Ask a founder why they are getting a SOC 2 and the honest answer is almost always the same: a customer asked, or a customer is about to.
That answer is treated as slightly embarrassing, as though the respectable reason would be security maturity. It is not embarrassing. It is the correct reason, and being clear about it produces better decisions than pretending otherwise.
Why the framing matters
A compliance project optimizes for passing. A sales gate optimizes for unblocking revenue by a date. Those two goals diverge in three concrete places.
Scope. A compliance framing pulls scope wide, because wider feels safer. A revenue framing asks which systems your buyers actually care about, which is usually the production environment that processes their data and nothing else. Scope is the single largest cost driver in an audit and the one most often set by default rather than by decision.
Timing. A compliance framing starts when the team has capacity. A revenue framing works backward from the deal that needs it, accounting for the observation window. A Type II report requires a period of operating evidence, commonly three to twelve months, so a company that starts when it feels ready routinely misses the quarter it needed the report for.
Exceptions. A compliance framing treats every exception as a failure to eliminate. A revenue framing asks which exceptions a buyer's security reviewer will stop on. Some exceptions are genuinely fine and cost nothing in a review. Others end deals. Those two categories are not ordered by their severity in the framework.
The claim nobody checks
One specific thing worth knowing, because it changes how much weight to put on a report you receive.
The system description is written by the company being audited, not by the auditor. The auditor tests whether the controls described are operating as described. They do not evaluate whether the described controls are the right ones, and they do not rewrite a scope that is narrower than a reader would assume.
That is not a scandal, it is how attestation works, and it has a practical consequence in both directions. As a vendor, it means your scope decision carries more weight than the audit fee. As a buyer, it means the first thing to read is the system description rather than the opinion, because an unqualified opinion on a scope that excludes the product you are buying tells you almost nothing.
Why the obvious answer is wrong
The obvious answer is that SOC 2 makes you more secure, so the framing is academic.
The evidence for that is weaker than the industry pretends. SOC 2 attests that the controls you described were operating as described during a window. It does not evaluate whether those controls were the right ones for your threat model, and the criteria are broad enough that two companies with very different actual security postures can both pass cleanly.
What SOC 2 reliably produces is documentation, consistency, and a forcing function for work that was already on the list. Those are real and worth having. They are not the same as being more secure, and a founder who believes they have bought security rather than a market access credential will underinvest in the parts that actually matter.
There is a second-order cost to the wrong framing too. A company that treats the report as the goal tends to stop at the report, and then the following year's surveillance period catches it having quietly let controls lapse, which is a worse outcome than never having claimed them.
The discriminating variables
Which deals is this actually unblocking?
The test: name the accounts. If you cannot name at least two real opportunities that require it, you are buying it speculatively, which may still be correct but should be a conscious call rather than an assumed one.
Type I or Type II, and does your buyer know the difference?
The test: ask a buyer's security team directly. Many will accept a Type I with a committed Type II date, which can pull revenue forward by two quarters. Some will not. This is a five-minute question that routinely goes unasked.
Is scope set by decision or by default?
The test: can somebody state which systems are in scope and why each one is there? Auditors will happily scope to whatever you present. Every system included adds evidence collection for the life of the programme.
Does the observation window fit the pipeline?
The test: work backward from the earliest deal that needs it. If the window does not fit, the decision is not whether to start sooner; it is whether to negotiate a Type I now with a dated commitment.
What the report costs, all in
The audit fee is the smallest line and the one everybody quotes.
Audit fee. Fifteen to forty thousand for a Type II at small-company scope, depending on firm and scope. Type I is roughly half.
Compliance automation platform. Ten to thirty thousand a year. Optional in principle, and in practice it is what makes the evidence collection survivable if nobody internally has done this before.
Penetration test. Ten to thirty thousand. Not strictly required by the criteria, and asked for by enough buyers alongside the report that most companies do it anyway.
Internal time. The line nobody budgets and the largest one. A first Type II consumes somewhere between a quarter and a half of one person's year, spread across whoever owns it plus engineering time for remediation. At a loaded rate that is frequently more than every other line combined.
Year two. Lower, but not near zero. Surveillance, evidence continuity, and whatever controls drifted. Budget half of year one, and be suspicious of a platform vendor who implies otherwise.
Total, realistically: eighty to a hundred and fifty thousand of real cost for a first Type II at a small company, of which under a third is the thing people call "the cost of SOC 2".
Run that arithmetic against the named deals. If the pipeline it unblocks is worth less than that, the honest answer might be to wait, and saying so to a board is a stronger position than starting and stalling.
The exceptions buyers actually read
A SOC 2 report is long and almost nobody reads all of it. Knowing which parts get read changes what is worth agonizing over.
A competent security reviewer opens the report and goes to two places. First, the auditor's opinion: is it unqualified. Second, the exceptions and management responses. Everything else is skimmed for scope, and the control descriptions are read closely only when something in the exceptions prompted a question.
That means one clean exception with a sensible management response costs you almost nothing, and three exceptions in the same control family costs you a great deal, because the pattern reads as a systemic gap rather than an incident.
It also means the system description matters more than founders expect. A reviewer checks whether the system in scope is the system they are buying. A report that scopes to a corporate environment while the product runs somewhere else is worse than no report, because it looks like an attempt to pass something off.
Decision table
| Situation | Do this | Why |
|---|---|---|
| Two or more named deals blocked | Start now, scope narrow | The revenue case is proven |
| One prospect asking, early stage | Ask if a Type I plus commitment works | Frequently accepted, two quarters faster |
| No named deals, board pressure | Delay, write the trust page instead | A trust page answers most questions for free |
| Regulated buyers in pipeline | Expect ISO 27001 to be asked for too | Plan one control set for both |
| Already have SOC 2, buyer wants ISO | Map, do not rebuild | Overlap is large; the gap is the work |
Scoping is where the money is
Scope is set once, in a conversation most founders treat as administrative, and it drives cost for years.
Three decisions inside it:
Which systems. The production environment that processes customer data is almost always in. The corporate environment is in to the extent it can reach production. Everything else is a choice, and "everything" is a choice that costs a great deal and buys almost nothing with buyers.
Which trust services criteria. Security is mandatory. Availability, confidentiality, processing integrity, and privacy are optional and each one adds controls, evidence, and audit time. Add one only when a buyer has asked for it in writing. Availability is the one most commonly added speculatively and most commonly regretted, because it drags in uptime commitments you now have to evidence.
Which observation window. Three months is the shortest most auditors will accept and produces a thinner report. Twelve months is the strongest. Six is the common compromise. The right answer is driven by the deal date, not by rigor.
The pattern I have watched repeatedly: a founder lets the auditor or the platform default the scope, ends up with three criteria and an over-broad system boundary, and pays for it every year forever. The narrowing conversation is much harder in year three than in year zero.
What changes the answer
Selling into Europe. ISO 27001 is asked for more often than SOC 2 in much of Europe, and building for the wrong one first is an expensive mistake that is entirely avoidable by asking three prospects which they require.
A trust page that already answers the questions. Gartner puts 67% of B2B buyers as preferring a rep-free evaluation, which means a good public trust page does real work before anyone asks for a report. It does not replace the report for buyers whose own regulator requires one, but it can defer the timing.
Very early stage. Below roughly fifteen people, the honest position is that you do not have the operational history to attest to, and saying so plainly to a prospect works better than a rushed Type I that a reviewer can see through.
What to do while you wait for the report
The observation window is dead time only if you let it be. Buyers are asking now.
Publish the trust material immediately, before the report exists. Certifications in progress with a target date, subprocessor list, data flow description, retention policy, and your answers to the twenty questions everybody asks. Gartner puts 67% of B2B buyers as preferring to evaluate without a sales rep, which means this page is doing work in evaluations you do not know are happening.
Then say the true thing to prospects: the audit is under way, the window closes on this date, and here is the evidence in the meantime. In my experience buyers respond considerably better to that than to vagueness, and a meaningful share will proceed on a contractual commitment to deliver the report rather than waiting for it.
What does not work is implying you have something you do not. Security reviewers check, the correction is remembered, and it costs more than the delay would have.
What to do Monday
Write down the two or three accounts this report unblocks, with the date each one needs it. Then ask one of those buyers, directly, whether a Type I with a committed Type II date would satisfy their review.
If the answer is yes, you have just moved the gate two quarters earlier at no cost. If it is no, you now have a real deadline to scope against instead of an aspiration.