ResearchJuly 8, 20267 minute read
Where the three months go
We asked eleven startups to account for the time their first SOC 2 took. Almost none of it was spent fixing security.
Dana Whitfield
Co-founder and CEO
Every founder who has been through a first SOC 2 says the same number: about three months. What almost nobody can tell you is where those three months went. So we asked. Eleven companies, between 8 and 60 people, all of them through a Type II in the last two years, all of them willing to go back through their tickets and their calendars with us.
The answer is uncomfortable. Across those eleven companies, the median time spent actually changing how the company operates was around eleven working days. Everything else was translation.
The four buckets
Once we sorted the work, it fell into four groups, and the sizes were consistent enough across companies to be worth naming.
- 01Finding out what the framework wants. Reading criteria written for auditors, then arguing about what they mean for a company of nine people. Median: 9 days spread over weeks, mostly evenings.
- 02Finding out what you already do. Going through Notion, Slack, GitHub settings and a spreadsheet somebody made in 2023, and working out which controls are already satisfied. Median: 14 days.
- 03Writing the documents. Policies, procedures, the plan you never wrote because you never needed it in writing. Median: 21 days, and the single most resented part.
- 04Collecting evidence in the shape the auditor asks for. Screenshots, exports, tickets, a list reconciled against another list. Median: 12 days.
Fixing something genuinely broken, turning on enforcement that was optional, closing a security group, setting up a review that did not exist, was the smallest bucket in nine of eleven companies.
I thought we were going to find out our security was bad. We found out our filing was bad.
Why translation is so expensive
A criterion says the entity authorizes, modifies or removes access based on roles and responsibilities. A startup has a Linear ticket that says offboard Ravi, and a comment underneath that says removed from Google and GitHub. Deciding whether that ticket satisfies that criterion is not a lookup. It is a reading, and the reading needs to know what an auditor will accept, what the sentence actually claims, and what it quietly leaves out. In that example, the cloud console was left out, which is exactly the sort of thing a sampled ticket gets rejected for.
For years the only way to get that reading was to hire someone who had done audits, or to pay a consultancy by the hour to read your Notion. Both work. Both cost more than a seed-stage company wants to spend on filing.
What the platforms solved, and what they did not
Compliance platforms took the fourth bucket, evidence collection, and made it much better. Connect the identity provider, connect the cloud account, and a dashboard tells you which settings are wrong. That is genuine progress and we are not going to pretend otherwise.
What no integration solved is buckets one, two and three, which is 44 of the 56 median days. Those buckets are prose. They are your policy, written by whoever had time, and a criterion, written by a standards body, and the gap between them. A checkbox cannot read a paragraph and tell you it is undated, unowned and unenforced. Something that reads can.
The number we are aiming at
If translation is the cost, then the goal is not a faster dashboard. It is to take the 44 days of reading, arguing and writing and turn them into a first pass you review. We are not claiming the eleven days of real work go away. They should not. If your offboarding genuinely misses the cloud console, someone has to go fix that, and no software should tell you otherwise.
Method: eleven companies, self-reported time reconstructed from tickets and calendars, medians rather than means because two outliers ran past six months. We are happy to share the interview guide with anyone doing similar work.
Find out where you stand
The free check runs on six controls and your own material.