Compliance platforms sell SOC 2 as something you can automate, and the evidence collection can be. The rest of the work is split: SOC 2 compliance consultants, platforms, auditors and pen testers each do one of four jobs, and none of them changes your code. The access checks, logging and backups an auditor samples are engineering work.

What you are actually buying from SOC 2 compliance consultants, and from the four sellers next to them

SOC 2 compliance consultants are one of five sellers in this market, and each does one job. The consultant interprets the criteria, finds the gaps and writes the policies. A compliance platform collects evidence. A CPA firm examines and issues the report. A pen tester attacks the running app. Engineering changes the code the other four assume is sound.

SOC 2 compliance services, as a buyer meets them, can mean any of the first four rows in the table below, and the labels overlap. A firm that lists itself among SOC 2 compliance companies, or calls itself a cyber security compliance company, could be selling any of those four jobs, so ask which row it is before comparing quotes. Whatever the label, the code changes sit in the fifth row, and that engineering is the core of production hardening, whether or not a report ever follows.

SOC 2 compliance consulting is the first row. It is sold by a lone SOC 2 consultant, by firms of SOC 2 certification consultants, and as packages called SOC 2 certification services. In each case the consulting prepares you for the report in the third row; the consultant does not issue it.

SellerThe one job it doesWhat you get backHow it is pricedWhat it does not do
Consultant or vCISOTells you what the criteria mean for your company, writes or tailors policies, runs the gap assessment, prepares you for the auditorA gap list, policies and a planA project fee or a monthly retainerIssue the report, or change the app
Compliance platformConnects to your cloud, code host, identity provider and HR tool, collects evidence, tracks control status, stores policiesA dashboard of control status and a store of evidenceA subscriptionFix a failing control, or issue the report
AuditorExamines your controls over a date or a period and issues the SOC 2 reportThe report, signed by a licensed CPA firmA fee per reportBuild the controls it will examine
Pen testerTests the running app and reports findingsA findings reportA fee per testChange your code
Engineering (an in-house engineer, a contractor, or a fixed-scope engagement)Changes the code: access control, logging, backups, CI, tests, and the evidence for eachControls that operate, with evidence you can openSalary, a day rate, or a fixed feeIssue or sign any report

The auditor row is the one rule in the table that is not my reading. The AICPA’s review checklist for a vendor’s SOC 2 report, a form it marks “For illustrative purposes only”, carries the note “Only a licensed CPA firm can issue a valid SOC 2 report”, and it sits with the AICPA’s SOC 2 report review materials. Who may perform the examination, and whether you need one at all, is the question behind do I need SOC 2. Whether the fourth row is mandatory is a separate question: whether SOC 2 requires a pen test is answered there, along with whether an AI pentest is enough.

What each of them bills, and the three payees hiding behind a single quote, is laid out in who actually gets paid when you buy a SOC 2, so the figures are not repeated here.

Startup compliance, for a company of two or three people, is mostly the fifth row first: the access checks, logs and backups an auditor will ask to see have to exist before any of the other four sellers has anything to work with. “When to pick each” below sets out the order I’d give compliance startups of that size.

The compliance platform: what the subscription automates, and what it leaves you

SOC 2 compliance software automates one half of the work: it pulls evidence from your cloud, code host and identity provider, tracks control status and stores policies. It leaves the other half: choosing the scope, making a failing check pass, everything inside your own application’s code, the judgment calls, and the auditor’s fee.

Compliance software in the SOC 2 sense is a subscription that connects to systems you already run and turns their settings into evidence. Vanta’s home page says it can “Automatically pull data from 400+ tools”. The reach of any SOC 2 compliance automation platform is set by those connections, which is why one of the questions near the end of this page asks which integrations cover your stack.

The left column below is one vendor’s own feature list, Secureframe’s packages page, read on 27 September 2026, not a claim about every platform. The middle column is my reading of what stays with you, and the right column says who usually does it.

The platform automates (Secureframe’s own feature names)What stays with youWho does that part
Automated Asset Scoping (rules per asset type)Deciding which system the report covers and which criteria applyYou, with a consultant if nobody has done it before
Automated Evidence CollectionMaking the control exist, so there is evidence to collectEngineering
Continuous Control MonitoringMaking a failing check pass: MFA switched on, backups tested, access reviewed, a change process that is realEngineering or whoever runs the accounts
Policy Management, Pre-built Policy TemplatesMaking each policy describe how the company actually works, then following itYou, or a consultant
Personnel Onboarding/OffboardingThe people work: tasks finished, access removed on a leaver’s last day in every system, the app’s own admin accounts includedYou and engineering
Risk ManagementThe risk assessment’s judgments: what could go wrong and what you will do about itYou
Secureframe Agent for DevicesEverything inside your own application: authorization, tenant isolation, audit logging, secure development evidenceEngineering
Access to the Secureframe Audit Partner NetworkThe examination itself, and the auditor’s feeA CPA firm, paid separately

The gap in that table is the application. An integration can see that branch protection is on for your repository; it cannot see whether your API checks who owns a record before it returns one. The same split, control by control, is in which SOC 2 controls are code and which are paperwork.

A policy file is not proof either. In my audits, a health-data product’s safety-policy file was exactly what a buyer or auditor would point to, and nothing loaded it at runtime; the full story is in a safety policy nothing loaded at runtime. A platform can store that file and mark the policy control green. Only the code decides whether the rule runs.

Security compliance software and IT compliance software are broader labels for the same products. SOC 2 compliance automation software need not be SOC 2 only. Drata’s help center, in the table below, lists frameworks from SOC 2 to ISO 42001, so the SOC 2 compliance tools on a shortlist can double as general compliance tools when a customer names a second framework. There is no best SOC 2 compliance software in general: the best compliance software for your company is the one whose integrations cover your host, database, code host and identity provider, at a renewal price you can live with. The “best” lists in the results for this search are written by platforms, consultancies or their resellers, so I don’t rank platforms on this page, and anyone shortlisting the best compliance management software for a five-person company will learn more from the eight questions near the end than from a list.

What compliance automation is, and what continuous compliance means

Compliance automation is software that collects control evidence through integrations and tests it against a framework on a schedule. Continuous compliance is the same checks run daily, so drift shows before the audit period is spoiled. It automates the evidence. The controls themselves, and the examination, are not automated.

Compliance as code is the engineering version of the same idea: a control written as a policy file or a CI check that fails the build when the rule is broken. Open Policy Agent describes itself as “an open source, general-purpose policy engine” that lets you “specify policy as code”, and says it can enforce policies in “CI/CD pipelines” among other places. A check like that is what turns a platform’s red test green without anyone clicking through a console, and it keeps the fix from quietly reverting.

Continuous compliance monitoring means the checks run every day instead of once before the audit, and continuous control monitoring is the same thing counted control by control. An admin account without MFA or a storage bucket made public shows up the week it happens rather than in the auditor’s sample. That matters most for a Type 2 report, which covers a period rather than a single date; the difference is set out in SOC 2 Type 1 vs Type 2. The kinds of automated compliance monitoring worth having, in my view, are configuration checks (MFA, public buckets, encryption settings), personnel checks (joiners and leavers), and evidence refresh, so a screenshot from March does not stand in for September. Both “Continuous Control Monitoring” and “Personnel Onboarding/Offboarding” are on the Secureframe list in the table above.

Ongoing compliance is where this pays off. Continuous compliance automation does the rechecking, so the second audit period should take less effort than the first, provided the fixes behind the green checks were real. The continuous compliance tools worth paying for tell a named person when a check turns red, instead of waiting for someone to open the dashboard.

GRC stands for governance, risk, and compliance, the term in NIST’s glossary entry for GRC. GRC automation is the enterprise name for the wider category, and a security and compliance automation platform is the same idea with security checks added to the list. What gets sold as automated compliance management is mostly the task list: who owes which policy acknowledgment or evidence upload. Automated compliance reporting is the export an auditor reads.

In my reading, no compliance automation tool decides the scope, makes the judgment calls or performs the examination, and the fixes inside your own code stay with an engineer. No automated compliance solution replaces the CPA firm in the table at the top. So SOC 2 compliance can be automated at the evidence end and not at the controls end. An automated compliance platform sees only what its integrations can read, so automated compliance tooling stops at the same line: it can read your settings, not what your application’s own code does.

The platforms by name, in their own words

Each row below is what the vendor says about itself, or for SafeBase what Drata’s help center says, on a page that answered a plain request on 27 September 2026. No row comes from a listicle. Sprinto has no row because its site refused a plain request when this page was planned.

PlatformWhat its own page says it is or offersSource and date
DrataA help center with a frameworks collection (SOC 2, ISO 27001, HIPAA, PCI DSS, Cyber Essentials, ISO 42001 and others) and product collections for connections, controls, monitoring, evidence, policies and personnelDrata Help Center, 27 Sep 2026
Vanta”Agentic Trust Platform”, with the integrations line quoted aboveVanta home page, 27 Sep 2026
SecureframeThree packages, “Fundamentals”, “Complete” and “Defense”, with the feature list in the table aboveSecureframe packages page, 27 Sep 2026
Thoropass”Laika Compliance, LLC dba Thoropass Assurance is a licensed certified public accounting firm registered with the American Institute of Certified Public Accountants (AICPA)“Thoropass company page, 27 Sep 2026
Delve”Whether you’re getting compliant for the first time or want to make your next audit less painful, Delve gets you across the finish line faster.”Delve home page, 27 Sep 2026
SafeBaseA trust center product; Drata’s help center carries an article titled “SafeBase Acquisition” and one on “SafeBase Trust Center document collection with the TPRM Agent”Drata Help Center, 27 Sep 2026
OneTrustA solution list of “AI Governance”, “Consent & Preferences”, “Data Use Governance”, “Privacy Automation”, “Tech Risk & Compliance” and “Third-Party Management”OneTrust home page, 27 Sep 2026
AuditBoardauditboard.com redirects to optro.ai, which calls itself “AI-Powered GRC Software”optro.ai, 27 Sep 2026

Going by its own help center, Drata software is used to run a compliance program across many frameworks, SOC 2 among them, and the Drata app is organized around connections, controls, monitoring and evidence. The same help center uses GRC vocabulary in its own article titles, such as “GRC Roles & Responsibilities” and “GRC Before and After Automation”, so, by those titles, Drata’s compliance automation doubles as a GRC tool.

Laika Compliance is a name you meet on Thoropass’s company page: the licensed CPA firm in the table is Laika Compliance, LLC, doing business as Thoropass Assurance, while Thoropass, Inc. calls itself “a leading cybersecurity and compliance professional services and technology firm”. That is what Thoropass is by its own account, and it makes the independence question concrete: when a platform and an audit firm share a brand, ask which legal entity signs your report.

Secureframe, by its packages page, is one platform sold in those three tiers. SafeBase, by Drata’s help center, is a trust center: the page where a customer reads your security documents. Vanta’s trust platform label points the same way: its home page puts “Compliance, risk, and proof” in one “Agentic Trust Platform”, so a trust management platform, in that vocabulary, sells the compliance program and the proof a customer reads as one product.

Drata’s main competitors, for a small SaaS, are the other rows above. The products overlap heavily, and anyone weighing Drata alternatives should compare the three things that differ for a small SaaS: whether the price is published, which auditors the platform works with, and whether its integrations cover your stack. Delve pitches both the first-time buyer and the company facing its next audit, so the Delve competitors a small company compares it with are the other SOC 2 platforms here. OneTrust and AuditBoard have a different set of competitors: by their own pages, those two sell AI governance, privacy and GRC suites, which is the next section’s purchase.

Audit and GRC software for larger companies: a different purchase

Audit and compliance software for internal audit and risk teams is a different purchase from a SOC 2 platform, even where the words overlap. In my reading, the buyer is the compliance department of a regulated or larger company. Its internal audit team runs audits in compliance audit management software. Its risk team follows regulatory change in compliance tracking software, or in a compliance and risk management software suite that spans many regulations. Implementing GRC at that scale is a project of months, and a GRC implementation needs an owner in every department before its regulatory compliance automation does anything useful. Automated regulatory compliance software of this kind follows rules across many jurisdictions; a SOC 2 platform follows one set of criteria. The best IT audit software for an internal audit function, and the compliance audit tools that come with it, answer questions a SaaS of two to twenty people does not have. My test for the difference: if nobody’s job title includes audit or risk, the purchase is a SOC 2 platform or nothing yet, not the best auditing software on anyone’s list. OneTrust and AuditBoard, in the table above, are the two names from that end of the market on this page.

What it costs

SOC 2 help is priced in five shapes: a consultant’s fixed fee or retainer, a platform subscription, an auditor’s fee per report, a pen tester’s fee per test, and an engineer’s time. Most of the published figures for audits and platforms sit in one cost breakdown; the vCISO figures are on this page.

Figures on this page come only from a seller’s own page on the day it was read, and any figure another page on this site already owns is pointed to rather than repeated.

SellerHow it pricesWhere the figures areSource and date
Consultant or readiness assessmentA fixed feeThe gap-assessment and readiness figures sellers publish, in the cost article’s section on other line itemsSellers’ own guides, read 3 Sep 2026
Compliance platformA subscriptionWhich platforms print a price, and what, in the cost article’s platform tablePlatforms’ own pricing pages, read 3 Sep 2026
AuditorA fee per reportThe published audit fee figures, in the cost articleAudit firms’ and sellers’ own pages, read 3 Sep 2026
Pen testerA fee per testThe page on buying a test, linked belowNot repeated here
vCISOA monthly retainer, or hourly for one-off projectsThis page, in the next sectionTwo sellers’ own pages, read 27 Sep 2026

The figures themselves are in SOC 2 cost for a small SaaS. Buying a penetration test, and what a small company can expect to pay for one, is in affordable penetration testing.

Prices checked: vCISO figures on 27 September 2026 on each seller’s own page; all other figures by pointer to the cost article, whose figures were pulled on 3 September 2026.

What the platforms cost: Drata pricing, Reddit threads, and where the published figures are

Drata pricing has to be pieced together from Reddit threads and sales quotes, because Drata had no pricing page when the SOC 2 cost breakdown checked on 3 September 2026. The figures in those threads come from one buyer’s negotiation each: useful for the shape of a quote, never a price to budget against.

The cost article’s platform table records, for that date, which platforms print a price and which do not, Drata’s row included, so it is not copied here. When the search results for Drata pricing on Reddit were pulled on 17 September 2026, the top four were Reddit threads, and two of their snippets quote individual buyers’ figures. Read them as anecdotes. A Drata cost quoted on a forum depends on the frameworks, headcount, term and discount that buyer negotiated, none of which you can check.

A Drata SOC 2 pricing quote, like any platform quote, settles only once you know which payee it covers and what it leaves out; the questions that tell you are in the cost article above. AuditBoard pricing is no easier to find: the old address now leads to Optro, whose pricing page offers “flexible pricing”, shows a form, and prints no figure.

The readiness consultant, the vCISO, and the gap assessment in between

vCISO cost is usually quoted as a monthly retainer, and by the hour for one-off projects. One seller publishes tiers at $2,500 and $4,500 a month; another states that virtual CISO retainers run $3,000 to $15,000 a month industry-wide. A readiness consultant’s fixed-fee project is the other way to buy the same preparation.

A vCISO is one way to buy the consultant row: a part-time security lead on a retainer. The two sellers behind those figures are named here and not linked. Curated Cyber’s pricing page lists a “vCISO Guidance” tier at $2500 per month, with the line “We DO NOT execute on deliverables but will give guidance to the business on how to execute on them.”, and a “vCISO” tier at $4500 per month that says “We are available anytime and execute on all your Curated deliverables.” The market figure is vCISO.com’s own statement about the market it sells into: “Industry-wide, virtual CISO retainers run $3,000 to $15,000 per month.” The same page says most senior firms price vCISO work by monthly retainer and puts hourly vCISO rates at $200-$400 per hour for one-off projects.

So vCISO pricing, and CISO-as-a-service pricing under its other name, comes in two shapes, and the difference between the two tiers above is the one to ask about in any quote: guidance only, or someone who does the work. Both sellers’ figures were read on their own pages on 27 September 2026.

What the retainer buys beyond SOC 2, and how it compares with a part-time technical lead, is covered in fractional CTO vs agency, and where a vCISO fits. For a company of two, I’d expect a fixed-fee readiness project to be a smaller purchase than a retainer, though that is a judgment about scope, not a price.

What a SOC 2 readiness consultant does, week by week

A SOC 2 readiness consultant takes you from “the customer asked for SOC 2” to “the auditor can start”. The first step is scope, and the criteria come from the AICPA’s trust services criteria, which cover “security, availability, processing integrity, confidentiality, or privacy”. The six steps below are my reading of the job, not a standard:

  1. 01 Scope. Which system the report covers, and which of the trust services categories are in it, chosen from what your customers actually ask for.
  2. 02 The gap assessment. What exists against what the criteria ask for. The next section says what a useful one hands back.
  3. 03 Policies. Tailored to how the company actually works, not downloaded and signed.
  4. 04 A remediation plan. Every gap with an owner and a date, and the engineering gaps marked as engineering.
  5. 05 An evidence dry run. Pull the evidence the auditor will ask for, before the auditor asks, and see what is missing.
  6. 06 The hand-off to the auditor. The scope, the system description and the evidence index, ready for the first request list.

A good consultant says which gaps are engineering work and who should do them; one who promises to close a code gap with a policy is selling paperwork. SOC 2 readiness consulting sold by the audit firm’s own affiliate raises an independence question worth asking, and the questions that separate the payees are in the cost article.

Gap assessment: what you get, and the tools sold for it

A compliance gap is a requirement with no control, or a control with no evidence. A useful gap assessment, by my working rule, has five columns: the gap, the criterion it maps to, whether it is paperwork, configuration or code, the owner, and the evidence that closes it. Code gaps need an engineer.

What a gap assessment is, and how it differs from a readiness or a risk assessment, is defined in the no-security-team article linked above. What matters here is the output. My working rule is that every compliance gap analysis should come back in this shape; the rows below are illustrative.

GapCriterion or control it maps toKindOwnerEvidence when closed
No written access control policyAccess controlPaperworkFounderThe approved policy, with acknowledgments
MFA not enforced on cloud console adminsAccess controlConfigurationWhoever owns the cloud accountThe enforced setting, or the platform’s passing check
Any signed-in user can read another customer’s invoice by changing the idAccess controlCodeEngineerA test that logs in as one customer and fails to read another’s record
No audit log of role changesMonitoringCodeEngineerLog entries for a test role change
Backups never restoredAvailability and recoveryConfiguration and processEngineerA dated restore record

A gap assessment tool can be a spreadsheet of the criteria, a platform’s readiness view, or a questionnaire product. The tool matters less than the third column, because a code gap, such as a missing tenant check on an endpoint or no audit log of role changes, is not closed by the consultant, the platform, the auditor or the pen tester. I’m not naming a best tool. Outside SOC 2, a cyber security gap analysis is the same exercise against a different list, such as the MVSP controls checklist, and the five columns still work.

Audit readiness: the assessment and the checklist before the auditor arrives

Audit readiness means every control in scope has an owner, is operating, and has evidence a stranger can find. A ten-line check, my working rule, covers scope, policies, access, joiners and leavers, change management, backups, logging, vendors, risk and incident response. An audit readiness assessment is a paid walk through that list, usually sold as the step before the audit.

That is the whole audit readiness definition I work to, and its meaning in practice is the list below. If you are preparing for an audit, use it as an audit prep checklist: tick a line only when you can open the evidence, not when you believe it exists.

  • Scope and system description written down.
  • Policies approved, and acknowledged by everyone they apply to.
  • An access list for each system, with MFA shown.
  • Joiner and leaver evidence: access given on the first day, removed on the last.
  • Change management evidence: pull requests, reviews, CI results.
  • Backup and restore evidence, including a dated restore.
  • Logging and alerting evidence.
  • A vendor list, with each vendor’s own report where it has one.
  • A dated risk assessment.
  • An incident response plan, with a record of a tabletop run.

Where each line lives in a builder-generated app is set out in the no-security-team article’s control table, linked above. The questionnaire version of the same audit readiness checklist is a separate question: what a security questionnaire asks.

Deliverable 12.6 of the Production Hardening Sprint delivers a technical controls checklist with supporting evidence organized for enterprise security review, and it is verified this way: link each documented control to its owner, configuration, or test evidence. This deliverable is not a SOC 2 audit report.

The auditor: SOC 2 audit services, audit firms, and what only they can do

SOC 2 audit services are the examination and the report, and they are bought from a CPA firm; the AICPA note quoted at the top of this page is the rule. That same checklist, written for reviewing a vendor’s SOC 2 report, asks “CPA firm license current?” and “What is the current peer review result?”, and points to the AICPA’s peer review site for the second. Both checks work just as well before you hire a firm.

SOC 2 audit firms run from small practices that do little else to large national ones, and platforms keep partner lists, as the Secureframe audit partner network in the table above shows. For choosing among SOC 2 audit companies, the four questions the profession publishes are in the do-I-need article linked above, not repeated here. I’d add two: how many first-time reports for companies under twenty people the firm issued last year, and how it works with your platform. IT audit companies are the wider category, auditing technology controls for many frameworks, SOC 2 among them. When one firm sells SOC 2 compliance audit services and readiness work together, ask which entity signs. An auditor that offers to write your controls is offering to audit its own work.

When to pick each

The order for a small SaaS has four steps: fix the engineering the report will examine, write the controls down, then buy the platform and book the auditor together, and time the pen test inside the audit period. A consultant comes first only when the deal has a date and nobody has done this before.

Every judgment in this section is mine, not a standard, and each option below has a case where it is the wrong first purchase.

A SOC 2 compliance consultant or vCISO

Fits when nobody on the team has been through an audit and the deal has a date on it. Fits when the customer’s questionnaire is already on the table and you need someone to read a big customer’s security questionnaire with you. Does not fit as a substitute for the engineering, because a consultant hands back a list of gaps and the code gaps stay open until someone changes the code. Does not fit when your platform’s onboarding already covers a simple scope.

A compliance platform

Fits when the report is definitely needed, a Type 2 is coming with months of evidence to collect, and your stack is one its integrations cover. Does not fit as the first purchase on an app whose basics are failing: the dashboard shows red for months while the subscription runs. Does not fit when your one customer would accept a questionnaire and a pen test summary instead; the do-I-need article linked above covers that trade.

A pen test, and the AI company SOC 2 pentest question

Fits when the customer’s contract, the auditor’s expectation or your own scope names one. Whether SOC 2 requires one, and whether an AI pentest is enough, is the live pen test article’s question, linked in the first section.

For an AI company, a SOC 2 pentest scope should add the model-facing surface: prompt injection paths, the permissions of any tool the model can call, spend limits, and the data sent to model providers. The attack itself is explained in what is prompt injection. Which kind of testing seller does what is compared in web application security testing services; buying one at a small company’s budget is the affordable penetration testing page linked under What it costs.

Does not fit before the holes you already know about are closed, because you pay for a report of what you already knew. Time it inside the audit period so the report is current when the auditor reads it.

The Production Hardening Sprint’s deliverable 3.10 tests the five highest-risk externally reachable attack surfaces, remediates findings, and delivers the methods and evidence. Formal third-party certifications and independent audit opinions are separate from the sprint deliverables.

The auditor

Fits when a customer or investor requires the report itself. Does not fit as a source of advice on building the controls it will examine. Book early: in my view, an auditor’s calendar fills faster than a small team’s evidence comes together.

Engineering first: is SOC 2 worth the investment for an early stage SaaS?

Whether the report is worth it depends on a named deal, and that argument belongs to the do-I-need article from the first section. What is worth doing either way is the engineering the report would examine, because the same work answers questionnaires, technical due diligence and the next incident.

I put engineering first because of three numbers. In the apps I audited in June and July 2026, 17 of the 21 third-party apps had no error tracking or alerting: when a user hits an error, nothing records it. At least 17 of the 21 third-party apps had no deploy gate, and so did all 5 founder apps: every push ships straight to production with nothing checking it first. At least 23 of the 26 audited apps had zero working automated tests. The 26 are 21 public and held-out third-party apps plus 5 of my own, a selected set I audited, not a random sample or a rate for AI-built apps in general.

Fits when the app was built fast and the basics are unproven. Does not fit when the app is already sound and the gap is paperwork, or when the customer needs the report next month; then the consultant and the platform come first, and the fixes arrive as their findings. Investors read the same evidence: see what investors look for in code, and for the data room, how to prepare for technical due diligence.

The other frameworks a customer may name: ISO 27001, Cyber Essentials, an ISMS

The frameworks a customer may name, ISO security standards included, come down to three documents: a SOC 2 report from a CPA firm, an ISO/IEC 27001 certificate from an accredited certification body, and a UK Cyber Essentials certificate. Which one a buyer asks for follows the buyer’s market and template, and the engineering controls underneath overlap heavily.

FrameworkWhat you end up holdingWho issues itSource and date
SOC 2A report on your controls, for a date or a periodA licensed CPA firmThe AICPA’s SOC 2 report review checklist, read 27 Sep 2026
ISO/IEC 27001A certificate that your information security management system meets the standardAn accredited certification body (“a third-party accredited certification body” in Microsoft’s description of its own audits)Microsoft’s ISO/IEC 27001 page, read 27 Sep 2026
Cyber EssentialsA UK certificate at one of two levels, Cyber Essentials or Cyber Essentials PlusAn assessor, through IASME, the NCSC’s Cyber Essentials Delivery PartnerThe NCSC’s Cyber Essentials page, read 27 Sep 2026

ISO 27000 is the family name. Microsoft’s ISO/IEC 27001 page says the ISO/IEC 27000 family of standards “outlines hundreds of controls and control mechanisms”, and 27001 is the member Microsoft certifies against. I quote no ISO text directly, because iso.org refused a plain request when this page was planned.

An IT security management system, or a cyber security management system, is the plain name for what ISO/IEC 27001 calls an Information Security Management System (ISMS). Microsoft’s page says the standard “formally specifies” one, and that it “brings information security under explicit management control”.

Which document a buyer asks for follows the buyer’s market and its procurement template; a UK central government buyer, for one, may name Cyber Essentials for the reasons in the procurement note below. Nothing on this page is legal or certification advice; where a scheme is described as required, the source says by whom and for what.

ISO 27001, in two sentences

ISO/IEC 27001 certification is a certificate that your management system meets the standard, issued by an accredited certification body after an audit. Two questions sit outside this page: what ISO 27001 certification costs a small SaaS, and how long it takes; and SOC 2 certification, and how it differs from ISO 27001.

Cyber Essentials and Cyber Essentials Plus: the UK scheme

Cyber Essentials is the minimum standard of cyber security the UK Government recommends, built on 5 technical controls. It has two levels: Cyber Essentials, a verified self-assessment marked by an assessor and priced by organization size from £320 plus VAT, and Cyber Essentials Plus, which adds independent technical testing priced by network size and complexity.

In the scheme’s own words, the NCSC’s Cyber Essentials page calls Cyber Essentials “the minimum standard of cyber security recommended by the Government for organisations of all sizes”, developed by the NCSC and “aligned to five technical controls”.

LevelHow it is assessedThe five technical controlsPrice as publishedSource and date
Cyber EssentialsSelf-led route: register through IASME, pay, complete the verified self-assessment; answers “signed-off by a board member or equivalent and then marked by an assessor”Firewalls; Secure configuration; Security update management; User access control; Malware protection”priced according to the size of your organisation, starting at £320 +VAT”NCSC, read 27 Sep 2026
Cyber Essentials Plus”The same protections, but with more rigorous, independent technical testing”The same five”priced according to the size and complexity of your network”; “Quoted” in the NCSC’s comparison tableNCSC, read 27 Sep 2026

The Cyber Essentials checklist is those five controls, and the NCSC lets you preview the “Question Set” for free before you register. The Cyber Essentials certification cost at the first level starts at the figure in the table and rises with size; Cyber Essentials costs at the Plus level are quoted, not published. The Cyber Essentials Plus audit is the independent technical testing, and the Cyber Essentials Plus requirements are the same five controls, independently tested on your systems rather than only self-assessed.

Who needs it: the NCSC says “A growing number of organisations require suppliers to be certified to bid for work”. For UK government work, Procurement Policy Note 014, published 17 February 2025, replaces PPN 09/14 and says that since 2014 the government has required suppliers bidding for certain types of public contracts to hold Cyber Essentials or Cyber Essentials Plus, or show equivalent controls. It applies to central government departments, their executive agencies and non-departmental public bodies, and NHS bodies, for contracts such as those where a supplier handles citizens’ personal information, and it says a required certificate “must be renewed annually by the supplier for the duration of the contract”. So a Cyber Essentials cert is not a one-off: the note’s own FAQ says suppliers “must recertify every 12 months in order to maintain a valid certificate”.

Cyber Essentials vs ISO 27001 is a short baseline of technical controls against a full management system, and holding one does not give you the other. A US SaaS with no UK buyers can skip Cyber Essentials until a UK buyer asks.

The SOC report family is a separate page

The other SOC reports, the attestation standards they are issued under, the controls a customer has to run on its own side, and the SOC logo are a separate topic, named in the ISO section above as SOC 2 certification. None of that is retold here.

If the product is AI: an AI management system, and the laws regarding AI

An AI management system, or AIMS, is what ISO/IEC 42001 sets requirements for: establishing, implementing, maintaining and continually improving how an organization manages AI. Laws regarding AI differ by jurisdiction. The EU’s AI Act, Regulation (EU) 2024/1689, defines 4 levels of risk and became applicable on 2 August 2026, with some rules phased in on other dates.

Microsoft’s ISO/IEC 42001 page describes it as “an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations”. What an artificial intelligence management system aims to do, in plain terms, is give AI the same written, owned, reviewed treatment an ISMS gives security, so a company that already runs an ISMS extends habits it has.

The law regarding artificial intelligence on this page is the EU’s only. The European Commission’s AI Act page says the regulation “entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions”: prohibited practices and AI literacy obligations from 2 February 2025, the governance rules and the obligations for general-purpose AI models from 2 August 2025, and the high-risk rules later, from 2 December 2027 for high-risk use cases in certain sensitive areas and 2 August 2028 for AI embedded in regulated products. Those two later dates come from the AI Omnibus, which, by the same page, reached political agreement on 7 May 2026 and entered into force on 27 July 2026. Which obligations apply depends on the risk level of your system, and that reading of the artificial intelligence law and regulation is a lawyer’s job, not a platform’s. I read no US government source for this page, so I make no US statement.

Artificial intelligence compliance monitoring, as a product category, is early and defined by the vendors selling it. What a SOC 2 report covers for AI features is answered in the no-security-team article’s questions, linked above.

Questions to ask before you pay

Eight questions, with the seller each is for and what a good answer sounds like. They are my working rules, not a standard:

  1. 01 What exactly do I hold at the end, and who signed it? (all) A good answer names the document and the legal entity: a gap list from the consultant, an evidence export from the platform, a report signed by a licensed CPA firm.
  2. 02 Which of my failing checks will you fix, and which are mine? (platform, consultant) A good answer is a list of named checks, not a promise to help with remediation.
  3. 03 Who on your side has taken a company under ten people through a first report? (consultant, auditor) A person you can speak to, and roughly how many such reports they have done.
  4. 04 Which integrations cover my stack today, by name? (platform) Your host, your database provider, your code host and your identity provider, each a yes or a no, with every no listed as manual evidence you will upload.
  5. 05 What happens to my evidence and policies if I cancel? (platform) An export in a format you can open, and the date by which you have to take it.
  6. 06 What is the renewal price, and what changed it for customers like me last year? (platform) A figure, or the rule the price follows, such as seats or frameworks, in writing.
  7. 07 Is a retest after fixes included? (pen tester) Yes, with the window stated, so the report you hand over shows the fixes.
  8. 08 What in my application will you not look at? (all) From the first four rows of the seller table, the honest answer is the code. That is the gap this page is about.

The questions for the auditor itself are the profession’s four in the do-I-need article, and the questions that tell you which payee a quote covers are in the cost article; both are linked in the first section.

Where the sprint fits

Deliverable 12.6 of the Production Hardening Sprint is the controls checklist with evidence described under audit readiness above, and deliverable 3.10 is the targeted test described under the pen test. The targeted security tests cover the five priority attack surfaces documented in the report, and the package also includes an OWASP review and a controls checklist with evidence. Legal advice and certification are separate services; the sprint implements and documents the technical data-handling controls. Hosting, paid tools and API usage remain in the client’s own accounts, and the sprint covers one codebase. Each deliverable is on the published list of 123 deliverables.

Common questions about SOC 2 readiness help

Which is better, Vanta or Drata?

Neither, in general. The two products overlap heavily, and for a small SaaS the choice comes down to three things: whether integrations exist for every system in your stack, which auditors each works with, and the quote you are actually offered. Get both quotes on the same scope and framework before you compare them.

Is SOC 2 hard to get?

The paperwork is tedious more than hard. The hard part is operating the controls for the whole audit period and being able to show they operated, and for an app that was built fast, the engineering gaps usually have to close before any of that can start.

Who are the top 10 SOC 2 auditors?

I don’t rank auditors, and a ranked list would not tell you the two things worth checking. Before you hire any firm, confirm its CPA firm license is current and look up its current peer review result, the same two checks the AICPA’s review checklist applies to the firm behind a vendor’s report.

What is better than SOC 2 compliance?

Nothing is better in general; the right document is the one your customer asked for. An ISO/IEC 27001 certificate is a different document from an accredited certification body, Cyber Essentials is a UK scheme, and many first customers will accept a completed security questionnaire with evidence attached.

Can ChatGPT do a gap analysis?

Partly. It can turn the criteria into a question list and draft policies from what you paste in or connect. It cannot show that a control operated through the audit period, which is the gap that matters. Never paste secrets or customer data into it.