How to get SOC 2 certified in 90 days
SOC 2 Type I is achievable in 90 days for most early-stage SaaS companies. This guide covers the full process: scoping, policy writing, control implementation, evidence collection, auditor selection, and report delivery. No fluff — just what you actually need to do and in what order.
Scope your SOC 2
- 1.Define which Trust Service Criteria you're pursuing. Security (CC) is required. Availability, Confidentiality, Processing Integrity, and Privacy are optional — pick based on what your customers ask for.
- 2.Define your system in scope. Most startups scope: production infrastructure, code deployment pipeline, and the tools that access customer data (identity provider, cloud console, support tools).
- 3.Identify your service commitments — what have you promised customers in your MSAs and DPAs? These drive your applicable criteria.
- 4.Choose Type I (point-in-time) or Type II (6–12 month observation period). For a first audit and investor due diligence, Type I is acceptable and faster.
Write your policies
- 1.You need at minimum: Information Security Policy, Access Control Policy, Acceptable Use Policy, Incident Response Plan, Change Management Policy, Vendor Management Policy, and a Business Continuity Plan.
- 2.Policies don't need to be long — a 1-page Information Security Policy is better than a 30-page one nobody reads. Write what you actually do, not what you aspire to do.
- 3.Assign a policy owner and review date. Auditors will ask who owns each policy and when it was last reviewed.
- 4.Have legal review your privacy-related policies (Privacy Policy, Data Retention Policy) before finalizing.
Implement missing controls
- 1.Run a gap assessment (use our free SOC 2 Readiness Checklist) to find what's missing. Prioritize: MFA across all systems, centralized access management, vulnerability scanning, and automated backups.
- 2.Enable MFA on every system: SSO/identity provider, cloud consoles (AWS, GCP, Azure), GitHub, Slack, support tools. This is the single most-checked control.
- 3.Set up centralized logging. CloudTrail (AWS) or Cloud Audit Logs (GCP) count. You need to show logs from production systems are being collected and retained.
- 4.Schedule a vulnerability scan. Automated scanning tools (Tenable, Qualys, or even GitHub Dependabot) generate evidence. Run one and document the findings and remediation plan.
Collect evidence
- 1.Evidence is documentation that your controls were operating. Start collecting now: screenshots of MFA settings, access review logs, backup configuration screens, security training completion records.
- 2.For Type I, you need to show controls were in place at a point in time. For Type II, you need evidence over a period. Either way, more is better — auditors want breadth.
- 3.Create a shared folder (Google Drive, SharePoint) organized by Trust Service Criterion. Label everything clearly.
- 4.Complete a security awareness training for all employees and document who completed it and when. Many platforms have free options (KnowBe4 free tier, Google security training).
Select and engage an auditor
- 1.Get quotes from 3–5 auditors. Price range for Type I: $15,000–$40,000. Faster turnaround and more complex scopes cost more. For Type II, budget $25,000–$60,000.
- 2.Ask specifically: What's the report delivery timeline? Will they do a readiness review before the formal audit? What format is evidence collection (portal vs. email vs. shared drive)?
- 3.Avoid the largest firms for first SOC 2s — they're slower and more expensive. Mid-tier firms (Schellman, Dansa D'Arata, Prescient Security, Sensiba San Filippo) are faster for startups.
- 4.Sign the engagement letter and schedule the kickoff. Auditors typically need 4–6 weeks from kickoff to report for Type I.
Audit execution and report
- 1.Respond to auditor evidence requests promptly. Delays here push your report delivery date — auditors have queues.
- 2.If the auditor finds an exception (a control that was supposed to be operating but wasn't), don't panic. Include a management response in the report explaining what happened and what you've fixed. A clean management response is better than a modified opinion.
- 3.Review the draft report carefully before signing off. Check that your system description accurately reflects how your product works.
- 4.Once the report is issued, share it with prospects under NDA. The SOC 2 report is a sales tool — it shortens procurement cycles with enterprise customers.
Check your SOC 2 readiness now
Free tool — check off controls you have in place and get a readiness score, category breakdown, and prioritized gap list. Takes 5 minutes.
Run free SOC 2 readiness check →Frequently asked questions
Can we get SOC 2 certified in 90 days if we've never done compliance before?
Type I yes, if you start immediately and have no major control gaps. Type II requires a minimum 6-month observation period, so the earliest you can complete Type II from scratch is 8–9 months.
How much does SOC 2 cost?
Auditor fees for Type I run $15,000–$40,000. Type II is $25,000–$60,000. Add $5,000–$15,000 for tools if you buy a compliance platform. Total first-year cost: $20,000–$55,000 for Type I.
Do we need a compliance platform like Vanta or Korrali Trust?
Not technically — you can do SOC 2 manually with spreadsheets and a shared drive. But compliance platforms reduce the audit cost by shortening evidence collection from weeks to hours. Korrali Trust is $299/mo vs Vanta's $6,000+/yr.
What's the difference between SOC 2 Type I and Type II?
Type I: auditor evaluates your controls as of a specific date (like a snapshot). Faster to obtain, less rigorous. Type II: auditor evaluates whether controls operated effectively over a 6–12 month period. More valuable to enterprise customers.
Which auditor should we use?
For first-time SOC 2: look for a mid-tier CPA firm that specializes in tech companies. Ask for references from SaaS companies at your size. Avoid the Big 4 for startup-stage audits — they're slow and expensive for smaller scopes.
Korrali Trust connects to your GitHub, AWS, and Okta to collect SOC 2 evidence automatically, and generates policy documents from your actual governance setup. At $299/mo — less than 1% of audit cost.
Start free trial →