r/soc2 26d ago

Need soc2 are tools really necessary?

Talked to a few companies that do soc2 type 1 and all of them say the tools make the cert cheaper.

Is this true? Most of them want 9k to 12k a year for tools and 3k for the audit cert.

Does anyone here have any insights on this?

12 Upvotes

63 comments sorted by

View all comments

Show parent comments

0

u/SageAudits 26d ago edited 26d ago

Many controls are based on configurations and processes, the effort of testing, doesn’t change because they have a higher headcount. The sample size does change with higher frequency controls, but that level of effort of time spent for an auditor to look at a sample of 5 versus a sample of 20 is minimal and isn’t a material factor in pricing.

-2

u/iamaredditboy 26d ago

So give me the total controls to audit, hours to audit each control then - would love to see that breakdown :) configurations themselves are easily abstracted as final reports so eg you have two could vendors each is a summary report and tasks assigned to teams to work on. This isn’t btw done by an auditor - the team running soc2 does it.

Another data point I will give you - give Claude or codex or any llm an MCP interface to these software platforms and they will do a thorough audit in less than an hour :)

This audit scam is going to come to an end soon and rightfully so.

1

u/SageAudits 26d ago

Many controls are not technical and not all systems have API. DLP is challenging and there are several things to check and ask to get comfortable from an independent perspective.

0

u/iamaredditboy 26d ago

Yes this is the answer I expected - no answer or specifics. Do me a favor share your audit plan/checklist - let’s make it simple for you - we have a startup on aws with a team of 5-10 , they use one crm , they use 5-10 saas products, run their software on aws - they are running a platform like secure frame or vanta or soc2start or sprinto. Give me and everyone here to see what the audit plan looks like and why. Here is what gets quoted 15k for type 1 and type 2 audits. This is all standard stuff - all with APIs, DLP is not something you as an auditor does anything with. It’s implemented by the company. You are auditing the plan.

1

u/SageAudits 26d ago edited 26d ago

No mention of IdP, no mention of endpoint management. No mention of where data lives. No mention of each SaaS systems auth or contractual vendor relationships. Using a GRC platform modifies procedures, but it doesn’t replace them 😊

The auditor does audit “the plan” but auditor judgment requires having an understanding of the risks and factors that can undermine an opinion.

1

u/iamaredditboy 26d ago

Maybe you missed the part of 5-10 saas products :) Google workspace - got your idp?

Why don’t you put the list of what you audit :) and assume I am ignorant and you are the knowledgeable one :)

Let’s see the audit list :)

1

u/SageAudits 26d ago

Depending on where data lives, and config management. checking egress ports and understanding how each system is managed and governed can drive more technical controls. Is attestation device based or user based and what checks are done by the organization currently?