Finally Compliant
Apply

Case study · anonymised at the client’s request

A SOC 2 Type II in eleven months. Here is where the time went.

A US B2B software startup went straight to a SOC 2 Type II on Drata, Security criteria only, with a three-month observation window. Our team was its outsourced product and engineering team, so the control work landed on us. The report was issued by an independent CPA firm in late summer 2026. Getting there took about eleven months and roughly 450 hours across five people. This is the write-up of why, and what we now do differently.

  • Type IISecurity criteria. Straight to Type II, no Type I first.
  • 22policies rewritten to match the real stack and team size
  • ~450 hacross five people, the founder included
  • 11 moend to end, from the purchase order to the final report

The situation

An enterprise partner’s security and compliance questionnaire made a SOC 2 report necessary. The founder bought Drata and, alongside it, a low-cost compliance vendor whose package bundled the policies, a penetration test and the audit. Scope was set to SOC 2 Type II on the Security criteria only, with a three-month observation window and no Type I on the way.

Our team was the company’s outsourced product and engineering team, working alongside the founder. The founder drove the first months: the vendor relationship, the platform’s task list, the personnel tasks. From spring 2026 our co-founder Karen Suen led the policy rewrite, the fieldwork coordination and the review of the report.

What the low-cost vendor delivered

The founder was told the vendor’s part would be about three hours of work and that the company would be in the audit within one to two weeks. The vendor’s own written goal was to have the observation period open within 30 days of kickoff. It opened more than three months after kickoff.

The vendor drafted the policy set within a week of kickoff and the founder approved it the next day. The templates turned out to describe processes for infrastructure the company did not use, and the mismatch surfaced only once the team started operating the policies. The rewrite began in spring 2026, when the observation window was already open.

“the old policies listed processes for infra we didn’t use.”
Karen Suen, co-founder, Finally Compliant, who led the program from spring 2026

What we actually did

The control work, in the order it mattered. All of it was done inside the client’s own accounts and repositories.

  1. 01

    Rewrote all 22 policies

    Each policy was rewritten to describe the stack the company actually ran and the size of team it actually had, then checked against the process it described before it was published.

  2. 02

    Implemented centralized logging

    The auditor wanted 90-plus days of retention, central collection and ad-hoc querying. Logging was consolidated into one service that meets all three.

  3. 03

    Retired three infrastructure providers

    Every provider is a subprocessor to review and a surface to defend. Three were retired to shrink the vendor surface, and the subprocessor list was updated to match.

  4. 04

    Added a second storage provider for backups

    A second storage provider was added for backups, and quarterly restore tests were run and documented during the observation window.

  5. 05

    Rolled out MFA across the company’s tools

    Enforced across the tools in scope and tracked to completion.

  6. 06

    Wrote the cloud-service and subprocessor inventory

    One documented list of every cloud service the product depends on, kept in the internal docs and updated as providers changed.

  7. 07

    Wrote vendor security reviews as pull requests

    Each review of a third-party service was written as a pull request in a docs repository, so the review, the reviewer and the approval are in the commit history.

  8. 08

    Migrated the authentication provider

    In part to remove a dependency on a vendor’s paid plan for its SOC 2 report.

  9. 09

    Reviewed and corrected the system description and the draft report

    The system description arrived with missing and outdated infrastructure details and a network diagram that needed redrawing; we filled the gaps and redrew it. The draft report was reviewed and corrections were sent before it was finalised.

“most of the policy wording was simplified or rewritten to reflect our actual tech stack and early stage startup team size”
Karen Suen, co-founder, Finally Compliant, who led the program from spring 2026

The audit

The observation window ran three months in 2026. Fieldwork followed, with the evidence requests arriving in batches. One batch held 18 requests against a single deadline; all 18 were closed by the deadline, and every follow-up the auditor raised after that was completed.

The system description and the draft report were reviewed and corrected before the report was finalised. The final SOC 2 Type II report was issued by an independent CPA firm in late summer 2026. The client shares it under NDA, and nothing about its contents appears in this write-up.

What we’d do differently, and now do

None of the roughly 450 hours went on things an auditor does not check. The order was wrong. Templates were bought and approved before anyone checked them against the stack. Controls were built by hand, one at a time, while the observation window was already running. Evidence was gathered when the auditor asked for it.

The SOC 2 Sprint is the same work done up front, by engineers, in 14 business days to audit-ready, before the observation window starts.

  1. 01

    Then

    Policy templates approved within a day of delivery, rewritten half a year later.

    Now

    Policies are drafted from the live repository and infrastructure, then reviewed line by line by the senior engineer on the account, before anyone approves them.

  2. 02

    Then

    Logging, backups, MFA and the vendor inventory built by hand while the window ran.

    Now

    Every control is implemented as a merged pull request in the first 14 business days, with written acceptance criteria. The commit history is the evidence.

  3. 03

    Then

    Evidence collected when the auditor asked, in batches, against deadlines.

    Now

    Continuous evidence collection is wired in week two, so the observation window opens in week three with evidence already flowing.

  4. 04

    Then

    The audit arranged through the vendor, and the dates the founder was given for entering the audit and for receiving the report both slipped.

    Now

    An independent, AICPA-peer-reviewed CPA firm is booked at kickoff with fieldwork dates reserved, and we answer every evidence request within 24 hours.

What the Sprint does not change: the observation window is three months minimum, the opinion is the auditor’s and theirs alone, and the audit is performed by an independent CPA firm, never by us.

Starting yours? Start in the right order.

Apply for a build slot

90 seconds · 3 questions decide it · we call within 5 minutes

The application takes about ninety seconds. Three questions decide whether the Sprint fits your situation, and you hear back either way.

Facts in this write-up are limited to what the client agreed can be shared. The report itself is available from the client under NDA.