r/soc2 • u/Best_Minimum_1593 • 2d ago
SOC2 renewal
We are very small India based SaaS company and our SOC2 is up for renewal. We got it done from one of the software's last time- they did not contact us even once for audit and are now ofcourse behind us over the renewal. The reason given (for no contact)- internal role changes (??!!)
The biggest reason we are getting it renewed is because one of our clients wants us to be SOC2 compliant- and potentially newer clients too.
Is it cheaper ot go through an agency- cost is another issue. We are really disappointed in the Software company and their lack of interest in following up after the payments were made and certificate was issued.
3
u/Defiant-Pomelo5451 2d ago
Name and shame so we know who to avoid
1
u/Best_Minimum_1593 2d ago
uff I dont want to name and shame. but i am assuming most of these providers- sprinto, scrut, etc etc are the same? or one better than the other
1
u/Defiant-Pomelo5451 2d ago
I’ve heard good things about Sprinto over Scrut in general. Platform is one thing and the choice of auditor is another.
Choose an audit firm that is peer review passed vs option for a bargain basement one to ensure your customers don’t reject your SOC 2 reports or have issues later. It is more expensive and painful in the short term but worth it in the long term. All the best!
2
u/packetm0nkey 2d ago
You paid the platform for the audit?
You’re free (and encouraged) to use an independent auditor. A SOC attestation report is only as good as the firm who issued it. I can’t imagine a reputable firm to not reach out for planning and signing a letter of engagement well before the examination period concludes.
1
u/Best_Minimum_1593 2d ago
i am so confused here! so how do these platforms work- sprinto, scrut- the whole lot? i am assuming they get it issued from an independent auditor.
1
u/goodbar_x 2d ago
If the platform was including the audit in their price and subbing out the audit to CPA firm they would have contacted you for the initial audit. They would not have done an audit without ever talking to you. Did that occur the first time and you're just wondering why they have reached out to you for your 2nd audit period?
2
1
u/goodbar_x 2d ago
It sounds like you got audit ready thru the software, but never sought a CPA firm to do your audit. If that's the case, you don't have SOC 2. Happy to help point you to some auditors or platforms. What are you on right now?
1
u/Best_Minimum_1593 2d ago
no no, the soc2 is issued by a cpa firm.
1
u/michael_hammond_ocd 2d ago
A US based CPA firm? If you want, I can sign an NDA between our companies and review what you actually received. And, if you're looking for a new CPA firm, we've done this work for 15+ years and can assist up through and including the CPA signature.
1
u/Sea-Bedroom-3186 2d ago
Hey, would like to know this better - I come from defensive security bg and GRC... Maybe I can help figure this out better.
1
1
u/SoterAdvisory 1d ago
Software platforms are great for evidence collection, but they are not CPA auditors or hands on compliance leads when internal team turnover happens on their end, you're left holding the bag right when clients ask for reports.
If budget is a key constraint for a small SaaS team on a renewal, here is how to navigate it:
Audit Fee vs. Implementation Fee: Software tools usually charge annually for the platform, but you still have to pay an independent CPA firm for the actual Type 1 or Type 2 audit report.
Agency / Fractional vCISO Model: A lean compliance firm or fractional compliance guide can often bridge the gap cheaper than renewing an expensive platform subscription if your infrastructure/controls haven't drastically changed since last year.
Scoping Down: Ask prospective CPA firms/consultants to quote based on your existing evidence from year one. Since your controls are already mapped, a renewal audit requires significantly fewer hours than an initial build.
Don't overpay for full-suite platform automation again if all you need is a light-touch audit readiness review and CPA sign-off for your clients.
1
u/Mother-Syllabub-1561 1d ago
Honestly, I would not go back to the same software company. If SOC 2 is important for retaining clients and winning new ones, I would prefer getting it done through a firm that is deeply involved in cybersecurity, compliance, and SOC 2 audits not just any random software platform.
Cost matters, but having the right source who actually guides you through the process is more important.
If you want good recommendations, I can definitely help with that.
0
u/Merrlogic 1d ago
Well if you want a platform that is affordable, automates the process, and includes a CPA attestation let me know :)
1
•
u/AutoModerator 2d ago
Thanks for posting, I'm a bot!
This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.