SOC 2 with no security team
Most Canadian companies that pass a first SOC 2 have no security team. They have one engineer who owns it, a manager who chases evidence, and a list of decisions nobody else can make for them.
You do not need a security team, a security hire or a CISO to pass a first SOC 2. You need one named owner with about two days a week for a quarter, enough authority to change how the engineering team works, and access to whoever signs things. Nothing in the Trust Services Criteria requires a security department. CC1 asks that responsibility is assigned and that the people doing the work are competent. A founder who does the work satisfies that as well as a job title does.
1 Named owner the criteria actually require
0 Criteria that name a security job title
2 days Per week the owner needs, through preparation
Who does each part, in a company with no security staff
Every task below exists in a first SOC 2. A task with no name against it is the one that stalls in month three.
| Task | Who normally does it | Can it be bought in? |
|---|---|---|
| Scope and system description | Founder or CTO, with the person who knows the architecture | Advised, not delegated. It is a business decision about what you are promising |
| Gap analysis against the criteria | Consultant, or the owner working through a checklist | Yes, and it is the best single thing to buy |
| Policy set, written to match what you actually do | Owner, from templates, reviewed by the founder | Partly. Templates get you 70 percent, the remaining 30 has to describe your reality |
| Access control changes, single sign-on, permission cleanup | Engineering | No. It is work inside your systems |
| Logging, alerting, retention | Engineering or whoever owns infrastructure | Partly, through a managed service |
| Vendor register and risk ratings | Operations, finance or the office manager, who already knows what you pay for | Yes, and it is often handed to the wrong person |
| Onboarding, offboarding and training evidence | Whoever runs people operations | Yes, through the tools you already use |
| Evidence collection through the window | Owner, on a calendar | Partly, through a platform, and never entirely |
| Answering the auditor during fieldwork | Owner, with engineering on call | No. The auditor needs the person who knows the system |
| The audit itself | A CPA firm | It has to be. Nobody internal can sign it |
The vendor register is routinely assigned to an engineer, who does not know what the company subscribes to. The person in finance approving the invoices could build it in an afternoon. That one allocation removes a fortnight. What the register has to contain is on the vendor management policy page.
What the owner cannot hand to anyone
- The scope decision
- What is inside the system boundary is a commercial commitment, not a technical one. A consultant can lay out the options and their cost. Somebody in your company has to choose. Getting it wrong in either direction is expensive, and scope and system description works through it.
- Deciding what the company will actually do
- A policy that says access is reviewed quarterly commits your engineering team to a quarterly ritual for as long as you hold the report. Signing policies you do not intend to follow is the most common way a first audit produces exceptions.
- Chasing people
- Evidence collection is mostly asking colleagues for things they consider unimportant. It requires standing in the company. An external consultant has none, and outsourced readiness stalls at this step.
- Answering the auditor
- Fieldwork questions are about your systems. The person who can answer them in one message rather than three rounds is internal. Their availability is the difference between four weeks and eight.
What to buy instead of hiring
The cheapest useful purchase is a one-off gap assessment at $6,000 to $15,000 CAD. It tells you what an auditor will accept before you spend three months building the wrong evidence. Above that sits a fixed-scope readiness project at $15,000 to $60,000 CAD, bought by companies with a hard customer deadline, and a fractional CISO at $3,000 to $12,000 CAD a month for when you will keep needing security leadership after the report is signed. The comparison, including the case for hiring nobody at all, is on do we need to hire someone for SOC 2.
The risk of a team of one
A single owner is enough to pass and fragile afterwards. If that person leaves in month eight, the evidence routine stops, the window develops a hole and the report carries an exception. Name a second person who attends the same meetings and knows where the evidence lives, even if they do none of the work. It is the cheapest insurance in the project.
If your engineering team is contractors
A company with no security staff often has no permanent engineering staff either. That changes the people-related evidence, not the outcome. Contractors with production access sit inside every population an auditor samples, and Canadian background screening does not look like the US screening a template assumes. Contractors and remote teams covers that, including the device evidence problem that is hardest for a distributed company with no security function.
The order to work in
- Name the owner and write down how many hours a week they get. Unfunded ownership is the most common reason a first attempt stalls.
- Decide the scope and write the system description early. Everything else is measured against it.
- Buy one gap assessment. Fix the ranked list rather than working through the criteria in order.
- Do the long-lead items first: log retention, single sign-on, the penetration test booking, training. These take calendar time you cannot recover.
- Start the observation window only when the controls are running, and put evidence collection on a recurring calendar entry.
The full stage-by-stage version is the preparation guide, and the week-by-week version of the first month is how to prepare for SOC 2. What all of it costs the owner in hours is on how much time SOC 2 actually takes.
Does SOC 2 require us to have a CISO?
No. The criteria require that responsibility for security is assigned to someone with appropriate authority and that the person is competent to hold it. A founder or engineering lead who owns it explicitly meets that. What auditors do test is whether the assignment is documented and whether the person actually acts on it.
Can one engineer do the whole thing?
The technical half, yes, at roughly two days a week for a quarter. The half that involves people operations, vendors and policy approval needs somebody with organisational reach, and forcing both onto one engineer is the usual reason a timeline slips by two months.
Will an auditor treat us as higher risk with no security team?
No. Auditors test controls, not headcount. A ten person company with tidy access reviews and complete evidence has an easier audit than a two hundred person company with a security team and no records.
Should we hire a security person before starting?
Usually not for the audit itself. A first security hire at $110,000 to $180,000 CAD a year costs more than the entire audit and takes three months to recruit, which is time the project does not have. Hire when the ongoing program justifies it, not to get a report.
Who signs the policies if there is no security leader?
A founder or an executive. What matters to the auditor is that an appropriate person approved them, that the approval is dated, and that the same person can explain why the policy says what it says.
Find a firm that works with small teams
Tell us who owns this internally and how much time they have. Firms here quote against that reality.
Get matched