Home โบ Guides
Vanta, Drata, or a Consultant? What a Small SaaS Company Actually Needs for SOC 2
Only a CPA firm can issue a SOC 2 report. Here's what platforms and readiness consultants actually do, what each costs, and which combination fits your company.
Updated
The short answer: to get a SOC 2 report you need exactly one thing โ a licensed CPA firm to perform the audit. Only a CPA firm can issue a SOC 2 report. Compliance platforms and readiness consultants are both optional help getting ready for that audit.
Everything besides the auditor is preparation:
- A compliance platform (Vanta, Drata, Secureframe, Sprinto and others) automates evidence collection and monitors your cloud and SaaS tools against SOC 2 controls.
- A readiness consultant scopes the audit, finds the gaps, writes the policies, and fixes what a platform can't reach.
Most small SaaS companies need the auditor plus one of the other two. Some need both. Very few need neither.
Who does what
| CPA audit firm | Compliance platform | Readiness consultant | |
|---|---|---|---|
| Issues the SOC 2 report | โ The only one that can | โ | โ |
| Connects to AWS/GCP, GitHub, Google Workspace, HR tools | โ | โ Its core job | โ Works with whatever you use |
| Continuous monitoring after the audit | โ | โ | Periodic, if engaged |
| Scopes which Trust Services Criteria apply | Confirms at the audit | Templates | โ |
| Writes policies that match how you actually operate | โ (can't โ independence) | Templates you adapt | โ |
| Handles controls with no integration (HR onboarding, vendor reviews, physical security, change management in practice) | โ | Partly โ you upload evidence | โ |
| Tells you Type I vs Type II and when to start the observation window | Can advise | Generic guidance | โ Based on your sales timeline |
| Remediation work | โ (can't โ independence) | Flags failures | โ |
The auditor's independence is the reason the last column exists. The firm that audits you is not allowed to build the controls it then tests. Someone else has to.
Three setups, and who each one fits
1. Platform + auditor, no consultant
Fits when you have an engineer or security lead with real time to own SOC 2 for 3โ6 months, your stack is mostly cloud and SaaS with good integrations, and you're comfortable adapting template policies yourself.
Watch for: the dashboard going green doesn't mean an auditor will agree. Integrations test configuration; they can't tell whether your vendor reviews actually happened.
2. Consultant + auditor, no platform
Fits very small teams (roughly under 20 people) doing a first Type I, with a simple environment and no appetite for another annual subscription. Evidence is collected once, for a point in time.
Watch for: Type II covers an observation period, often 3 to 12 months. Collecting months of evidence by hand is where this setup gets painful, and where a platform starts to earn its fee.
3. Platform + consultant + auditor
Fits when an enterprise deal has a date on it, nobody internal can own the project, or the platform is already bought but the project has stalled. The consultant configures the platform, covers the controls it can't reach, and gets you to an auditor-ready state.
Watch for: paying twice for the same work. The consultant should work inside the platform you already have, not build a parallel spreadsheet.
What it costs
These are third-party market estimates, not vendor quotes, so you can sanity-check what you're offered. They vary with company size, scope and auditor, and platforms don't publish list prices.
| Item | Typical range | Notes |
|---|---|---|
| CPA audit โ Type I | $5,000โ$25,000 | Audit fee only; excludes readiness work |
| CPA audit โ Type II | $15,000โ$80,000+ | Audit fee only; small SaaS companies often land around $20,000โ$50,000, and complex scopes or Big Four firms run well above |
| Compliance platform | $7,500โ$30,000+ per year | For small-to-mid SaaS; entry tiers commonly ~$7,500โ$20,000, enterprise tiers far higher |
| Our readiness work | $0 โ $299โ$750 โ $2,500โ$10,000+ | Free scan โ fixed-fee gap assessment โ project |
Our tiers, as published:
- Free SOC 2 Readiness Scan ($0): high-level control-gap summary and a Type I / Type II recommendation, within 24 hours.
- Gap Assessment & Evidence Roadmap ($299โ$750, fixed fee): full control mapping against your Trust Services Criteria, an evidence checklist, and a 30-minute walkthrough.
- Audit Readiness & Remediation ($2,500โ$10,000+, project): control build-out, evidence-collection support, policy development, and a control narrative built to survive fieldwork.
The questions that decide it
Answer these before you sign anything:
- Is there a deal waiting on the report, and when does it close? That date decides Type I first or straight to Type II, and whether you can afford to learn as you go.
- Who will own this internally, and how many hours a week do they really have? If the honest answer is "nobody", buy help, not just software.
- How much of your environment has integrations? Mostly AWS/GCP, GitHub and Google Workspace: a platform covers a lot. On-prem systems, legacy apps or physical offices: much of the evidence is manual either way.
- Is this a one-time report or an annual commitment? Most customers who ask for SOC 2 ask again next year, which is the strongest argument for a platform.
- Have you already bought a platform? Then the question isn't which platform โ it's who configures it and closes the gaps it can't see.
Where we fit
We prepare SaaS companies for the audit. We are not a CPA firm and do not issue SOC 2 reports; you engage an independent auditor for that.
We work with or without a platform. If you already use Vanta, Drata, Secureframe, Sprinto or another tool, we work inside it. If you don't, we'll tell you honestly whether you need one.
Disclosure: we have no partner, referral or reseller relationship with any compliance platform or audit firm named on this page, and we aren't paid to recommend any of them.
Frequently asked questions
Can Vanta or Drata get us SOC 2 on their own?
No tool can. A SOC 2 report is issued only by a licensed CPA firm. Platforms automate a large part of the preparation and evidence collection, and many teams with a capable internal owner use one without a consultant. You still need an auditor.
Is a compliance platform required for SOC 2?
No. The AICPA's Trust Services Criteria don't specify or require any particular software. Small teams doing a first Type I often manage with a consultant and well-organized evidence. Platforms earn their cost mainly on Type II and on keeping evidence current year after year.
Type I or Type II first?
Type I reports on your control design at a point in time and can be done faster. Type II reports on whether controls operated over an observation period. If a customer specifically requires Type II, a Type I may still help unblock the deal while the observation window runs. Ask your customer which they'll accept before you pick.
How long does SOC 2 take for a small SaaS company?
Readiness is typically a matter of weeks to a few months, depending on how much is already in place. A Type II then adds its observation period โ commonly 3 to 12 months โ before the report can be issued.
We bought a platform six months ago and we're stuck. Is that common?
Very. The integrations connect quickly; the policies, manual controls and evidence that the integrations can't reach are where projects stall. That's the specific gap a readiness engagement is for.
Sources
- AICPA & CIMA โ SOC 2ยฎ โ SOC for Service Organizations: Trust Services Criteria
- AICPA & CIMA โ 2017 Trust Services Criteria (with revised points of focus, 2022)
- Secureframe โ SOC 2 audit cost (third-party cost estimates)
- Scrut โ Cost of a SOC 2 audit (third-party cost estimates)