Security and compliance review
SOC 2, and what a buyer's technical review actually checks for before a contract can be signed
4 min read
The previous lesson named security and compliance review as frequently the first gate a vendor has to clear, not the last. This lesson explains the specific mechanics — what SOC 2 actually is, why buyers ask for it, and what it costs to have one.
What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA), built around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. [Established] — this is the AICPA's own published framework, a standards-body source, not a vendor claim. A SOC 2 report is produced by an independent, licensed CPA firm that examines a vendor's actual controls against those criteria and issues an attestation — not a certification the vendor awards itself, and not a marketing claim, which is precisely why enterprise buyers ask for it specifically rather than accepting a vendor's own security page as sufficient.
Type I versus Type II is the distinction that matters most in a real sales cycle:
- Type I attests that controls are designed appropriately, evaluated at a single point in time.
- Type II attests that those controls actually operated effectively over an observation period, typically 3 to 12 months. [Established]
A Type II report is materially stronger evidence, because it demonstrates sustained operation rather than a snapshot — and it is what most serious enterprise buyers ask for by name. Enterprise procurement teams, and regulated industries specifically (financial services, healthcare), routinely require a SOC 2 Type II report before onboarding a vendor, independent of deal size. [Directional] — consistent across multiple compliance-industry sources describing standard enterprise procurement practice, though "routinely" varies by industry and by how regulated the buyer is.
What it costs, and why that cost is a real barrier to entry
A first Type II audit, all-in (control implementation, audit-firm fees, and the internal time to prepare), commonly runs $30,000 to $80,000 for a small-to-mid-sized company, with the audit engagement itself frequently priced $20,000 to $60,000; larger scope or a larger audit firm can push the total well past $150,000. Ongoing annual renewal typically runs $15,000 to $40,000. [Directional] — consistent across multiple compliance-vendor and audit-advisory sources; note that several of the sources reporting these figures also sell SOC 2 compliance software, which gives them a mild interest in making the process sound achievable and worth paying for rather than prohibitive. The ranges themselves are broadly consistent across independent firms, which is why they clear the [Directional] bar, but the framing around them (how "easy" the process is) deserves the same skepticism this platform applies to any vendor describing the cost of its own category.
This cost is a genuine structural barrier, not an inconvenience: it means a vendor cannot credibly compete for enterprise deals that require SOC 2 — a large fraction of them — until they've spent real money and months of preparation on something that adds zero product functionality. Module 5's capital lesson treats this as one of several real, non-optional costs of entry into this business model, not an optional nice-to-have.
What else a technical review typically checks
SOC 2 is the most commonly requested attestation, but a real enterprise security review frequently checks several things at once, drawing on frameworks like the Cloud Security Alliance's CAIQ questionnaire or NIST 800-53 controls as a scoring baseline: data encryption in transit and at rest, access-control and authentication practices (increasingly, single sign-on support is a hard requirement rather than a preference), incident-response process, sub-processor and data-residency disclosure, and — for government or public-sector buyers specifically — FedRAMP authorization, a considerably heavier and more expensive process than SOC 2 alone. [Directional] — consistent across multiple procurement and vendor-risk-assessment sources describing standard practice; the specific checklist varies by buyer and industry.
Why this belongs this early in the course
A founder evaluating whether to pursue enterprise contracts needs this lesson before the pricing and build-vs-integrate lessons that follow, not after: the true cost of competing for enterprise deals includes a compliance-readiness cost that has nothing to do with the product itself, has to be paid before the first serious RFP response, and, per the previous lesson, can eliminate a vendor from consideration before a single stakeholder conversation happens. Treat "do we have, or can we credibly get, SOC 2 Type II" as a go/no-go gate to check before investing further sales effort, not a detail to handle once a deal is already close to closing.
Up next
Enterprise pricing and negotiation
Why there is no real "list price" once a deal is big enough to need one, and the actual mechanics of how the number gets negotiated down
3 min