The short answer
- Preparation: 3 to 6 months, depending on the company and where you are starting from.
- Audit period: 3 months, during which your controls are monitored in a compliance platform such as Vanta.
- The audit, which takes place at the end of the audit period. Your audit firm can tell you how long their testing and report writing takes.
Phase 1: Preparation
This is where most of the work is. By the end of it, every control should be in place and working.
- Decide the scope: which systems and which criteria. Most first reports cover Security only.
- Choose a compliance platform and an audit firm.
- Connect your systems to the platform and fix the tests that fail.
- Write, approve and roll out your security policies.
- Get every employee through policy acceptance and security training.
- Complete the one-time items: risk assessment, vendor reviews, access review and an incident response exercise.
Phase 2: The audit period
For a Type 2 report, the auditor needs to see that your controls worked over time, not just on one day. For a first report that period is commonly three months.
During it, the platform monitors your systems and your team carries on as normal. The job is to keep the tests passing and to collect proof as things happen. See what you have to prove during the audit period.
Phase 3: The audit
At the end of the period, the auditor tests your controls. They ask for lists of what happened during the period, such as new hires and code changes, choose samples, and request evidence for each one. They may also hold walkthrough calls with your team. When testing is complete, they issue the report.
What slows it down
- Nobody owns the project, so it moves only when someone has spare time.
- Engineering time is needed for fixes and is hard to get.
- Policies describe things the company doesn't actually do.
- Employees are slow to finish training and install the laptop agent.
- The scope changes partway through.
What speeds it up
- One person accountable for the whole project.
- Scope decided at the start and kept small for the first report.
- The audit firm chosen early, so their expectations are known.
- A weekly check-in where open items are reviewed and assigned.
What about Type 1?
A Type 1 report describes your controls at a single point in time, so it can be completed once preparation is finished, without an audit period. Some companies get a Type 1 first to give customers something sooner, then follow with a Type 2. Check which one your customers are asking for before you decide.
We run the whole timeline for you, from readiness review to final report. See SOC 2 readiness and audit management.
