Post: Understanding SOC-2 Type-2 Audits for SMBs

July 26, 2025

Overview

This paper will help members of senior management of small to mid-sized companies understand the value and cost of obtaining a SOC-2 Type-2 Audit certification. One of the most important things to keep in mind is that, although the cost of maintaining your company’s SOC-2 status far exceeds the cost of the audit itself, the value of obtaining and maintaining your audit status is usually far greater still.

Reasons for SOC-2

There are three main reasons for a company to obtain a SOC-2 audit:

  • It may be “table-stakes” in your industry, meaning every serious participant is expected to have it
  • It may be a requirement of a specific partner or client you want to work with
  • You may obtain a SOC-2 audit electively to demonstrate your commitment to data security and risk management, in order to gain a competitive advantage

Although official numbers are not published, sources estimate that 7,000 – 14,000 companies will obtain their initial SOC-2 audits in 2025, and that about 20-40% of SaaS companies with revenue over $50MM are SOC-2 compliant or are in the process of becoming compliant.

What is a SOC-2 Audit

A SOC-2 audit provides an impartial, third-party answer to two questions for your audience:

  • Has your firm established policies, standards, and procedures appropriate to the service commitments  you are making to your clients and to your business?
  • Is your firm actually performing all the actions necessary to implement the promises you have made, as confirmed by reliable, contemporaneous documentation of those actions?

The SOC 2 audit is based on the AICPA trust services criteria that include Security, Availability, Processing Integrity, Confidentiality, and Privacy related controls. The company gets to determine the criteria that apply to its business and that will be included in their report.

There are 2 types of SOC reports. The first one is called a  “SOC 2 Type 1” audit, which examines your commitments and your supporting policies, standards, and procedures. This type of report determines if the controls are in place and designed properly as of a given date.

The Type-1 audit doesn’t actually confirm that you are doing anything, but it says your systems are appropriate to your promises and your business.

The second one is a “SOC 2 Type-2” audit which actually examines the documentary evidence of whether you have been adhering to your own promises and procedures over a period of time This is still only a statistical sample audit, so it does not examine every record of every action, but it does provide a reasonable assurance that you are following your procedures and that a client could reasonably expect that you have fulfilled your service  commitments.

To perform the Type-2 audit, an auditor or audit team will:

  1. Examine your statement of the SOC trust services criteria that you have committed to and the details of your commitments
  2. Examine your internal documentation of your data security, process control, and risk management policies, standards, and procedures, and then determine whether they are appropriate to the commitments you have made and to your business context.
  3. Audit, on a random sample basis, the documents your procedures have committed to create and maintain that confirm your ongoing, contemporaneous compliance with your own policies and procedures.

Commitments

In SOC-2 parlance, companies commit to one or more of the following five “Trust Services Criteria” (formerly known as “Trust Principles”), always including Security and usually others as well.

  • Security – Information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems.
    • Implies:
      • Authentication systems
      • Access controls
      • Intrusion detection
  • Availability – The system is available for operation and use as committed or agreed.
    • Implies:
      • Backup processes
      • Performance and uptime monitoring
      • Disaster recovery plans
  • Processing Integrity – System processing is complete, valid, accurate, timely, and authorized.
    • Implies:
      • Input validation
      • Data is protected against unauthorized or unexpected alteration
      • Transaction reconciliation
      • Logging of changes and processing errors
  • Confidentiality – Information designated as confidential is protected as committed or agreed.
    • Implies:
      • Access restrictions
      • Data encryption
      • Proper data disposal
  • Privacy – Personal information is collected, used, retained, disclosed, and disposed of in accordance with the entity’s privacy notice and applicable privacy laws.
    • Implies:
      • Notice and consent
      • GDPR / CCPA alignment

Policies

A “Data Security Policy” is typically a broad statement of intent that designates what data is to be protected, why, generally how, who is responsible for protection. The policy is senior management’s expression of intent, commitment, and allocation of appropriate resources towards data security.

For example a statement signed by the company president stating “Company X commits to implement a program to provide for the security, integrity, and accessibility of data associated with its ABC SaaS service, and designates Ellen Smith as the Director of Data Security and assigns her the staff, time, and resources to effect such program” is a very abbreviated Data Security Policy.

Standards

Standards are an expression of performance criteria that the company spells out as constituting an adequate execution of its Data Security Policy.

For example: “Employee access credentials will be disabled within four hours of termination of any staff member’s employment” is a Standard.

Procedures

Procedures articulate the actual processes by which the standards will be achieved and the ends of the policy obtained. They are the instructions to the people who actually have to “do” data security.

For example, a written list of steps for how to conduct a quarterly drill where a database backup file is fully restored to operational status and success is documented is a “Procedure.”

Documentation

A big part of the SOC-2 audit process is being able to demonstrate that, at any given point in time in the past, you were adhering to your own procedures and were compliant with the standards you set. 

For example, if one of your standards is that employee access to confidential information shall be terminated within four hours of the termination of an employee’s employment, then reasonable documentation would be a signed contemporaneous record (i.e.; recorded at the actual time of the event) of when a terminated employee was actually terminated and when that employee’s access credentials were suspended. Further documentation might be a monthly audit of which employees have active credentials cross referenced against a list of employees who were hired, terminated, or employed within the same month.

Weak or inadequate documentation might be a report that is generated at the end of the year that attempts to determine when employee access was terminated for each terminated employee, even if no record was made at the time of each termination.

Implementation Costs

Expenses related to SOC-2 certification fall into six general categories:

  • Initial Preparation – This is the cost of analyzing your business needs and creating the documentation for policies, standards, and procedures you do not yet have
  • Audit – this is the cost of having an external auditor come and perform the audit
  • Security Tools – This is the cost of software, systems, and services to perform actual data security activities like: endpoint protection, software vulnerability scanning, network intrusion detection systems, automated data gathering, and auditing systems.
  • Training – Humans are some of the greatest weaknesses in any organization’s data security posture. Training them to understand their roles and obligations, training them to be aware of threats and how to respond to them is an ongoing commitment but one with a high payoff. Some training is more targeted, for example having your Data Security Manager obtain certification in data security incident response management.
  • Record Keeping – Whether you record your data security activities and ongoing results manually or automatically, engaging in solid record-keeping will minimize the effort you need to make at audit-time when the auditor asks for a mass of randomly selected audit information like: “Show me your vulnerability scan results from the week of April 7”, “Show me all activity in your software change management system for the week of July 18”, “For these 6 people who left your firm, show me their termination papers and documentation of when their access credentials were terminated,” etc.
  • Security Process Administration – Most of the activities your data security program will have to be performed by someone. Usually that is at least a data security manager, and possibly an entire team, depending on the size of your organization. For the most part, it is difficult or impossible to add these responsibilities to the workload of people already in your organization, either due to the time involved or the knowledge and training required.
  • Management Involvement – Good data security programs need to be monitored for their efficacy, internal compliance, need for update, changes in threat environment, and changes in applicable industry benchmarks. Senior management needs to allocate time to be informed, to evaluate costs and risks, to assess calls for additional investment, and to assess whether the program is achieving its ends and how discrepancies are to be handled. Ultimately, senior management answers to shareholders and external partners as to the efficacy of the data security program and needs to be prepared to make an investment of time and attention.

Preparation

Preparing for an initial SOC-2 audit can take anywhere from a few weeks (for a company with a well-established data security posture that just needs to tidy up a few documents) to a full year (for an organization with an ongoing, established business but new formal data security controls, policies, and procedures in place and potentially needing to hire staff or a consultant, procure and install systems, and train staff.) Cost can vary from $3,000 to over $100,000.

The key milestones in preparing for a SOC-2 Type-1 audit are:

  • Determine which trust services criteria you will commit to
  • Draft policies
  • Audit data assets
  • Identify standards
  • Perform a risk assessment, and document risk management steps
  • Document procedures
  • Create detailed week-by-week schedules of data security implementation, enforcement, and record-keeping tasks
  • Hire or train data security staff
  • Research and procure tools and support systems
  • Train rank-and-file staff on data security
  • Select an auditor and schedule the audit

Audit

Depending on the size and complexity of your organization, the audit itself may take as little as two days and as much as two weeks to complete. The cost of a Type-1 audit is generally $10,000 – $25,000 and for a Type-2 audit (with random sampling) is $10,000 to $60,000, although for a large organization it can extend well into six-figures.

Typically, an auditor (or team) will come on site, interview staff, and obtain high-level documents (like policies, standards, and procedures.) Then within a few days, they will request randomly selected sample documents, reports, and data. You will have just a few days to supply these (without raising suspicion that you are generating them after-the-fact). The auditor may ask for clarifications or supplemental data in most cases.

Once they have the data they need, the auditor may take a few weeks to review the data and draft their report.

A SOC report usually contains 5 main sections as follows:

  • Independent Auditors Report
  • Management Assertion Letter
  • Description of the Controls
  • Summary of Controls, Tests, and Conclusions from the Independent Auditor
  • Other Information Provided by the Client (this section is optional and is not part of the independent auditor’s opinion

The best way to speed the audit process and to prevent it from being a mad scramble for data you think you have but can’t find is to make the investment throughout the year to generate your weekly, monthly, or quarterly tests / audits / reports / data samples, to document everything thoroughly, to store it methodically, and to have clear lines of responsibility so you instantly know whom to ask for what when the auditor’s requests arrive.

Cost of Controls / Maintenance

The majority of costs related to obtaining and maintaining SOC 2 audit readiness relate to performance of the ongoing trust controls and documenting that performance. Some costs are associated with external tools or services to perform security steps or to help with documentation. Here is a representative budget for a small SaaS company:

  • Third party annual network penetration test
  • Automated network vulnerability scanning tool
  • Document management system (for secure sharing, life-cycle management)
  • Endpoint security system (anti-virus, remote wipe)
  • Network Intrusion Detection System
  • Secure storage for PKI keys
  • Encrypted storage devices for backups / disaster-recovery resources
  • Secure enclosure(s) for network equipment
  • Colocation facility
  • Off-site / alternate-cloud backup facility
  • Monitoring tools like: Solar Winds / Service Now
  • Uptime Monitoring: Site24x7
  • Security awareness training for staff
  • Cost of the audit firm
  • Physical security costs: key-card door locks, video surveillance and recording
  • Cost of employees performing the control functions
    • Risk assessments
    • Incident response planning
    • Incident response drills
    • Security procedures
    • Compliance monitoring and benchmarking
    • Policy and program governance
  • Change management system (JIRA)
  • Secure coding practices: static or dynamic code analysis tools (SAST / DAST)
  • Active Directory / LDAP implementation
  • Vendor Risk Management Tool (Smarsh, )

Companies control costs by using a range of solutions that run the gamut between spreadsheets and emails to dedicated SaaS tools.

Summary

Obtaining and maintaining SOC-2 audit status is as much an exercise in implementing good data security practices as it is in good record-keeping. Whether it’s a slow, steady, disciplined effort throughout the year or a mad scramble at the end, it requires an investment and an effort (though slow-and-steady produces a lot less pain).

In the end, having a SOC-2 audit can be a gateway to a new level of customer trust and access to another tier of client engagements, both of which usually spell solid revenue growth. Virtually every company that implements a SOC-2 audited data security program regards it as a healthy effort with long-term positive impacts.

Authors

Anthony Faulise is an NYC-area consultant focused on digital product strategy, development, and implementation. Mr. Faulise has established data security programs for a number of SaaS companies and has been through the SOC-2 audit process multiple times. Mr. Faulise has been a head of product, director of product development, and CTO of start-up and early-stage companies for over 20 years. He earned his bachelor’s degree in electrical engineering and computer science from Princeton University, his master’s degree in computer engineering from Rice University, and his MBA at Duke University’s Fuqua School of Business. You can reach him at afaulise@tripledigitconsulting.com.

Mike Pinna is the owner of Pinna Consulting LLC, where he provides IT audit and assurance services with a focus on IT security and System and Organization Controls (SOC) reporting.  These services are all related to providing assurance on the security, reliability, confidentiality, availability, and integrity of information technology systems.  He is also recently certified in ISO 27001:2022, which is an international standard for information security. Michael earned his Bachelor of Science in Applied Economics at Cornell University and his Master of Business Administration in Finance from Binghamton University.  He is a member of the American Institute of Certified Public Accountants and the New Jersey Society of Certified Public Accountants. He is a Certified Public Accountant in the states of New York and New Jersey.

Facebook
WhatsApp
Twitter
LinkedIn
Pinterest

Leave a Reply

ABOUT THE AUTHOR
Anthony Faulise

I help founders and leaders of small- to mid-sized tech and tech-enabled companies un-stuck product-led growth.

Whether it’s helping define a coherent product strategy, helping focus on execution to realize plans you already have, or ensuring customer and market feedback are shaping development to optimize the performance of your current products, I’m passionate about helping you unlock the potential of the business you’ve built.

I’ve founded start-ups, led product management and product development teams, and guided products to growth in the $10s of millions to $100s of millions per year.

I love finding the intersection of business imperatives and customer needs, untangling product process problems, and building the capabilities of product teams.

If you think your company’s product is not living up to its full potential, we should talk. Call me.

FOLLOW ME ON

Discover more from Triple Digit Consulting

Subscribe now to keep reading and get access to the full archive.

Continue reading