What Vanta automates for SOC 2, and what still takes people.

Vanta removes a lot of the manual evidence collection from SOC 2. It does not run the project for you. Here is what the platform handles, what it leaves to you, and who needs to do the rest.

SOC 2 guide · By Elevated Vibration · Updated October 2026

What Vanta does

Vanta is a compliance automation platform. You connect it to the systems your company runs on, and it checks them continuously against the controls a SOC 2 auditor will test.

  • Connects to your cloud provider, identity provider, HR system, code repository and company laptops.
  • Runs automated tests, such as whether multi-factor authentication is on and whether laptops are encrypted.
  • Provides policy templates you can adapt.
  • Tracks tasks for each employee, such as accepting policies and completing security training.
  • Gives your auditor one place to review the evidence.

That is a real saving. Before platforms like this, most of that evidence was collected by hand with screenshots and spreadsheets.

What Vanta doesn't do

The platform tells you what is wrong. It does not fix it, and it cannot see work that happens outside the systems it is connected to.

Connecting everything

Each integration has to be authorized by an administrator with the right permissions. Some of your systems will not have an integration at all, so their evidence has to be gathered and uploaded manually. Every company laptop needs the monitoring agent installed, which means following up with every employee until it is done.

Fixing failed tests

The first time everything is connected, most companies see a long list of failing tests. Each one is a real task: turn on multi-factor authentication for the people who don't have it, encrypt a database, remove access for someone who left months ago, get the last few employees to finish their training. Someone has to assign each task, follow up, and confirm the test now passes.

Writing policies that match reality

Templates are a starting point. An auditor tests you against what your policies say, so each one has to be edited to describe what your company actually does, approved by leadership, and accepted by every employee.

The work no tool can see

Some controls are carried out by people and documented afterward. These typically include:

  • A risk assessment
  • Reviews of your important vendors
  • Periodic reviews of who has access to key systems
  • An incident response exercise
  • A penetration test, if your auditor or customers expect one

None of these are generated by the platform. Someone has to do them and upload the proof.

The audit period is where things get missed

A SOC 2 Type 2 report covers a period of time, commonly three months for a first report. Throughout that period the tests have to stay passing, and normal company life keeps creating new evidence to collect: people join, people leave, code ships, laptops get replaced.

Someone has to watch the dashboard every week and fix what drifts. We cover that in detail in what you have to prove during the SOC 2 audit period.

Who should own it

In most small companies the work lands on an engineer, who is pulled off the product, or on an operations manager who already has a full job. The third option is to hand the project to someone outside the company who has done it before.

We set up Vanta, clear the failing tests with your team, write and roll out the policies, and manage the audit through to the final report. See SOC 2 readiness and audit management.

Related articles

How to Set Up Vanta for SOC 2

What to connect, configure and assign when you set up Vanta, in the order that saves rework.

The SOC 2 Audit Period: What You Have to Prove

During the three-month audit period, someone has to keep the tests passing and collect proof that your controls are really being used.

What to Prepare Before You Engage a SOC 2 Auditor

The decisions and documents to have ready before your first call with an audit firm.

Vanta and SOC 2 questions

Straight answers.

Does Vanta perform the SOC 2 audit?

No. Vanta is software. An independent audit firm tests your controls and issues the SOC 2 report.

Can we get SOC 2 with Vanta alone?

Not by itself. You need the platform, people to do the setup and ongoing work, and an independent auditor.

What are the alternatives to Vanta?

Drata and Secureframe are comparable compliance automation platforms. Vanta is the one we prefer.

Who fixes the failing tests in Vanta?

Your team makes the changes inside your own systems. We tell them exactly what to change, track each item and confirm the test passes.

Need a hand with Vanta?

Tell us where things stand. We'll tell you plainly what it will take to get to a report.

Book a free call