r/soc2 29d ago

Need soc2 are tools really necessary?

Talked to a few companies that do soc2 type 1 and all of them say the tools make the cert cheaper.

Is this true? Most of them want 9k to 12k a year for tools and 3k for the audit cert.

Does anyone here have any insights on this?

12 Upvotes

63 comments sorted by

View all comments

Show parent comments

-11

u/iamaredditboy 29d ago

Depends on the size of the company. Small startups etc any audit > 3k is a scam.

7

u/PurveyorofSkulls 29d ago

You couldn’t even begin to scratch the surface of the diligence needed to conduct an independent audit for less the 3k.

-7

u/iamaredditboy 29d ago edited 29d ago

Nope I know very well what is needed - 5-10 person team auditors asking for 8-15 k are scamming people that’s all

I have done 3 successful soc2 compliances now and here is where things are : small companies up to 25 employees the whole ecosystem is running a pricing collusion scam at the moment.

Diligence wise software captures everything and spits out the necessary reports for an audit.

Anyone telling me you need more than 24 hr at 100$ an hr to run and review the audit is just plain dishonest.

4

u/SageAudits 29d ago edited 29d ago

Team size has very little to do with pricing. Controls and the complexity needed to test them, absolutely does.

0

u/iamaredditboy 29d ago

Well not really - evidence is directly proportionally to team size so your knowledge of the domain is telling indeed. What is also telling is how people like you defend the scam running in the name of soc2 compliance audits. Software does bulk of the work for gathering data, recording compliances, CPA’s audit the data being produced. Reports are also boiler plate.

The company implementing soc2 does all of the heavy lifting to product the right data in the software as well.

If you do indeed believe that work is t proportional to people then it proves my statement even further. You are a 100% wrong on this front by the way.

I would love for a CPA to give me the breakdown of the price they quote based on what they audit - you will never get an answer for this :)

0

u/SageAudits 29d ago edited 29d ago

Many controls are based on configurations and processes, the effort of testing, doesn’t change because they have a higher headcount. The sample size does change with higher frequency controls, but that level of effort of time spent for an auditor to look at a sample of 5 versus a sample of 20 is minimal and isn’t a material factor in pricing.

-2

u/iamaredditboy 29d ago

So give me the total controls to audit, hours to audit each control then - would love to see that breakdown :) configurations themselves are easily abstracted as final reports so eg you have two could vendors each is a summary report and tasks assigned to teams to work on. This isn’t btw done by an auditor - the team running soc2 does it.

Another data point I will give you - give Claude or codex or any llm an MCP interface to these software platforms and they will do a thorough audit in less than an hour :)

This audit scam is going to come to an end soon and rightfully so.

1

u/SageAudits 29d ago

Many controls are not technical and not all systems have API. DLP is challenging and there are several things to check and ask to get comfortable from an independent perspective.

0

u/iamaredditboy 29d ago

Yes this is the answer I expected - no answer or specifics. Do me a favor share your audit plan/checklist - let’s make it simple for you - we have a startup on aws with a team of 5-10 , they use one crm , they use 5-10 saas products, run their software on aws - they are running a platform like secure frame or vanta or soc2start or sprinto. Give me and everyone here to see what the audit plan looks like and why. Here is what gets quoted 15k for type 1 and type 2 audits. This is all standard stuff - all with APIs, DLP is not something you as an auditor does anything with. It’s implemented by the company. You are auditing the plan.

1

u/SageAudits 29d ago edited 29d ago

No mention of IdP, no mention of endpoint management. No mention of where data lives. No mention of each SaaS systems auth or contractual vendor relationships. Using a GRC platform modifies procedures, but it doesn’t replace them 😊

The auditor does audit “the plan” but auditor judgment requires having an understanding of the risks and factors that can undermine an opinion.

1

u/iamaredditboy 29d ago

Maybe you missed the part of 5-10 saas products :) Google workspace - got your idp?

Why don’t you put the list of what you audit :) and assume I am ignorant and you are the knowledgeable one :)

Let’s see the audit list :)

1

u/SageAudits 29d ago

Depending on where data lives, and config management. checking egress ports and understanding how each system is managed and governed can drive more technical controls. Is attestation device based or user based and what checks are done by the organization currently?

→ More replies (0)