What to prepare before you engage a SOC 2 auditor.

The first call with an audit firm goes better, and the quote is more accurate, when you arrive with a few decisions made and a few documents in hand.

SOC 2 guide · By Elevated Vibration · Updated October 2026

Decisions to make first

  • Type 1 or Type 2. Ask the customers who are requesting the report which they need. See Type 1 vs Type 2.
  • Scope. Which product, which systems and which teams the report will cover.
  • Criteria. Security is required. Availability, Confidentiality, Processing Integrity and Privacy are optional and add work.
  • Dates. When you want the audit period to start and when you need the report.
  • Platform. Which compliance platform you use or plan to use, and whether the auditor works in it.

Documents to have ready

  • A short description of what your product does and who uses it.
  • A diagram or list of the systems it runs on, including your cloud hosting provider.
  • An org chart and headcount.
  • The list of your important vendors.
  • Your security policies, even in draft.
  • The names of the people who own engineering, IT, HR and security.

Know where you stand

Do a readiness review before the audit period begins, either yourself or with help. The goal is to find the gaps while there is still time to close them, not during the audit. If you use a compliance platform, the list of failing tests is a good starting point.

Choose one point of contact

The auditor will send a steady stream of questions and requests. They need one person to send them to, and that person needs the time to respond. Audits slow down most when requests are spread across several people.

Questions to ask the audit firm

Have these ready for the call. We cover them in more detail in how to choose a SOC 2 auditor.

  • How many companies of our size and type have you audited?
  • Do you work inside our compliance platform?
  • What is your timeline from the end of the audit period to the final report?
  • What does the fee include, and what would next year cost?

What the auditor does not do

The auditor tests your controls and issues the report. To stay independent, they do not design your controls, write your policies or fix your gaps. That work is yours, or your partner's.

We run the readiness review, get everything prepared and then act as the auditor's point of contact. See SOC 2 readiness and audit management.

Related articles

How to Choose a SOC 2 Auditor

What to look for in an audit firm and the questions to ask before you sign.

SOC 2 Type 1 vs Type 2: Which Do You Need?

How the two report types differ, what customers usually ask for, and how to decide.

How Long Does SOC 2 Take? A Realistic Timeline

Three to six months of preparation, a three-month audit period, then the audit. What happens in each phase.

Common questions

Straight answers.

When should we contact a SOC 2 auditor?

Early in preparation. Knowing the auditor's expectations and availability before the audit period starts avoids surprises later.

Who can perform a SOC 2 audit?

A SOC 2 report is issued by an independent, licensed CPA firm.

Do we need to be fully ready before talking to an auditor?

No. You need to know your scope, report type and timeline. Controls must be in place before the audit period begins.

Getting ready for an audit?

Tell us your deadline and where things stand. We'll tell you plainly what it will take.

Book a free call