A customer asked for your SOC 2 report: what to do this week
Do not promise a date you cannot keep. In the first week, find out exactly which report the customer accepts, share the security material you already have, name an owner, and send a written plan with a realistic milestone such as a Type I date or a Type II start date.
For most startups the first SOC 2 request comes from a procurement or security team during a deal that matters. The instinct is to say yes to any deadline. A better first week protects the deal and your credibility.
Day 1: what exactly is the customer asking for?
Reply with three questions. Do you need a Type I, a Type II, or either? Which Trust Services Criteria do you need beyond Security? Would you accept an interim step, such as a completed security questionnaire, a readiness letter or a Type I, while a Type II is in progress? The answers decide your plan, and many security teams appreciate a supplier who asks.
Day 2: what can you share today?
Gather what exists: your security policies if any, a description of your architecture and hosting, your identity and access setup, encryption practices, backup and incident response arrangements, and any existing pen test report. Offer to complete the customer's questionnaire. Be accurate: a questionnaire answer is a claim you may later have to prove to an auditor.
Day 3: who owns this?
Name one person. In a small company this is often a technical co-founder or the first engineering lead. If nobody can give it several hours a week for the next few months, that is the signal to look at an expert-guided tool, where a named expert plans the work with you. The path finder on this site asks this question first for a reason.
Day 4: shortlist the path and the tools
Decide between expert-guided and self-serve, then shortlist two or three tools. Ask each vendor how they would get you to the milestone the customer accepts, which auditors they work with, and whether those auditors are licensed CPA firms enrolled in AICPA peer review. Be wary of any vendor speed claim you cannot turn into a contract term.
Day 5: send a written plan
Send the customer a one-page plan: owner, tool, target report type, target date for a Type I or a Type II start, and what you will share in the meantime. Keep the dates conservative. A plan you meet builds more trust than an early date you miss.
What if the customer needs the report very soon?
Ask whether a Type I is acceptable as a first step. A Type I covers control design at one date and can be done once readiness is complete; a Type II needs an observation period after that. If only a Type II will do and the deadline is close, say so honestly and offer interim assurance.
Sources
- AICPA SOC suite of servicesSource: aicpa-cima.com · Read 2026-09-29
Questions founders ask
Can we send a SOC 2 report we do not have yet?
No. You can share your plan, your policies and a completed questionnaire, and a readiness letter if an auditor or expert has assessed you.
Will a customer accept a Type I?
Some will, especially from a young company, often with a commitment to a Type II later. Ask them.