.Respond to auditor evidence requests promptly. Delays here push your report delivery date — auditors have queues.
  • 2.If the auditor finds an exception (a control that was supposed to be operating but wasn't), don't panic. Include a management response in the report explaining what happened and what you've fixed. A clean management response is better than a modified opinion.
  • 3.Review the draft report carefully before signing off. Check that your system description accurately reflects how your product works.
  • 4.Once the report is issued, share it with prospects under NDA. The SOC 2 report is a sales tool — it shortens procurement cycles with enterprise customers.

Check your SOC 2 readiness now

Free tool — check off controls you have in place and get a readiness score, category breakdown, and prioritized gap list. Takes 5 minutes.

Run free SOC 2 readiness check →

Frequently asked questions

Can we get SOC 2 certified in 90 days if we've never done compliance before?

Type I yes, if you start immediately and have no major control gaps. Type II requires a minimum 6-month observation period, so the earliest you can complete Type II from scratch is 8–9 months.

How much does SOC 2 cost?

Auditor fees for Type I run $15,000–$40,000. Type II is $25,000–$60,000. Add $5,000–$15,000 for tools if you buy a compliance platform. Total first-year cost: $20,000–$55,000 for Type I.

Do we need a compliance platform like Vanta or Korrali Trust?

Not technically — you can do SOC 2 manually with spreadsheets and a shared drive. But compliance platforms reduce the audit cost by shortening evidence collection from weeks to hours. Korrali Trust is $299/mo vs Vanta's $6,000+/yr.

What's the difference between SOC 2 Type I and Type II?

Type I: auditor evaluates your controls as of a specific date (like a snapshot). Faster to obtain, less rigorous. Type II: auditor evaluates whether controls operated effectively over a 6–12 month period. More valuable to enterprise customers.

Which auditor should we use?

For first-time SOC 2: look for a mid-tier CPA firm that specializes in tech companies. Ask for references from SaaS companies at your size. Avoid the Big 4 for startup-stage audits — they're slow and expensive for smaller scopes.

Korrali Trust connects to your GitHub, AWS, and Okta to collect SOC 2 evidence automatically, and generates policy documents from your actual governance setup. At $299/mo — less than 1% of audit cost.

Start free trial →