GetSOC2

A customer asked for our SOC 2 report

Nothing about this is unusual and nothing about it is fast. The reply that keeps the deal alive is a date and a plan, sent within about two business days, and it does not require you to have started anything yet.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

If a customer has asked for your SOC 2 report and you do not have one, you are six to nine months from a first Type 2 and two to four months from a Type 1. No auditor, platform or consultant changes that. What you do this week is not start an audit. Find out exactly what was asked for, work out whether the deal needs the report or the assurance behind it, and reply with a dated plan before the buyer assumes you have nothing.

2 days Before silence starts costing you the deal

6 to 9 months Standing start to a first Type 2 report

$35,000 to $90,000 First year, all in, CAD, under 100 staff

What to do in the first week

In order, and none of it costs money.

  1. Find the exact words. Ask your sales contact to forward the message, the security schedule or the questionnaire row where the request appears. There is a large difference between "do you have a SOC 2", "please provide your SOC 2 Type 2 report" and a contract clause committing you to one within twelve months. The first is a screening question, the third is an obligation you may already have signed.
  2. Find out who is asking. A procurement analyst working a checklist, a security engineer who will read the report, and a legal team drafting a security addendum want three different things. The reason your customer is asking is almost always their own vendor risk obligation rather than a standard they chose, which is what makes substitutes negotiable.
  3. Ask what the deadline is tied to. A go-live date, a fiscal year, a renewal or an internal audit each behave differently when you ask to move them. A date nobody can explain is usually a default from a template.
  4. Work out whether a Type 1 unblocks the contract. If the buyer will sign on a Type 1 with a committed Type 2 date, you are two to four months out instead of six to nine.
  5. Reply. Not with a promise of a report, with a plan that has dates in it. The wording is below.

The three honest replies

Only one of these is a lie, and it is the one most companies send.

Replies to a SOC 2 request when you do not have a report
ReplyHow it landsUse when
"We are SOC 2 compliant" with no reportBadly. There is no such status, and the reviewer who asks for the report next month gets a second, worse surpriseNever
"We do not have one yet. Here is our security posture, here is our audit plan, here are the dates"Normally fine. Most buyers have onboarded a vendor mid-audit beforeAlmost always
"We do not have one and we are not pursuing one"Ends some deals and costs nothing in othersWhen the deal does not justify the spend, covered on saying no

The middle reply is the one to write. It works because it is checkable. Name the report type you are pursuing, the Trust Services category, the observation window start date, the auditor if you have chosen one, and the month you expect delivery. Then attach whatever assurance you can produce now. What a buyer will accept in the interim is on what to offer instead of a report.

Do not say certified

SOC 2 produces an attestation report signed by a CPA firm. There is no certificate and no certifying body, so "SOC 2 certified" is wrong in a way a security reviewer notices immediately. What you actually receive explains what to send in place of a certificate.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What you are committing to, in CAD

Before you promise a date, know the size of the cheque. These are Canadian ranges for a company under 100 staff, Security criteria only.

First SOC 2, Canadian company under 100 staff, CAD
LineLeanTypical
CPA firm audit fee, Type 2 first year$20,000 to $35,000$30,000 to $60,000
Readiness support$0 to $15,000$15,000 to $60,000
Compliance platform, first year$0 to $8,000$8,000 to $30,000
Penetration test and one retest$10,000 to $18,000$10,000 to $24,000
Year one, external spend$30,000 to $76,000$63,000 to $174,000

Add 200 to 500 hours of your own team's time, which appears on no invoice. The full breakdown by line is on what SOC 2 costs in Canada. If the number above is out of reach, the cheapest honest route takes the same project down to roughly $28,000 to $45,000 CAD.

Which report can exist by their date

Work backwards from the date the customer named. Nobody compresses the observation window. It is calendar time in which your controls have to have operated.

What can exist, counting from today
Time availableWhat is achievable
Under 8 weeksNothing signed by an auditor. A completed questionnaire, a penetration test and a written control summary
2 to 4 monthsA Type 1, if readiness moves quickly and an auditor has capacity
5 to 7 monthsA Type 2 over a three month window, if preparation starts now
9 months or moreA Type 2 over a six or twelve month window, which is what a renewing buyer will eventually want

The deadline back-calculator does this against a real date and says which report cannot exist. Type 1 against Type 2 covers the choice. If the date is already impossible, say so this week rather than in month four, and read how to reset the date once before you send that message.

Three things not to do this week

Buying is the reflex and it is usually premature.

  • Do not sign a compliance platform on day two. A platform cannot backdate an observation window and cannot tell you what your scope is. Under about thirty people it is often the wrong first purchase, which the platform page takes a position on.
  • Do not let the auditor do your readiness. Independence rules mean the firm that prepares you generally cannot audit you, so hiring one firm for both usually costs you the auditor.
  • Do not commit to a report date in a contract before you have a scope. A clause promising a Type 2 within nine months, signed before anyone has looked at your logging, is a liability you cannot renegotiate later.

If the buyer will start their security review before any report can exist, passing a security review without SOC 2 lists what most reviewers accept in the meantime.

Our customer wants the report before we can possibly have one. What do we send?

Send a dated audit plan, a completed security questionnaire, your most recent penetration test summary and a written control description. Most buyers accept a vendor mid-audit on those terms with a contractual commitment to deliver the report. The full list of substitutes is on what to offer instead.

Can we start the observation window before we hire an auditor?

Yes, and it is often the right move when the date is tight. The window is a period your controls operated in, not a period the auditor is watching. What you cannot do is claim a window in which the controls did not yet exist, so the window starts when they are genuinely running.

Is a Type 1 enough to close the deal?

Often, for a first contract, when it comes with a committed Type 2 date. Buyers who have written their vendor risk policy carefully will accept a Type 1 with conditions. Buyers whose policy names a Type 2 usually cannot, because the person you are talking to has no authority to change it.

How much of this can we do without hiring anybody?

Most of the preparation, at a company under about eighty people with an engineer willing to own it. What you cannot do internally is the audit itself, which has to be a CPA firm. The internal route and its hour cost is set out on SOC 2 with no security team.

Should we tell the customer we have not started?

Tell them where you are, in specifics. Buyers discount vague answers heavily and treat precise ones as evidence of competence, even when the precise answer is that your window opens in six weeks. Vagueness is what gets you replaced in the shortlist.

Get quotes from Canadian firms

Tell us the date your customer named and what they asked for. Firms here quote in CAD against a real scope.

Get matched