SOC 2 prep with no compliance budget
About seventy percent of a first SOC 2 is work rather than purchase, and you can do all of it before spending a dollar. The two things you cannot get for free are the CPA firm and the penetration test.
You can complete most of a first SOC 2 preparation with no compliance budget at all. Scope, the system description, the policy set, access control cleanup, logging, the vendor register, onboarding and offboarding records, training and the whole evidence routine are labour rather than purchase. What you cannot avoid paying for is the CPA firm, at $20,000 to $35,000 CAD for a first Type 2 under 25 staff, and a penetration test at $8,000 to $18,000 CAD. Everything between those two is optional.
$0 To complete readiness, if you have the hours
$28,000 The two bills you cannot avoid, from, CAD
200 to 400 Hours the free route costs instead
What is free, what is cheap, what is unavoidable
| Work | Cost if you do it yourself | What buying it gets you |
|---|---|---|
| Scope and system description | $0, 10 to 20 hours | A consultant asks better questions. The decision is still yours |
| Gap analysis against the criteria | $0 with a checklist, 8 to 16 hours | $6,000 to $15,000 buys a ranked list and, more usefully, knowing what an auditor accepts |
| Policy set | $0 from templates, 40 to 80 hours | Time. Templates are widely available and the rewriting is the work either way |
| Access control, single sign-on, permission cleanup | $0 in labour, plus any identity tier upgrade | Nothing external. This is engineering work in your systems |
| Logging and retention | $0 to $6,000 a year in storage | Managed services reduce effort and add subscription |
| Vendor register | $0, an afternoon | Nothing worth paying for at this size |
| Evidence collection through the window | $0, 3 to 5 hours a week | $8,000 and up a year for a platform that automates part of it |
| Security training | $0 to $500, delivered internally with a record | Vendor platforms make the record tidier |
| Penetration test | Not available free | $8,000 to $18,000. Auditors expect it and buyers ask for it |
| The audit | Not available free | $20,000 to $35,000. A CPA firm has to sign it |
| Minimum external spend, first Type 2, under 25 staff | $28,000 to $53,000 CAD | |
That total is the lean path costed from the other direction on the cheapest honest way to get SOC 2. If the whole number is out of reach, the question is whether to do this at all yet, and is SOC 2 worth it at our size gives the test.
The free work, in the order that keeps its value
Everything here is worth doing even if you never book an audit. It is the same work a security questionnaire asks about. Do the long-lead items first: they consume calendar rather than effort.
0 of 0 done ·
The full stage-by-stage version is the preparation guide, the artifacts each control needs are on evidence collection, and the templates to start from are on policy templates, which is the Canadian version of a list that is usually twelve American documents.
Log retention is the one that cannot wait
Most items on that list can be done in any order. Log retention cannot. Logs you did not keep do not exist later, and an observation window with no logs behind it is a window you have to run again. If you do one thing this week with no budget, set retention to the period you intend to claim.
Running the program without a platform
Under about thirty people, a spreadsheet, a shared drive and a recurring calendar entry are sufficient for a first audit. What a spreadsheet gives up is everything automatic. Nothing connects to your cloud and nothing checks a control unless a person remembers. If you want that, buy Vanta or Drata and do not pretend a spreadsheet does it.
The free workspace we run
TrazTech operates this site and runs a free compliance workspace called traztech Workspace. It supplies a mapped control set, an evidence register, 40 policy templates with approval history and a risk register, across 10 frameworks. Scheduled checks run daily against AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira and file the result against the control they prove. Anything else with an API is described as a check rather than picked off a list. Free means no credit card, no trial period, no paid tier, no seat limit and no export fee, and the data stays yours if you later hire somebody else or nobody at all.
It suits a company with the hours but not the subscription. It does not suit an estate that needs hundreds of pre-built integrations, an endpoint agent or HR system evidence, and if that is you then the $8,000 and up is the right spend and we will help you set the platform up. There are other free tools in the same shape, and the comparison is on readiness without a platform, and the evidence half is evidence without a platform.
The first dollars to spend, when there are any
- A gap assessment, $6,000 to $15,000 CAD. Highest return of anything on this page. It stops you producing three months of evidence in a shape the auditor will not accept.
- The penetration test, $8,000 to $18,000 CAD, booked early in the window so findings have time to be fixed and retested.
- Any identity provider tier that gives you single sign-on and access logs. It is frequently three to five times your current tier and it saves more hours than anything else you can buy.
- Fixed-scope readiness help, $15,000 to $60,000 CAD, only if there is a customer deadline or nobody with the hours. The options are compared on do we need to hire someone.
- A compliance platform, last, and only above about thirty people.
Can we prepare for SOC 2 for free?
You can complete the preparation for nothing but time, roughly 200 to 400 hours at a small company. You cannot get the report for free, because a CPA firm has to perform the examination and sign the opinion.
Do we need a compliance platform to pass?
No. Auditors accept evidence in whatever form it arrives, including screenshots, exports and tickets in a folder structure. Under about thirty people a platform is frequently the wrong first purchase.
Are free policy templates good enough for an auditor?
Templates are a starting point and never the finished article. An auditor tests whether you do what your policy says, so a template describing a process you do not follow creates exceptions rather than preventing them. Rewrite every clause to match reality, and cut the ones that do not apply.
What is the single most expensive mistake on a no-budget path?
Opening the observation window before the controls are actually running. The fix is a new window and another three months, and no amount of money shortens it. The second most expensive is not turning on log retention early.
How do we know we are ready without paying for an assessment?
Score yourself against the criteria first, then decide. The readiness scorecard and am I ready both produce a gap list at no cost, and they tell you whether the paid assessment is worth buying.
See where you stand before you spend
Score the criteria you already meet, then decide which dollar to spend first.
Check your readiness