Playbook · Track 2 · Lesson 5 of 10 · 2 min

SOC 2 for startups: the first 90 days

Short answer

In the first 90 days a startup can usually scope the report, pick a tool, write and approve policies, close the biggest control gaps and either reach a Type I audit or start a Type II observation period. The plan below is our editorial framework, not a promise of timing; your auditor sets the audit dates.

What happens in days 1 to 15?

Name an owner. Confirm with the customer which report type and criteria they need. Decide the scope: the product, the cloud accounts and the people involved. Pick a path (expert-guided or self-serve) and a tool. Ask each vendor which auditors it works with and whether they are licensed CPA firms enrolled in AICPA peer review.

What happens in days 16 to 45?

Connect the tool to your cloud provider, identity provider, code repository, HR system and ticketing tool so evidence starts flowing. Run the tool's gap assessment. Draft policies from templates, adapt them to how you actually work, and have leadership approve them. Start security awareness training and background checks if your policies require them. Fix the gaps that affect many controls first: single sign-on and multi-factor authentication, device management, logging and access reviews.

What happens in days 46 to 75?

Close the remaining gaps. Run the first access review and record it. Write down your risk assessment and your vendor list with a review of the important ones. Test incident response with a tabletop exercise and keep the notes. Collect evidence for controls that are not automated, such as board or leadership oversight. If a customer also asked for a penetration test, schedule it now so the findings can be fixed before the audit.

What happens in days 76 to 90?

Do a readiness review with your expert or your auditor. For a Type I, agree the report date and hand over evidence. For a Type II, agree the observation period start date; from that day controls must run as described, and the evidence the auditor samples comes from within the period.

What usually slows startups down?

Four things come up again and again: no clear owner, policies that describe a company that does not exist, evidence for manual controls left until the end, and a late decision about the auditor. The first and last are decisions, not work, and can be made in week one.

Where do tools and experts help most?

Tools help most with evidence from connected systems and with tracking. Experts help most with scoping, policies that match reality, and the audit conversation. That is why the expert guidance criterion carries the most weight in our ranking.

What should you read next?

Next lesson · 6 of 10

SOC 2 checklist for startups: 20 items for a first audit

Questions founders ask

Can a startup get SOC 2 in 90 days?

A Type I report within about three months is realistic for many small teams if the auditor is booked early. A Type II takes longer because the observation period has to run after readiness.

Do vendors promise faster timelines?

Some do, for example Comp AI says companies get 'SOC 2 Type I & II audit-ready in days'. Treat speed claims as the vendor's own and ask what 'audit-ready' means in their contract.