Operations

Your SOC 2 Will Take Twice as Long

February: the auditor quotes six months. September: the deal needs the report. The letter lands the following February, and the deal closed elsewhere.

Your SOC 2 Will Take Twice as Long
Illustration · Deimar Gutiérrez

February. The auditor's engagement letter quotes a six-month SOC 2 timeline. The deal in the pipeline needs the report by September. On paper the math closes. In the room, it won't.

The audit opens in March. The first gap assessment finds thirty-seven control gaps. Some are trivial, like missing policies you can write in a week. Some are structural: encryption at rest for backup data, formal vendor risk management, access reviews the company ran informally and now has to document. Then the work cascades. Each gap pulls in engineering, which pulls in a vendor review, which pulls in another policy, which pulls in more paperwork. By June the auditor's open-items list has grown, not shrunk. The three-month observation window can't start until the gaps close. September comes and goes. The deal closes elsewhere in late August. The letter lands the following February, a year after the audit began.

This is the most common compliance-timeline miss at growth stage, and founders underprice it every time. Vendor timelines assume the company already runs most controls correctly and only has to document them. Most growth-stage companies don't run most controls correctly. Closing the gaps before the audit can certify anything is the part the timeline hides. It's also the part that doubles the calendar.

The cascade is predictable. A gap assessment surfaces thirty or forty items. Each item, once started, surfaces its own dependencies. Fix encryption at rest and the engineers head to the storage layer. The storage layer needs a vendor risk review. The review needs a vendor risk process that exists on paper. The process needs a policy. The policy needs legal to read it. Legal needs bandwidth. Every step is small. The sum is months.

Run it as two projects, not one

Split the work. Phase one is the gap assessment and remediation. Phase two is the formal audit. A consultant or an auditor can run phase one. It surfaces the work that has to happen before the audit can pass. That remediation runs alongside your other priorities, usually over two to three months. Only when the gaps close does the formal audit start, with the observation period and fieldwork on a known clock.

The two-phase shape reads differently on a calendar. Gap assessment lands in month one. Fixes run through months two and three. The formal audit opens in month four. Controls run under observation through month six. Fieldwork lands in month seven. The letter issues in month eight. It's slower on paper than the six-month promise. It's the one you can plan against, because the gap assessment already told you the truth.

Most companies skip the split because the gap assessment costs money, ten to twenty thousand dollars from a competent firm, and hands back a to-do list instead of a certificate. The work has no external artifact while it's underway. The compliance team wants to start the formal audit now, because the audit produces the visible badge at the end. Leadership wants the same badge, because it's what the customer asked for.

The deferred work is the actual progress. Teams that run the gap assessment first ship their SOC 2 letters sooner than teams that open the formal audit first. One path cascades and doubles. The other lands on schedule.

The deeper constraint is engineering capacity, not auditor availability. The engineers who have to implement encryption at rest, formalize access reviews, and document deploys have other work. Feature work wins the fight. Most managers deprioritize compliance, because the customer-facing item is louder. The auditor sits ready. The engineering team isn't.

What holds the line is committing engineering capacity up front, in writing, with named people and protected time. Named engineers carry specific compliance items on their quarterly goals. The protected time sits on the calendar before the audit starts. The goals get reviewed monthly against the remediation plan. Now compliance competes on even terms with features, because the feature team doesn't also own the compliance goals.

The math backs the protection. A deal lost to a slow audit costs more than the engineering time you'd reallocate to ship on schedule. The lost deal above, a six-figure annual contract, dwarfed the deferred feature work that closing the gaps would have cost. Few companies run that comparison out loud, so compliance keeps losing to features worth less than the deal it would have won.

Treat compliance as two projects: close the gaps, then run the audit. Fund each one on purpose. Before you sign the auditor's engagement letter, put these four questions on the table:

  • Has the company run a gap assessment, separate from the formal audit, that names the remediation work in advance?
  • If yes: what's the remediation timeline, and does it sit on the engineering team's quarterly goals?
  • If no: which specific deal is driving the date, and does that deal survive an audit that runs twice the published estimate?
  • What named engineering capacity is committed to remediation, with explicit cover from feature work?