Ask what the customer actually needs
When a prospect asks for SOC 2, get the requirement in writing before committing to a programme. Ask which product and system are in scope, which report they expect, and when procurement needs it. Find out whether an interim security review is acceptable; do not assume it will be. This is a commercial qualification step as well as a security conversation. It helps you distinguish a firm contractual requirement from a questionnaire that offers several acceptable forms of evidence.
What the community conversations reveal
In the sampled March-to-September discussions, small teams describe procurement pressure, uncertainty about cost and difficulty collecting evidence. Other commenters challenge the assumption that every early-stage SaaS needs the same programme immediately. Several contributors sell compliance services or tools. Their anecdotes help frame questions, but they do not establish typical prices or guarantee that a particular report will close a deal. Your customer’s actual requirement should lead the decision.
Distinguish readiness work from the examination
SOC 2 concerns an examination of a service organisation’s system and controls, using the applicable Trust Services Criteria. AICPA’s resources describe the reporting framework. A code review or readiness assessment can identify engineering gaps and help organise evidence; it does not issue the independent SOC 2 report. Keep that distinction explicit in proposals and sales material. Ask the CPA firm performing the examination to confirm the report type, scope and evidence period appropriate to the engagement.
Draw a boundary around the service
Start with one page showing the customer-facing service, data stores, infrastructure providers and people who operate it. Mark where customer information enters and leaves. Include support and administration workflows rather than only the application diagram. Then ask who has access to each component and how changes are approved. This working inventory gives a small team something concrete to discuss with its examiner before assembling a large folder of disconnected screenshots.
Build an evidence register that matches real work
For each agreed control, record its owner, operating frequency, evidence location and current gap. A practical engineering example is release approval: identify where the change was reviewed, what checks ran and which revision reached production. Another is departing staff: retain evidence that access was removed from the relevant systems. These are illustrative preparation examples, not a complete control catalogue. Agree the actual evidence requirements with the examiner and protect the records according to their sensitivity.
Use tools after you understand the process
Compare tools against your inventory and team capacity. Ask which evidence is collected automatically, which tasks still require a person, and how you can export your records. Include implementation effort and examination fees in the budget discussion rather than comparing subscription prices alone. A platform can support a process; it cannot make an inaccurate policy true. If your document says every production change is reviewed, the team needs a workable review practice and evidence of following it.
Handle the current sales conversation honestly
Give the prospect a factual account of the controls you operate, the evidence you can share and the work still in progress. Do not call a planned assessment a completed report. Avoid promising an examination date before scope and examiner availability are established. If an interim questionnaire is accepted, answer the questions against the actual service. Track exceptions and commitments so that an optimistic sales answer does not become a forgotten operational obligation.
Leave the first planning session with decisions
Aim to leave with five decisions: the customer requirement, service boundary, examiner contact, evidence owners and a realistic gap-remediation plan. CodeSignOff can support the engineering readiness work, including access, change and recovery evidence. The independent examination remains a separate engagement. That division lets a small team make progress without confusing a security improvement project with a promise of certification.
Sources & further reading
Reference material for the guidance and examples above. Where included, community discussions provide context rather than verified incident evidence.
Prepared with AI-assisted research and checked against the linked documentation. Community discussions inform the questions; they are not verified incident reports.
