How to prepare for SOC 2: the first 30 days
A customer asked for a SOC 2 report and nobody in the building has done one. This is what the next four weeks look like if you want the rest of the project to go well.
In the first thirty days you make four decisions and buy nothing. Which report has been asked for and by when, what is in scope, who owns the program, and the earliest date your observation window can honestly open. Every other decision in a SOC 2 project is downstream of those four, and the projects that run late are almost always the ones that skipped them to get started on something visible.
This is the chronological version. The preparation guide covers the whole engagement stage by stage, and the timeline covers the months after this one. What follows is only the first four weeks, because that month decides most of what happens in the eight after it.
4 weeks Covered by this page, and no further
1 Named owner the month has to produce
$0 to $20,000 Range of defensible month-one spend, CAD
Week one: find out what was actually asked for
Go back to whoever asked. Almost nobody does this and it is the highest value hour in the entire project. Four questions, in an email if a call is awkward.
Type 1 or Type 2. They are different purchases with different timelines, and the fee difference is roughly fifteen thousand dollars CAD. A buyer who has not specified will often accept a Type 1 now with a Type 2 to follow, which is a far easier commitment to meet.
Which criteria. Security is in every SOC 2. Availability, confidentiality, processing integrity and privacy are each extra scope, extra evidence and extra fee. Ask whether they need any beyond security, because the default answer from a security team that has not thought about it is often that security alone is fine.
By when, and what happens if it slips. There is usually a difference between the date in the questionnaire and the date the deal actually requires. Find out which one you are working to.
What they will accept in the meantime. This is the question that saves deals. A Type 2 needs an observation window before an auditor can begin, so if the deadline is inside three months, the report does not exist at any price. Buyers routinely accept a Type 1, a signed engagement letter from an audit firm with a target date, or a security questionnaire and a penetration test report as a bridge. Ask before you assume the deal is lost.
Then name the owner. Not a committee. One person with a few hours a week protected and the authority to change how engineering works. Most of the remediation is engineering change rather than paperwork. In a company under fifty people that is usually a senior engineer, a head of platform or a technical co-founder. A program split across three people who each have a day job moves at the speed of the least available one.
What not to do in week one
Do not book a platform demo, do not call audit firms, and do not download a policy pack. All three feel like progress and all three are decisions you cannot make well yet: the platform is priced on headcount and framework count you have not settled, the auditor quotes against a scope you have not written, and the policy set commits you to controls you have not chosen. There is nothing to buy in week one.
Week two: write the scope down
One page. What the product is, which environments run it, what data it holds, who your subprocessors are, and where your people work from. Then the harder half: what is deliberately out of scope and why. The marketing site, the internal analytics warehouse, the acquired product line nobody has integrated yet, the professional services team's laptops.
Written scope is what makes an audit quote comparable, what tells you which systems your evidence has to cover, and what stops an auditor pulling in a system you assumed was out at the worst possible moment. It is a page of writing and it is the cheapest artifact in the whole project. If you want the boundary tests that catch the systems people forget, and the ten sections a description has to carry, scope and the system description is the longer version of this week.
While you are there, produce two lists that everything else depends on: every system that holds customer data, and every person with production access. Both come out of your identity provider and your cloud console in an afternoon, and both are populations an auditor will eventually sample from.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Week three: find out where you stand
Now score yourself, under one rule: nothing counts unless you can produce the artifact. Not "we do access reviews", but here are the last two with dates and names on them. Applied honestly this finds most of what a paid assessment finds. Applied loosely it finds nothing, because it becomes people confirming their own work.
The readiness scorecard is the structured version of this week: thirty-six questions across access control, change management, monitoring, incident response, vendors and people, scored per section so you can see which area is a project rather than a tidy-up. Expect about a third of the items you assumed were fine to move to partial once you go looking for the evidence. That movement is the point of the exercise.
Sort what is left by lead time rather than by severity. Anything with a cycle inside the observation window is the long pole: access reviews, vendor reviews, training completion, the penetration test and its remediation. Log retention belongs with them for a different reason, since retention cannot be applied backwards to logs that have already been deleted.
Week four: decide the plan and the spend
Work backwards. Take the longest lead time from week three, add it to today, and that is the earliest date your observation window can honestly open. Add three months at minimum for the window itself, then four to eight weeks for fieldwork and the report. That arithmetic gives you a report date, and if it lands after the date from week one, you now know that in month one rather than in month five.
Then the two spending decisions, which are separate and are not alternatives. What readiness costs in Canada sets out the ranges behind both, including the internal hours nobody quotes.
| Option | Cost | Buy it when |
|---|---|---|
| Nothing yet | $0 | Under about thirty people, one cloud, a date you control. This is a normal and defensible choice |
| Compliance platform | $9,000 to $40,000 a year | Above about thirty people, or when evidence collection would otherwise be somebody's part-time job |
| Readiness assessment | $5,000 to $20,000 | First audit, complicated environment, or a date set by a signed contract |
| Consultant-led readiness | $20,000 to $60,000 | The date is not yours to move and nobody internally has the hours |
Finish the month by putting every periodic control on one named person's calendar, with the evidence folder path in the description. The recurring calendar entry is the control for most of them, and nearly every missed quarterly review traces back to it being nobody's specific job on a specific day.
What you should be holding after four weeks
None of this is a control. It is the paperwork that makes the next three months possible, and a month one that produces all seven is a month one that worked.
0 of 0 done ·
If the third item on that list has no name against it, stop and read SOC 2 with no security team, because unfunded ownership is the most common reason a first month is repeated. Whether that owner needs help, or a hire, is priced on do we need to hire someone for SOC 2.
The rows in that table we sell
TrazTech operates this site and sells two of the four options above: the readiness assessment and consultant-led readiness. The bands in the table are what it quotes for them. It does not sell the audit, because the firm that builds your controls cannot also attest to them.
The first row can be structured rather than improvised. TrazTech runs a free compliance workspace called traztech Workspace: 10 frameworks, an evidence register mapped to controls, 40 policy templates with approval history, a risk register, and daily scheduled checks against AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira. No credit card, no paid tier, no seat limit, no export fee. It gives you the control set that the fifth item on the checklist above, the gap list, is measured against, which is the part of week three that takes longest from a blank page.
Take the second row instead when your estate needs hundreds of integrations, an endpoint agent or HR system evidence. The workspace has seven connectors, no endpoint agent and no HR integration. And if month one produced all seven checklist items with nobody's help, rows three and four are money you do not need to spend.
What month two looks like
Remediation, which is four to twelve weeks depending on how much of your gap list is engineering change. Policies get written or edited during it rather than before it, because a policy written before you have decided the cadence commits you to somebody else's cadence. The policy checklist works out which documents you need and the policy templates page covers how to edit a downloaded set without writing exceptions into your own report.
Evidence collection starts during month two, not when the window opens. Set the routine up while remediation is running, build the list with the evidence tracker, and give the first month of it to somebody to actually do, because a routine nobody has practised is a routine that quietly fails in week three of the window.
All four of the tools on this site were built for the weeks described above, and each gives you the answer on screen rather than behind an address.
When you get to the point of engaging a firm, the readiness quiz is a fast check on whether that call is worth making yet, and GetSOC2 covers Canadian audit firms, fees and report types.
When the report finally arrives, what to publish once your SOC 2 report arrives covers the first month of using it.
Common questions
How long does SOC 2 preparation take from a standing start?
Two to four months of preparation, then the observation window on top, which is three months at the shortest for a Type 2. Six to nine months from a standing start to a Type 2 report in hand is a realistic plan. A Type 1 can follow preparation almost immediately, which is why it is the usual answer to a deadline inside a quarter.
What should we do first when a customer asks for SOC 2?
Ask them four questions: Type 1 or Type 2, which criteria, by when, and what they will accept in the meantime. The last one is the important one, because a Type 2 cannot exist inside three months and buyers routinely accept a Type 1 or an engagement letter as a bridge. Then name one internal owner before anything else happens.
Should we buy a compliance platform in the first month?
No. Platform pricing depends on headcount and how many frameworks you carry, and in month one you have not settled scope or decided whether a second framework is coming. Buying in month two or three costs the same and is a better-informed purchase. Below about thirty people, going without one for a first audit is a normal choice rather than a compromise.
Can we prepare for SOC 2 without hiring anyone?
Yes, for a straightforward cloud application in a company of roughly ten to fifty people. The work is unglamorous rather than difficult, and doing the first pass internally means somebody in the building understands the program, which matters more in year two than year one. Pay for help when the date is set by a signed contract, when the environment is complicated, or when an earlier attempt already stalled.
Who should own SOC 2 internally?
Whoever can change how engineering works without asking permission, usually a senior engineer, a head of platform or a technical co-founder. Assigning it to an office manager or a junior analyst fails predictably, because most of the remediation is changes to systems rather than documents.
Want a second opinion on the first month
Send us what came back from the customer and what you found in week three, and we will tell you whether the plan holds.
Get matched