AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

SOC 2 for a 20-Person Company: Type 1, Type 2, the Cost, and When You Actually Need It

SOC 2 for small business, explained plainly: Type 1 vs Type 2, what drives the cost, who really needs a report, and how a founder loses a deal without one.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The PDF that cost $180,000

The founder of a 20-person HR software company gets the email on a Thursday. The buyer, a regional hospital group, has moved the deal to procurement. Procurement has one question: please provide your most recent SOC 2 report.

He has a security page on the website. It has a padlock icon, a paragraph about encryption, and the logo of the cloud provider. He exports it to PDF and sends it over with a friendly note.

The reply arrives Monday. It is polite and it is final. The hospital's vendor policy requires a SOC 2 Type 2 report covering at least six months, and the group cannot proceed without one. The deal, worth $180,000 in the first year, goes to a competitor with twelve employees and a report.

The founder does what founders do. He searches "SOC 2 cost" and gets seven vendors who will make him "audit-ready in weeks". He calls one. The first question they ask is whether he wants Type 1 or Type 2, and he realizes he has never known the difference.

He is not behind because his security is bad. His security is probably fine. He is behind because he cannot prove it in the format the buyer's policy accepts, and the buyer's policy does not care how good the engineering is.

What the heck does this mean

SOC 2 is a report, not a certificate. A licensed CPA firm examines your controls against a set of criteria published by the AICPA and writes an opinion. The report is what you hand to a customer.

The Trust Services Criteria are the categories the auditor tests against. Security is mandatory. Availability, confidentiality, processing integrity and privacy are optional, and most first reports take Security alone.

Type 1 says your controls were designed properly on one date. It is a photograph.

Type 2 says your controls operated over a period, typically three to twelve months, and the auditor sampled the evidence. It is a film. Buyers who know what they are doing ask for Type 2, which is why the hospital did.

Readiness is the unglamorous part: writing the policies, turning on the logs, closing the gaps, and collecting evidence before the auditor arrives.

Cost has three parts. The auditor's fee, which depends on scope and period. The tooling, if you use any. And your own time, which is the biggest line and the one nobody quotes. All three together are less than the deal the founder just lost, which is the only cost comparison that matters.

The numbers that matter

Valid ISO 27001 certificates worldwide reached 96,709 in the ISO Survey 2024, published by ISO in 2025. Customer demand for a third-party attestation is not a fad; it is now the default in procurement.

Breaches that took more than 200 days to identify and contain cost $5.65 million, against $4.32 million for those resolved faster, according to the IBM 2026 Cost of a Data Breach Report. A Type 2 report rewards the controls that shorten that window, which is the argument for running them continuously rather than staging them for the audit.

98% of organizations have a relationship with at least one vendor that has been breached, per SecurityScorecard's 2025 research. That is why the hospital asked. You are the vendor.

What to do this week

  1. Put every employee and contractor behind one identity provider, turn on MFA, and write a two-line offboarding rule: access removed the day someone leaves, and someone signs that it happened. Auditors sample departures first. (CIS 5 Account Management)
  2. List every account with admin rights in your cloud, your code hosting and your database, and cut the list until it hurts. A 20-person company with nine admins has a finding waiting to happen. (CIS 5 Account Management)
  3. Turn on audit logging in the cloud console, the identity provider and the production database, and set retention to twelve months. A Type 2 is built on logs that exist for the whole observation period, so today is the earliest possible start date. (CIS 8 Audit Log Management)
  4. Make the vendor list: hosting, email, payroll, support desk, any subprocessor that touches customer data. Collect each one's SOC 2 or equivalent and note who reviewed it. (CIS 15 Service Provider Management)
  5. Schedule a quarterly access review on the calendar now, and do the first one this week: every user, every system, does this person still need this. Keep the spreadsheet as evidence. (CIS 6 Access Control Management)
  6. Pick the observation window and tell the auditor. Six months starting the first of next month means a Type 2 report before your next renewal season, and a Type 1 in the meantime if a deal cannot wait. (CIS 8 Audit Log Management)

Where AccuSights fits

We do the readiness work, not the badge selling. Our team implements the controls a SOC 2 auditor will test at a reasonable rate, from identity and logging to data loss prevention, scanning and protection of the assets in scope, and we keep the evidence flowing so the observation window is not a scramble. If you are not sure a report is needed at all, take the three-minute Cyber Hygiene Test, then book 15 minutes with an engineer who has read more SOC 2 reports than he would like to admit.

Questions people ask

How long does SOC 2 take? A Type 1 can be issued a few weeks after your controls are in place, because it only looks at a single date. A Type 2 needs an observation window, commonly three to twelve months, during which the controls have to run and leave evidence, plus the auditor's fieldwork afterward. For a 20-person company starting from a reasonable baseline, the honest planning number is six to nine months from decision to a Type 2 report in hand.

Can a company with no security team get SOC 2? Yes. The report describes controls, not headcount. What you need is someone accountable, usually the founder or CTO, a written set of policies you actually follow, and evidence that the controls ran. Most 20-person companies pair an outside firm for the implementation and evidence with an internal owner for the decisions.

Does SOC 2 expire? The report itself does not carry an expiry date, but it covers a period, and buyers read the end date. Once a Type 2 is more than twelve months old, procurement teams treat it as stale and ask for a bridge letter or a new report. In practice you are on an annual cycle, which is why continuous evidence collection beats a yearly scramble.

The report is the receipt. The security is the purchase. Buy the second one properly and the first one writes itself.

Controls this post maps to

CIS 5 Account ManagementCIS 8 Audit Log ManagementCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.