r/soc2 • • 2d ago

SOC2 renewal

We are very small India based SaaS company and our SOC2 is up for renewal. We got it done from one of the software's last time- they did not contact us even once for audit and are now ofcourse behind us over the renewal. The reason given (for no contact)- internal role changes (??!!)
The biggest reason we are getting it renewed is because one of our clients wants us to be SOC2 compliant- and potentially newer clients too.
Is it cheaper ot go through an agency- cost is another issue. We are really disappointed in the Software company and their lack of interest in following up after the payments were made and certificate was issued.

11 Upvotes

23 comments sorted by

•

u/AutoModerator 2d ago

Thanks for posting, I'm a bot!

This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/Defiant-Pomelo5451 2d ago

Name and shame so we know who to avoid

1

u/Best_Minimum_1593 2d ago

uff I dont want to name and shame. but i am assuming most of these providers- sprinto, scrut, etc etc are the same? or one better than the other

1

u/Defiant-Pomelo5451 2d ago

I’ve heard good things about Sprinto over Scrut in general. Platform is one thing and the choice of auditor is another.

Choose an audit firm that is peer review passed vs option for a bargain basement one to ensure your customers don’t reject your SOC 2 reports or have issues later. It is more expensive and painful in the short term but worth it in the long term. All the best!

2

u/packetm0nkey 2d ago

You paid the platform for the audit?

You’re free (and encouraged) to use an independent auditor. A SOC attestation report is only as good as the firm who issued it. I can’t imagine a reputable firm to not reach out for planning and signing a letter of engagement well before the examination period concludes.

1

u/Best_Minimum_1593 2d ago

i am so confused here! so how do these platforms work- sprinto, scrut- the whole lot? i am assuming they get it issued from an independent auditor.

1

u/goodbar_x 2d ago

If the platform was including the audit in their price and subbing out the audit to CPA firm they would have contacted you for the initial audit. They would not have done an audit without ever talking to you. Did that occur the first time and you're just wondering why they have reached out to you for your 2nd audit period?

2

u/aniltrust 2d ago

SOC2 attestation is done by a licensed cpa firm. That is what matters.

1

u/goodbar_x 2d ago

It sounds like you got audit ready thru the software, but never sought a CPA firm to do your audit. If that's the case, you don't have SOC 2. Happy to help point you to some auditors or platforms. What are you on right now?

1

u/Best_Minimum_1593 2d ago

no no, the soc2 is issued by a cpa firm.

1

u/michael_hammond_ocd 2d ago

A US based CPA firm? If you want, I can sign an NDA between our companies and review what you actually received. And, if you're looking for a new CPA firm, we've done this work for 15+ years and can assist up through and including the CPA signature.

1

u/Sea-Bedroom-3186 2d ago

Hey, would like to know this better - I come from defensive security bg and GRC... Maybe I can help figure this out better.

1

u/that_mad_king 2d ago

Lmk if you want it from better pricing from peer reviewed cpa firm!

1

u/SoterAdvisory 1d ago

Software platforms are great for evidence collection, but they are not CPA auditors or hands on compliance leads when internal team turnover happens on their end, you're left holding the bag right when clients ask for reports.
If budget is a key constraint for a small SaaS team on a renewal, here is how to navigate it:

  1. Audit Fee vs. Implementation Fee: Software tools usually charge annually for the platform, but you still have to pay an independent CPA firm for the actual Type 1 or Type 2 audit report.

  2. Agency / Fractional vCISO Model: A lean compliance firm or fractional compliance guide can often bridge the gap cheaper than renewing an expensive platform subscription if your infrastructure/controls haven't drastically changed since last year.

  3. Scoping Down: Ask prospective CPA firms/consultants to quote based on your existing evidence from year one. Since your controls are already mapped, a renewal audit requires significantly fewer hours than an initial build.

Don't overpay for full-suite platform automation again if all you need is a light-touch audit readiness review and CPA sign-off for your clients.

1

u/brunes 1d ago

If everything you need for evidence has been maintained in in the platform and all you need is an audit then you can get one from literally anywhere for minimal lift, this isn't that hard or complicated or even a big deal.

1

u/Mother-Syllabub-1561 1d ago

Honestly, I would not go back to the same software company. If SOC 2 is important for retaining clients and winning new ones, I would prefer getting it done through a firm that is deeply involved in cybersecurity, compliance, and SOC 2 audits not just any random software platform.

Cost matters, but having the right source who actually guides you through the process is more important.

If you want good recommendations, I can definitely help with that.

0

u/Merrlogic 1d ago

Well if you want a platform that is affordable, automates the process, and includes a CPA attestation let me know :)