Skip to content

Current as of August 9, 2026. Reviewed quarterly. The rules in this area move; the date matters.

SOC 2, before the enterprise deal

The question is almost never "how do we get SOC 2." It's "what unblocks this particular deal, and in what order."

This page is general information for operators, current as of the date shown. It is not legal advice, and reading it does not create an attorney-client relationship. Specific facts change the answer.

What buyers are actually asking for

When procurement says "SOC 2," they almost always mean Type II. That's a report on how your controls actually operated across an observation window, which is a different thing from a Type I, a snapshot of whether the controls existed on the day the auditor looked. Experienced buyers know the difference, and some of them will tell you flatly that a Type I doesn't count. One more thing worth knowing before you go into that conversation: neither report is a certification. Both are an auditor's opinion, and what the report says about exceptions matters far more than the fact that you have one to hand over.

The honest clock and the honest bill

From a standing start, a Type I typically runs $12,000 to $40,000 and takes three to eight months. A Type II runs $15,000 to $75,000 and takes six to twenty months, and the reason for the gap is simple: the observation window is calendar time, and nobody has figured out how to compress calendar time. Then add a penetration test. No AICPA criterion requires one, and effectively every enterprise buyer and cyber insurer asks for one anyway. So if somebody on your sales team told a prospect the Type II lands "next quarter" and you don't have an audit underway today, that promise is already wrong, and the buyer will work it out before you tell them.

What your platform does, and the calls it can't make

Compliance platforms are genuinely good at what they do: collecting evidence, monitoring controls, handing you policy templates to start from. What they don't do is decide what passes, because that stays the auditor's call, and they don't touch the legal questions the deal actually turns on. Can you stand behind the answer you gave to question 141? Is the customer's audit-rights clause acceptable as drafted? What happens if you sign the security exhibit and then miss a control six months later? Those answers are representations, and you own every one of them. The better news is that the fights are narrower and far more repeatable than a 214-question form makes them look. It's usually the same three: an audit-rights clause with no notice period, no frequency cap and no scope limit; a security exhibit that incorporates your policies by reference, so an ordinary internal policy edit quietly becomes a contractual breach; and an encryption answer that's true of production but not of backups. Settle those positions in writing while the deal is still open, because once the exhibit is signed you're asking for a favor rather than negotiating a term.

Closing deals mid-audit

Deals close during the observation window all the time, so a pending audit is not a reason to stall the conversation. What works is showing your work: a trust page that's true, current policies, the gap assessment, the auditor's engagement letter, and a straight sentence like "our Type II report is expected in Q3, and here's what we can show you today." What doesn't work is "we're SOC 2 compliant" when what you actually mean is "we bought a compliance platform subscription." That answer goes into the buyer's file, in writing, with your name next to it.

The AI layer on top

If you sell AI, a second generation of questions is arriving on top of SOC 2. The Cloud Security Alliance published AI-CAIQ in October 2025: 243 control objectives across 18 domains, mapped to NIST AI 600-1, ISO/IEC 42001 and the EU AI Act. Alongside it comes a much blunter one, “are you ISO 42001 certified or implementing it?”, which by mid-2026 was showing up in roughly 40% of enterprise AI RFPs in the EU and about 25% in North America. If you already hold ISO 27001, standing up the management system runs six to nine months, and the first certification audit takes another nine to fifteen. Budget against those numbers now, because the day a deal asks is the worst possible day to start counting.

Before the next security review

SOC 2 gets you into the room. What sets you apart once you're there is answering the hard questions quickly, in writing, without overclaiming a single one. That's a habit rather than a document, and you can build it before the next deal needs it.

This is the general version.

A briefing can tell you how the rules run. It can't tell you how they run against your facts. That's the fifteen-minute call.