โ— SOC 2 Compliance Services Get a Free Readiness Scan

Home โ€บ Guides

Vanta, Drata, or a Consultant? What a Small SaaS Company Actually Needs for SOC 2

Only a CPA firm can issue a SOC 2 report. Here's what platforms and readiness consultants actually do, what each costs, and which combination fits your company.

Updated

The short answer: to get a SOC 2 report you need exactly one thing โ€” a licensed CPA firm to perform the audit. Only a CPA firm can issue a SOC 2 report. Compliance platforms and readiness consultants are both optional help getting ready for that audit.

Everything besides the auditor is preparation:

  • A compliance platform (Vanta, Drata, Secureframe, Sprinto and others) automates evidence collection and monitors your cloud and SaaS tools against SOC 2 controls.
  • A readiness consultant scopes the audit, finds the gaps, writes the policies, and fixes what a platform can't reach.

Most small SaaS companies need the auditor plus one of the other two. Some need both. Very few need neither.

Who does what

CPA audit firmCompliance platformReadiness consultant
Issues the SOC 2 reportโœ… The only one that canโŒโŒ
Connects to AWS/GCP, GitHub, Google Workspace, HR toolsโŒโœ… Its core jobโŒ Works with whatever you use
Continuous monitoring after the auditโŒโœ…Periodic, if engaged
Scopes which Trust Services Criteria applyConfirms at the auditTemplatesโœ…
Writes policies that match how you actually operateโŒ (can't โ€” independence)Templates you adaptโœ…
Handles controls with no integration (HR onboarding, vendor reviews, physical security, change management in practice)โŒPartly โ€” you upload evidenceโœ…
Tells you Type I vs Type II and when to start the observation windowCan adviseGeneric guidanceโœ… Based on your sales timeline
Remediation workโŒ (can't โ€” independence)Flags failuresโœ…

The auditor's independence is the reason the last column exists. The firm that audits you is not allowed to build the controls it then tests. Someone else has to.

Three setups, and who each one fits

1. Platform + auditor, no consultant

Fits when you have an engineer or security lead with real time to own SOC 2 for 3โ€“6 months, your stack is mostly cloud and SaaS with good integrations, and you're comfortable adapting template policies yourself.

Watch for: the dashboard going green doesn't mean an auditor will agree. Integrations test configuration; they can't tell whether your vendor reviews actually happened.

2. Consultant + auditor, no platform

Fits very small teams (roughly under 20 people) doing a first Type I, with a simple environment and no appetite for another annual subscription. Evidence is collected once, for a point in time.

Watch for: Type II covers an observation period, often 3 to 12 months. Collecting months of evidence by hand is where this setup gets painful, and where a platform starts to earn its fee.

3. Platform + consultant + auditor

Fits when an enterprise deal has a date on it, nobody internal can own the project, or the platform is already bought but the project has stalled. The consultant configures the platform, covers the controls it can't reach, and gets you to an auditor-ready state.

Watch for: paying twice for the same work. The consultant should work inside the platform you already have, not build a parallel spreadsheet.

What it costs

These are third-party market estimates, not vendor quotes, so you can sanity-check what you're offered. They vary with company size, scope and auditor, and platforms don't publish list prices.

ItemTypical rangeNotes
CPA audit โ€” Type I$5,000โ€“$25,000Audit fee only; excludes readiness work
CPA audit โ€” Type II$15,000โ€“$80,000+Audit fee only; small SaaS companies often land around $20,000โ€“$50,000, and complex scopes or Big Four firms run well above
Compliance platform$7,500โ€“$30,000+ per yearFor small-to-mid SaaS; entry tiers commonly ~$7,500โ€“$20,000, enterprise tiers far higher
Our readiness work$0 โ†’ $299โ€“$750 โ†’ $2,500โ€“$10,000+Free scan โ†’ fixed-fee gap assessment โ†’ project

Our tiers, as published:

  • Free SOC 2 Readiness Scan ($0): high-level control-gap summary and a Type I / Type II recommendation, within 24 hours.
  • Gap Assessment & Evidence Roadmap ($299โ€“$750, fixed fee): full control mapping against your Trust Services Criteria, an evidence checklist, and a 30-minute walkthrough.
  • Audit Readiness & Remediation ($2,500โ€“$10,000+, project): control build-out, evidence-collection support, policy development, and a control narrative built to survive fieldwork.

The questions that decide it

Answer these before you sign anything:

  1. Is there a deal waiting on the report, and when does it close? That date decides Type I first or straight to Type II, and whether you can afford to learn as you go.
  2. Who will own this internally, and how many hours a week do they really have? If the honest answer is "nobody", buy help, not just software.
  3. How much of your environment has integrations? Mostly AWS/GCP, GitHub and Google Workspace: a platform covers a lot. On-prem systems, legacy apps or physical offices: much of the evidence is manual either way.
  4. Is this a one-time report or an annual commitment? Most customers who ask for SOC 2 ask again next year, which is the strongest argument for a platform.
  5. Have you already bought a platform? Then the question isn't which platform โ€” it's who configures it and closes the gaps it can't see.

Where we fit

We prepare SaaS companies for the audit. We are not a CPA firm and do not issue SOC 2 reports; you engage an independent auditor for that.

We work with or without a platform. If you already use Vanta, Drata, Secureframe, Sprinto or another tool, we work inside it. If you don't, we'll tell you honestly whether you need one.

Disclosure: we have no partner, referral or reseller relationship with any compliance platform or audit firm named on this page, and we aren't paid to recommend any of them.

Frequently asked questions

Can Vanta or Drata get us SOC 2 on their own?

No tool can. A SOC 2 report is issued only by a licensed CPA firm. Platforms automate a large part of the preparation and evidence collection, and many teams with a capable internal owner use one without a consultant. You still need an auditor.

Is a compliance platform required for SOC 2?

No. The AICPA's Trust Services Criteria don't specify or require any particular software. Small teams doing a first Type I often manage with a consultant and well-organized evidence. Platforms earn their cost mainly on Type II and on keeping evidence current year after year.

Type I or Type II first?

Type I reports on your control design at a point in time and can be done faster. Type II reports on whether controls operated over an observation period. If a customer specifically requires Type II, a Type I may still help unblock the deal while the observation window runs. Ask your customer which they'll accept before you pick.

How long does SOC 2 take for a small SaaS company?

Readiness is typically a matter of weeks to a few months, depending on how much is already in place. A Type II then adds its observation period โ€” commonly 3 to 12 months โ€” before the report can be issued.

We bought a platform six months ago and we're stuck. Is that common?

Very. The integrations connect quickly; the policies, manual controls and evidence that the integrations can't reach are where projects stall. That's the specific gap a readiness engagement is for.

Sources

Tell us what triggered the compliance question.

Business context only โ€” no sensitive documents yet. Initial response within 24 hours.

๐Ÿ”’ Your information is never sold. The scan is a readiness check, not a certification or legal opinion.
โœ“ Thanks โ€” your request was received. We'll respond within 24 hours.