The SOC 2 playbook for startups
Ten lessons in three tracks, in the order most first-time teams need them. Start with Basics if SOC 2 is new; jump to Running it if you have already picked a tool.
Track 1: Basics
What is SOC 2? A plain guide for startups
What the report is, who issues it and why customers ask for it.
Lesson 2 · 2026-01-12 · 2 min · Stop 1: DecideThe SOC 2 Trust Services Criteria: which to include in your first audit
Security is required; how to decide on the other four.
Lesson 3 · 2026-01-19 · 2 min · Stop 4: Type I or observation periodSOC 2 Type I vs Type II: which should a startup do first?
Point-in-time design or operation over a period, and how to choose.
Track 2: Planning
Expert-guided vs self-serve SOC 2: choosing your path
Who owns the plan: a named expert or your own team.
Lesson 5 · 2026-02-01 · 2 min · Stop 3: ReadinessSOC 2 for startups: the first 90 days
Scope, tool, policies, gaps and the audit date, in four stretches.
Lesson 6 · 2026-02-22 · 2 min · Stop 3: ReadinessSOC 2 checklist for startups: 20 items for a first audit
Twenty items to settle before the auditor arrives, printable.
Track 3: Running it
SOC 2 policies for startups: what your first audit needs
Which policies to write and how to keep them true.
Lesson 8 · 2026-03-08 · 2 min · Stop 3: ReadinessSOC 2 evidence collection and integrations, explained for startups
What evidence is, what integrations automate, what needs a person.
Lesson 9 · 2026-09-29 · 2 min · Stop 5: AuditHow to choose a SOC 2 auditor for your first audit
CPA licence, peer review, independence and what to ask.
Lesson 10 · 2026-04-25 · 2 min · Stop 6: Report and renewAfter your first SOC 2 report: sharing, renewing and the next framework
Sharing, bridge letters, renewal and the next framework.