Skip to content
diviteb

Guide · 8 chapters

SOC 2 readiness for software teams

Controls, evidence, and the engineering work that makes the audit a non-event.

Chapter 01

What SOC 2 asks for

SOC 2 is a third-party attestation that you have controls in place to protect customer data, and that those controls operate as documented. It's not a checklist of tools — it's a checklist of behaviors and evidence.

Chapter 02

Pick Type 1 first

Type 1 is a point-in-time attestation. Type 2 covers an observation window, commonly 3 to 12 months. Pick Type 1 first — it lets you demonstrate the controls exist before you commit to a year of evidence collection.

Chapter 03

The five Trust Service Criteria

Security is mandatory. Availability, Processing Integrity, Confidentiality, and Privacy are optional. Most B2B SaaS shops scope to Security + Availability + Confidentiality. Add Privacy if you're handling consumer data.

Chapter 04

The engineering work

The work that turns into evidence: SSO with MFA, role-based access reviewed quarterly, encrypted backups, vulnerability scanning, change management documented in PRs, incident response runbooks, and an audit log of everything privileged.

  • SSO + hardware-key MFA on everything privileged.
  • Quarterly access reviews — automated reports, manual sign-off.
  • Backups encrypted at rest, restored quarterly to verify.
  • Vulnerability scanning in CI, alerting on critical findings.
  • Incident response runbooks tested in tabletop exercises.

Chapter 05

Evidence collection

Use a vendor (Vanta, Drata, Secureframe) — building an evidence collection system in-house is a year of engineering work for a function that's basically commoditized. Pick one, integrate with your stack, let it collect evidence on autopilot.

Chapter 06

The audit itself

Pick a CPA firm experienced in SOC 2 for software. They'll request evidence (your vendor exports it), interview the people who own the controls (your engineering leads), and write the report. Ask each firm for its timeline up front. Type 2 adds the full observation window on top.

Chapter 07

What it costs

Budget three lines: the evidence vendor, the audit firm, and engineering time. Vendor and auditor prices vary with scope and headcount — get quotes from two or three of each. Engineering time is the line teams underestimate. Plan for a focused lead-up, then a standing slice of one engineer's week to keep evidence current.

Chapter 08

The shape of an engagement with us

We aim to join 8-12 weeks before the target Type 1 date. Week 1: gap analysis. Weeks 2-6: engineering work. Weeks 7-10: evidence collection and auditor walkthroughs. The goal: walk into fieldwork with every known gap closed. The attestation itself comes from your auditor, not from us.

Run this with your team

Book the workshop version.

A half-day workshop with your team — same content, your codebase. We tailor the chapters to where your team is today.