Guide · 8 chapters
SOC 2 readiness for software teams
Controls, evidence, and the engineering work that makes the audit a non-event.
Chapter 01
What SOC 2 asks for
SOC 2 is a third-party attestation that you have controls in place to protect customer data, and that those controls operate as documented. It's not a checklist of tools — it's a checklist of behaviors and evidence.
Chapter 02
Pick Type 1 first
Type 1 is a point-in-time attestation. Type 2 covers an observation window, commonly 3 to 12 months. Pick Type 1 first — it lets you demonstrate the controls exist before you commit to a year of evidence collection.
Chapter 03
The five Trust Service Criteria
Security is mandatory. Availability, Processing Integrity, Confidentiality, and Privacy are optional. Most B2B SaaS shops scope to Security + Availability + Confidentiality. Add Privacy if you're handling consumer data.
Chapter 04
The engineering work
The work that turns into evidence: SSO with MFA, role-based access reviewed quarterly, encrypted backups, vulnerability scanning, change management documented in PRs, incident response runbooks, and an audit log of everything privileged.
- SSO + hardware-key MFA on everything privileged.
- Quarterly access reviews — automated reports, manual sign-off.
- Backups encrypted at rest, restored quarterly to verify.
- Vulnerability scanning in CI, alerting on critical findings.
- Incident response runbooks tested in tabletop exercises.
Chapter 05
Evidence collection
Use a vendor (Vanta, Drata, Secureframe) — building an evidence collection system in-house is a year of engineering work for a function that's basically commoditized. Pick one, integrate with your stack, let it collect evidence on autopilot.
Chapter 06
The audit itself
Pick a CPA firm experienced in SOC 2 for software. They'll request evidence (your vendor exports it), interview the people who own the controls (your engineering leads), and write the report. Ask each firm for its timeline up front. Type 2 adds the full observation window on top.
Chapter 07
What it costs
Budget three lines: the evidence vendor, the audit firm, and engineering time. Vendor and auditor prices vary with scope and headcount — get quotes from two or three of each. Engineering time is the line teams underestimate. Plan for a focused lead-up, then a standing slice of one engineer's week to keep evidence current.
Chapter 08
The shape of an engagement with us
We aim to join 8-12 weeks before the target Type 1 date. Week 1: gap analysis. Weeks 2-6: engineering work. Weeks 7-10: evidence collection and auditor walkthroughs. The goal: walk into fieldwork with every known gap closed. The attestation itself comes from your auditor, not from us.
More guides
Multi-tenant SaaS, end to end
Postgres RLS, RBAC, metered billing, and a SOC 2-ready audit trail — wired in before the first tenant signs.
Building production AI agents
Tool use against real APIs, eval harnesses, observability, and the kill-switches you'll want.
Core Web Vitals — the playbook we run
LCP, INP, CLS — how we diagnose, fix, and lock in. With the GitHub Action we use to enforce.
Run this with your team
Book the workshop version.
A half-day workshop with your team — same content, your codebase. We tailor the chapters to where your team is today.