What if we say no to a SOC 2 request?
Saying no is a real option and it is the correct one more often than the compliance industry admits. What decides it is not principle. It is the contract value against the first-year cost, and whether the buyer has an exception path.
You can decline, and for a Canadian company under about 30 people facing a single deal worth less than roughly $60,000 CAD a year, declining is usually the right financial answer. A first SOC 2 costs $35,000 to $90,000 CAD in year one plus 200 to 500 internal hours, and it recurs at $30,000 to $60,000 CAD a year after that. One deal rarely pays for it. What decides the question is whether the request is the first of many or a one-off. The second and third buyer change the arithmetic.
$30,000 to $60,000 Recurring annual cost after year one, CAD
2 Buyers asking before declining stops being rational
When no costs you very little
| Your situation | Declining is |
|---|---|
| One prospect asking, contract under $60,000 CAD a year, no others in pipeline | Usually correct. Offer an interim package and revisit if a second buyer asks |
| The request came from a procurement template and you are a low-risk vendor | Often unnecessary. Ask which tier you are in before you decide anything |
| You do not touch customer data or hold credentials into their systems | Frequently a misapplied control. Say so, in writing, with a data flow description |
| Two or more buyers have asked in the last six months | A mistake. The cost is now spread and the next request is already coming |
| The contract is your largest, or it is the account the next ten follow | A mistake, unless the timeline makes the report impossible anyway |
| You signed a security addendum that names a SOC 2 report | Not available. You have an obligation, not a request |
The row people get wrong is the third. A meaningful share of SOC 2 requests reach vendors who never touch the customer's data, because the buyer's tiering was done by a form rather than a person. A one-page description of what data you hold and what access you have re-tiers you surprisingly often, and it costs an afternoon. What the buyer is trying to satisfy is on why your customer is asking.
The arithmetic, in CAD
Set the recurring cost against the recurring revenue, not the first invoice against the first year. A buyer's vendor review repeats annually, and a lapsed report causes a problem at their next cycle.
| Annual contract value | Year one cost | Verdict on one deal alone |
|---|---|---|
| $25,000 CAD | $35,000 to $90,000 | No. Decline or offer a substitute |
| $60,000 CAD | $35,000 to $90,000 | Marginal. Only if a second buyer is likely |
| $150,000 CAD | $35,000 to $90,000 | Yes, if the term is multi-year |
| $400,000 CAD or more | $35,000 to $90,000 | Yes, and the delay is the expensive part rather than the fee |
| Rough break-even against a single account, first year | Around $100,000 CAD of committed multi-year revenue | |
Those numbers come from the CAD cost breakdown, and the same test done against your whole pipeline rather than one deal is on is SOC 2 worth it at our size. If the verdict is yes but the number is frightening, the cheapest honest route moves the top row considerably.
How to say no without losing the relationship
Decline the artifact, not the assurance. The sentence that works names the constraint, offers something real, and leaves a trigger for revisiting.
- Say what you are not doing and why, in one line. "We are not pursuing a SOC 2 report this year at our size" is better than a paragraph of hedging.
- Offer what you can produce. A completed questionnaire, a penetration test summary and a written control description close more vendor assessments than founders expect. The full list is on what to offer instead.
- Ask about their exception path directly. Most vendor risk policies have one with a named approver and an expiry date.
- Name the trigger that changes your answer. "If this becomes a requirement at renewal, or if a second enterprise customer asks, we will start" is a commitment that costs nothing.
- Put it in writing to the person who owns the control, not only to your sales contact, so the reasoning survives being relayed.
What not to do instead of saying no
Do not say the audit is under way when it is not, do not name a date you have not tested against an observation window, and do not describe yourself as compliant. Each of those is discovered later by a person who then has to explain to their own auditor why they onboarded you. Declining honestly costs you a deal. Being caught costs you the relationship and sometimes the reference.
What no actually costs you
Usually one deal, sometimes not even that. It also costs you the queue behind it: the same request tends to arrive from every enterprise buyer in the same segment within a year or two. Declining once is a decision. Declining three times is a market position, and it caps the size of customer you can sell to. That is a legitimate strategy for a company selling to small businesses and a poor one for a company moving up-market.
The other cost is timing. Starting after the fourth request means starting with a deal on hold and no room. That is where compressed timelines and rush rates come from. Starting after the first request, with no deadline, is the cheapest version of this project, and preparing with no budget is how to do that groundwork before committing to a fee.
Will we lose the deal if we say no?
Sometimes. More often you lose it only if you offer nothing in place of the report. Buyers whose policy has an exception path will onboard a vendor with a questionnaire, a penetration test and a rating, provided somebody with authority signs the exception.
Can we say we will do it later without committing to a date?
You can, and it is honest, but it will not close a vendor assessment. An undated intention gives their approver nothing to sign. Either give a date you have checked against a real observation window or decline cleanly.
What if we already signed a contract that requires SOC 2?
Then this is not a request and declining is a breach. Read the clause for the deadline and the report type, and start immediately, because the clause was probably written assuming a timeline nobody checked.
Does declining hurt us with other prospects?
Not directly. Nobody publishes it. It hurts indirectly by capping the segment you can sell into, because the same requirement appears across enterprise procurement in a way that does not vary much by buyer.
We are pre-revenue. Should we ever say yes?
Almost never before a customer has made it a condition of signing. Money spent on a report before that point buys nothing, and the underlying control work counts toward the audit whenever it does become necessary. That case is made on SOC 2 for startups.
If the answer turns out to be yes
Get CAD quotes from Canadian firms before you commit to a date with a customer.
Get matched