A purchase order lands in your inbox with a twelve page security addendum attached. Buried in the middle is one sentence: the vendor shall provide a current SOC 2 report. You have eleven employees, one server closet, and nobody who has ever held a SOC 2 report in their hands. The client is your biggest, and the renewal is ninety days out.
The good news is that this is a procurement checkbox, and checkboxes are negotiable more often than small vendors assume. The caveat: this is general information, not legal or accounting advice. What your contract requires is a legal question for an attorney. What an engagement would cover is an accounting question for a CPA firm. We can tell you how this usually goes. We cannot tell you what your paperwork says.
What a SOC 2 report actually is, in plain terms
Start with the correction we make most often. SOC 2 is not a certification. Nobody hands you a plaque, and no company is “SOC 2 certified,” whatever the logo on their website implies. The AICPA, the professional body behind the standards, describes System and Organization Controls as a suite of service offerings CPAs may provide in connection with system level controls of a service organization. In plain English, a SOC 2 is a report a CPA firm writes after examining how you actually run your systems.
The AICPA describes a SOC 2 examination as covering controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. Read that list again and notice the word “or.” Those are five separate subject areas, and a report does not have to cover all of them.
- A CPA firm issues it. The AICPA describes SOC 2 examinations as work performed by CPAs in public practice. Your IT provider cannot issue one, and neither can a compliance software vendor.
- It describes your controls, not your product. How you grant access, offboard people, patch, back up, and respond when something breaks.
- The scope is a decision. Which systems, which subject areas. A narrow scope is a legitimate answer, not a dodge.
The two report types, described the way your client will describe them
SOC 2 reports come in two types, and which one you are asked for drives your calendar more than anything else. We will describe the difference the way buyers and sellers talk about it rather than reciting a professional standard, because the engagement letter is where the definition that binds you actually lives.
In the shorthand everyone uses, one type is concerned with how your controls are set up, and the other with how they held up across a stretch of time. The second needs a window of history to look at, which is why you cannot buy it in a hurry. One path takes weeks of preparation. The other realistically consumes much of a year.
So get your client to say in writing which type they need and by when. Procurement often copies these clauses without knowing the difference. Ask.
Why the readiness work costs more than the audit
Owners budget for the accountant’s invoice and get blindsided by everything else. The examination fee is usually the smaller line item.
- Writing down what you already do. Most small companies have decent habits and no documentation. Turning habits into written policy takes real hours.
- Buying the tools you skipped. Centralized logging, device management, tested backups, formal vendor reviews. Each one is a subscription you carry forever.
- Changing how people work. Access reviews on a schedule. Offboarding the same day. Changes recorded instead of shouted across the office.
- Producing evidence, repeatedly. Doing the thing is not enough. You have to show a stranger you did it, on the dates you claim.
- Somebody’s calendar. One person internally has to own this, and that time comes out of revenue generating work.
We are not going to print a dollar figure, and we would be skeptical of anyone who does without seeing your environment. Quotes swing on scope, subject areas, headcount, and how much preparation you do yourself. Get three approximate ranges in writing instead: one from a CPA firm for the examination, one from a readiness consultant if you want help, and one honest estimate of your own staff hours at what they are really worth. That third number is the one people forget, and often the largest.
The honest conversation about whether the contract justifies it
Sometimes the correct business answer is to let the deal go. Run the arithmetic before your ego gets involved, and run it with your accountant.
- What is this contract worth across its full term? Not year one. The whole thing, discounted for the real chance they leave anyway.
- Is this recurring or one time? Reports go stale. Assume you are signing up to spend something like it again, on a cycle.
- Is anyone else asking? Three prospects raising it makes this a market entry cost. One client asking once is a negotiation.
- What happens if you say no? Ask directly. A surprising number of these clauses come with an exception process procurement never volunteers.
What to propose before you say yes
In our experience the client’s risk team wants assurance, not one specific document. Give them a cheaper way to get comfortable, in this order.
- Answer their security questionnaire seriously. A complete, specific, honest response satisfies a surprising share of these requests. A vague one guarantees escalation.
- Offer a documented security program. NIST’s small business guidance recommends that policies and procedures be readily accessible to employees, that employees sign a statement confirming they have read and will follow them, and that you train employees immediately when hired and at least annually after that. Achievable in weeks, and it reads as credible.
- Propose a different framework. Ask what else they accept from vendors your size. Some will take an alternative recognized framework or an independent assessment.
- Offer a commitment instead of a document. A contractual promise to deliver a report by a stated future date keeps the deal alive and spreads the spend.
- Ask what risk they are trying to retire. Occasionally they are worried about one specific thing, like where their data sits. Solve that instead.
The bottom line
A SOC 2 request is not a verdict on your company. It is a procurement control applied bluntly, usually by someone who never looked at your size. Understand what the report is, find out which type is being demanded and by when, price the readiness work honestly including your own hours, then decide like an owner instead of a nervous vendor. Sometimes the answer is yes and the work genuinely makes you better. Occasionally it is that this client is not worth what they are asking. If you are weighing whether the security work is worth doing on its own merits, our take on why cybersecurity is no longer optional for mid sized businesses covers that ground.
One last time, because it matters: this is general information, not legal or accounting advice. An attorney has to confirm what your contract requires and what you are exposed to if you cannot deliver it. A CPA firm has to define the scope, the type, and the fee. Use both before you commit to anything.
Harrison Ward Technology works with small and mid sized businesses across Denton County who are getting these requests for the first time. We do not issue SOC 2 reports, and nobody outside a CPA firm can. What we do is get the underlying technology in order, document what you are actually doing, and sit with you while you decide whether the contract justifies the effort. Our piece on what to look for in an IT partner covers the rest. Contact us today
Sources:
Comments are closed