SOC 2 Basics

How long does SOC 2 take?

SOC 2 Type 1 typically takes 2–4 months from kickoff to report. SOC 2 Type 2 takes 6–12 months because it requires an observation period (minimum 3 months) during which your controls must operate consistently before the auditor can attest to them.

The biggest variable is the gap remediation phase — teams that already have policies in place can cut months off the timeline. See the full SOC 2 timeline breakdown for a phase-by-phase guide.

What’s the difference between SOC 2 Type 1 and Type 2?

SOC 2 Type 1 is a point-in-time attestation: the auditor confirms your controls exist and are designed correctly as of a specific date. SOC 2 Type 2 covers an observation period (typically 3–12 months) and confirms your controls operated effectively throughout that window.

Enterprise buyers generally prefer Type 2, but many will accept Type 1 while you complete your Type 2 observation period. See SOC 2 Type 1 vs Type 2 for a full comparison and decision framework.

How much does SOC 2 cost for a startup?

Audit fees from a licensed CPA firm typically run $15,000–$60,000 depending on scope, firm, and whether you’re pursuing Type 1 or Type 2. That’s just the audit itself. Total cost also includes readiness work (policies, controls, tooling), which can add $10,000–$30,000+ if done with consultants — or significantly less if done in-house with templates. GRC platforms for Type 2 evidence collection run $10,000–$25,000/year.

See the full SOC 2 cost breakdown by stage (seed, Series A, Series B).

What Trust Service Criteria do I need?

Security (the Common Criteria, or CC) is mandatory for every SOC 2 report. Most startups also add Availability, which enterprise buyers care about. The other three criteria — Confidentiality, Processing Integrity, and Privacy — are optional and extend the control requirements significantly.

Start narrow with Security + Availability. Add others in future audits as customer requirements dictate.

What policies do I need for SOC 2?

Most SOC 2 audits require documentation covering these 12 policy types:

Information Security Policy (ISP) — your foundational security document
Incident Response Plan (IRP) — detection, containment, recovery, notification
Access Control Policy — RBAC, provisioning, deprovisioning, reviews
Change Management Policy — SDLC, code review, deployment process
Business Continuity Plan (BCP) — disaster recovery, RPO/RTO targets
Risk Assessment Framework — annual risk assessment methodology
Vendor Risk Management — third-party evaluation and monitoring
Employee Security Training Plan — onboarding, annual training, phishing
Vulnerability Management Policy — scanning, patching, penetration testing
Privacy Policy — data handling disclosure
Data Processing Agreement (DPA) — processing on behalf of customers
Encryption & Data Protection Policy — at-rest, in-transit, key management

Writing these from scratch takes 40–80 hours. The ShieldDocs Starter Kit includes all 12 templates ready to customize in a weekend.

Stop rewriting SOC 2 policies from scratch

12 professional templates ready to customize. Cut 40–80 hours of documentation work to a weekend.

Get the Starter Kit — $147 →

Security Questionnaires

What does a vendor security questionnaire actually check?

Vendor security questionnaires typically cover: encryption (data at rest and in transit), access controls (MFA, RBAC, offboarding), incident response (detection, notification timelines), backup and recovery (RPO/RTO targets), data retention and deletion policies, sub-processors and third-party risk, and certifications (SOC 2, ISO 27001, GDPR compliance).

A SOC 2 report is the fastest way to answer most of these questions at once — you hand over the report rather than completing 150 individual questionnaire items.

Do I need SOC 2 or can I just answer questionnaires manually?

Early on, answering questionnaires manually works fine. Most seed-stage startups handle their first dozen questionnaires this way. Once questionnaires hit 10+ per quarter — each taking 4–8 hours to complete — the math shifts in favor of SOC 2.

A SOC 2 report answers the bulk of every questionnaire up front, and many enterprise procurement teams now require SOC 2 explicitly rather than accepting manual questionnaire responses.

What’s the difference between SOC 2 and ISO 27001?

SOC 2 is an AICPA attestation standard most common in North America. Your auditor is a licensed US CPA firm that produces an attestation report. ISO 27001 is an international certification (from ISO/IEC) more commonly required by European and APAC customers.

The controls overlap significantly, but the process and market positioning differ. For most US SaaS companies selling to US enterprise, SOC 2 is the right first step. If you’re expanding into Europe, ISO 27001 may become relevant later.

GDPR

Does GDPR apply to my SaaS startup?

Yes, if you process personal data of EU residents — regardless of where your company is based. “Personal data” is broad: it includes names, email addresses, IP addresses, and any other information that can identify an individual. GDPR applies even if you have just one EU customer.

If you’re collecting leads, running analytics, or storing user accounts for anyone in the EU, GDPR applies to you.

What’s the difference between GDPR and SOC 2?

SOC 2 is a voluntary security audit conducted by a CPA firm. It demonstrates that your controls are designed and operating effectively. GDPR is a legal regulation with mandatory compliance obligations, enforceable fines, and specific rights for EU data subjects.

You may need both. They complement each other: SOC 2 demonstrates the security controls that GDPR requires you to have, so pursuing SOC 2 makes your GDPR compliance story significantly stronger.

What documents do I need for GDPR compliance?

The core GDPR documents every SaaS startup needs:

Privacy Policy — your public-facing data handling disclosure
Data Processing Agreement (DPA) — required when you process data on behalf of EU customers
Sub-processor list — disclosing the third-party services that touch EU personal data
Records of Processing Activities (ROPA) — an internal log of every data processing activity you run

The ShieldDocs Starter Kit includes Privacy Policy and DPA templates ready to customize.

Going It Without a Consultant

Can I do SOC 2 without a consultant?

Yes — for the readiness and preparation work. The actual audit must be conducted by a licensed CPA firm, but everything before that (gap analysis, policy writing, control implementation, evidence setup) is DIY-able.

Most seed-stage teams do the prep work in-house and hire an auditor only for the audit itself. The key investment is time and the right templates — professional policy templates cut 40–80 hours of documentation work down to a weekend.

Ready to get compliant?