The email arrives on a Tuesday. Your biggest prospect — the one whose logo would change your next fundraise — has moved you to security review. Attached is a 240-row questionnaire and one line that matters: "Please attach your most recent SOC 2 Type II report."
You have fourteen employees. Nobody's title contains the word "security." The deal is now parked behind a document you don't have.
This guide is about that exact situation: how a SOC 2 audit for small business actually works when you have no compliance team, no six-figure budget, and a deal on the clock. If you need the fundamentals first — what the report is, what the Trust Services Criteria cover, Type 1 versus Type 2 — start with our complete SOC 2 guide and come back. Everything below assumes you already know them.
What "Small Business" Actually Changes About SOC 2
Almost nothing, and that is the point people get wrong in both directions.
The Trust Services Criteria contain no headcount threshold. There is no simplified SOC 2 for companies under fifty people. An auditor evaluates whether your controls are appropriate to the size and complexity of your operation, which means a fourteen-person SaaS company is measured against a fourteen-person company's risk profile — not against a bank's.
That cuts in your favour more often than founders expect. Fewer employees means fewer accounts to review. One production environment means one set of configurations to evidence. No legacy estate means no twenty-year-old server nobody wants to talk about.
What genuinely changes is execution, and it comes down to three constraints:
- No dedicated owner. Nobody wakes up whose only job is this. The work lands on a founder or a senior engineer who already has a roadmap.
- No tolerance for waste. A large company absorbs a badly scoped audit. At your size, scoping in two extra criteria can add tens of thousands of dollars and two months for no commercial return.
- No natural segregation of duties. The person who writes the code deploys the code. That is a real control problem and it has a real, accepted solution — covered further down.
What a SOC 2 Audit Costs for a Small Business
Published SOC 2 pricing is misleading because vendors quote the piece they sell. The auditor quotes the audit. The platform quotes the licence. Neither is the number you will actually spend.
Realistic cost by headcount
These are year-one, all-in ranges for a Type 2 report scoped to the Security criterion, based on typical small-business engagements:
| Company size | CPA auditor fee | Compliance tooling | Readiness & pen test | Realistic year-one total |
|---|---|---|---|---|
| Under 25 | $12,000 – $20,000 | $8,000 – $15,000 | $10,000 – $20,000 | $30,000 – $55,000 |
| 25 – 50 | $18,000 – $30,000 | $12,000 – $20,000 | $15,000 – $30,000 | $45,000 – $80,000 |
| 50 – 100 | $25,000 – $45,000 | $15,000 – $30,000 | $25,000 – $45,000 | $65,000 – $120,000 |
Note the pattern: the auditor's fee is only about 35 to 40 percent of what you spend. Founders who budget for the audit quote alone are typically off by a factor of two and a half. If you are above 100 people, or want the year-two renewal economics and a three-year view, our full guide to SOC 2 certification cost extends this table. For how it compares against ISO 27001 and other frameworks, see our certification cost breakdown.
Where the money actually goes
The invisible line item is your own team. A first SOC 2 consumes somewhere between 150 and 400 internal hours — policy drafting, evidence gathering, remediating whatever the readiness assessment finds, and sitting in auditor walkthroughs. At a loaded engineering cost of $80 an hour, that is $12,000 to $32,000 of capacity that is not building product. It is the largest cost in the project and the one nobody puts in the spreadsheet.
What you can safely cut
- Extra Trust Services Criteria. Every criterion beyond Security adds audit fee and control work. Add them only when a signed contract demands it.
- A Big 4 auditor. Their brand carries no additional weight on a SOC 2 report and their fees are often three to five times a competent regional CPA firm's.
- A Type 1 you don't need. See the next section.
- Headcount. Hiring a compliance manager for a first SOC 2 at under fifty people is almost always more expensive than fractional support.
Want a number for your actual situation?
Scope, headcount, and cloud footprint change the total significantly. Our calculator gives you a scoped estimate in a few minutes.
Calculate my SOC 2 costType 1 First, or Straight to Type 2?
For a small business this is a commercial decision, not a technical one.
Go Type 1 first if a specific deal is blocked right now. A Type 1 attests that your controls are suitably designed at a point in time. Once controls are genuinely in place, a Type 1 can be issued in a matter of weeks. Many enterprise buyers will accept it, plus a committed Type 2 date, as enough to release the contract. When one signature is holding up six figures of revenue, that bridge is worth its cost.
Skip straight to Type 2 if nothing is on fire. Type 1 is a separate engagement with its own fee for a report most buyers regard as provisional. If you can absorb a three-to-six-month observation window without losing the deal, going directly to Type 2 saves both money and a duplicated audit cycle.
One nuance specific to small companies: your first Type 2 observation period can be as short as three months. Enterprise buyers generally prefer twelve, but a three-month initial window is widely accepted for a first report and gets you a real Type 2 far sooner. Subsequent reports then extend to a full year. If you are weighing this against your funding stage, our startup compliance roadmap maps it to ARR milestones.
Scope Reduction: The Single Biggest Cost Lever
Nothing else on this page will save you as much money as scoping correctly. Scope determines audit fee, control count, evidence volume, and remediation effort simultaneously.
Start with Security and nothing else
Security — the Common Criteria — is the only criterion mandatory in every SOC 2 report. Availability, Confidentiality, Processing Integrity, and Privacy are all optional.
The overwhelming majority of enterprise security questionnaires are satisfied by a Security-only report. Add Availability when you have contractual uptime SLAs you are being held to. Add Confidentiality when you handle customer data under specific contractual handling terms. Add Privacy only if you process consumer personal data at scale and a customer has explicitly asked — it is the most demanding criterion by a distance and rarely justified at small scale.
Define the system, not the company
SOC 2 audits a system, not a legal entity. Your scope should describe the specific production environment that delivers your service to customers, together with the infrastructure, data stores, and personnel that support it.
Deliberately outside that boundary: your marketing website, internal tools with no customer data, your finance stack, sandbox environments with synthetic data. Every system you leave out is one you do not have to evidence four times a year. Write the boundary down explicitly in your system description — ambiguity is what lets scope creep back in during fieldwork.
Use your cloud provider's carve-out
If you run on AWS, Azure, or GCP, you do not audit their data centres. Physical security, environmental controls, and hypervisor isolation are covered by the provider's own SOC 2, and you inherit them through the carve-out method: you reference their report in your system description rather than testing those controls yourself.
What this does not cover is anything above the hypervisor — your IAM configuration, your encryption choices, your network rules, your application access control. Running on a compliant cloud makes you inherit a floor, not a report.
Running SOC 2 Without a Security Team
What the founder or CTO has to own personally
You can delegate evidence collection. You cannot delegate these four, because auditors will interview whoever holds them and expect genuine command of the detail:
- The risk assessment. A documented, annually refreshed view of what could go wrong and what you decided to do about it. This is the spine of the whole report.
- Scope and the system description. The boundary decision above is a leadership call with direct cost consequences.
- Access approvals. Someone senior must approve who gets production access, and that approval must leave a timestamped trail.
- Vendor risk decisions. Accepting a subprocessor that lacks its own SOC 2 is a business risk decision, not an engineering one.
Segregation of duties when there are twelve of you
The classic finding at small companies: the engineer who writes the code also approves and deploys it. Textbook SOC 2 wants those separated. With twelve people you cannot separate them, and auditors know this.
The accepted answer is a documented compensating control. In practice that means mandatory peer review before merge with branch protection enforcing it, an immutable deployment log nobody can edit, and a named second person — usually the founder — reviewing that log on a fixed, documented cadence.
State the constraint honestly in your system description and describe the compensating control. Auditors accept this routinely. What they do not accept is a policy claiming separation that your commit history plainly contradicts.
How many policies you actually need
Between twelve and twenty. Information security, access control, change management, incident response, vendor management, business continuity and disaster recovery, risk assessment, data classification, encryption, secure development, acceptable use, and HR security covering onboarding and offboarding.
Length is irrelevant; accuracy is everything. Auditors test policies against observed reality. A two-page access control policy that precisely describes what you do will pass where a thirty-page template downloaded from the internet will fail on the first walkthrough, because it describes a company you are not.
Do You Need a Compliance Automation Platform?
Below roughly fifty employees, a platform like Vanta, Drata, or Secureframe usually pays for itself — but for one specific reason: continuous evidence collection.
SOC 2 Type 2 tests controls across the whole observation period, not on audit day. That means proving quarterly access reviews happened, that laptops stayed encrypted, that onboarding checklists were completed every time. Done manually, that is several days of screenshotting per quarter, and it is exactly the work that slips when a release is late.
Be clear about what a platform does not do. It does not write your risk assessment, decide your scope, remediate findings, or replace a readiness assessment. It integrates with your stack and monitors what is already there. Buying one before fixing the underlying process just gives you an automated, well-organised record of non-compliance. If you are comparing tools and pricing, we cover the trade-offs in our guide to compliance platform alternatives.
How to Choose a SOC 2 Auditor as a Small Company
The report must be issued by a licensed CPA firm. Beyond that, brand buys you very little.
- Regional and boutique CPA firms specialising in SOC 2 are the right default for most small businesses. They are typically three to five times cheaper than national firms and are used to your scale.
- National firms make sense if you sell into heavily regulated buyers — large financial institutions or government — who occasionally name acceptable firms in contract terms.
- Big 4 is almost never justified for a first SOC 2 at under 100 people.
Four questions worth asking every firm you shortlist: How many companies our size did you audit last year? Who actually performs the fieldwork, and is it outsourced? What is the fee for the follow-up report next year? What is your typical turnaround from fieldwork to issued report?
For the fuller picture, including how auditors differ from readiness consultancies and automation platforms, see our guide to choosing a SOC 2 compliance company.
Two warnings. First, a firm that also sells you the readiness work cannot audit you independently — that is an independence conflict, and a serious buyer's security team will spot it. Keep readiness and audit separate. Second, treat any firm that guarantees a clean opinion as disqualified; the opinion is the one thing they cannot promise in advance.
A Realistic 90-Day Plan for a 15-Person Team
This assumes Security-only scope, one production environment, and roughly one engineer-day per week of committed effort.
| Weeks | Focus | Outcome |
|---|---|---|
| 1 – 2 | Scope and gap analysis | System boundary agreed in writing; a ranked list of what is missing |
| 3 – 5 | Policies and risk assessment | 12–20 policies written to match reality; risk register signed off by leadership |
| 4 – 8 | Technical remediation | SSO and MFA enforced, least-privilege access applied, logging and alerting live, laptops encrypted and managed |
| 6 – 9 | Tooling and evidence | Automation platform connected; first access review and security training completed and recorded |
| 9 – 11 | Readiness assessment | Independent check that finds the gaps before your auditor charges you to find them |
| 12 | Auditor engaged, observation begins | Type 2 window opens; Type 1 issued here if a deal needs it |
Add the observation period — three months at minimum, twelve for a mature report — plus four to eight weeks of fieldwork and report writing. A small business starting today should expect an issued Type 2 report in roughly seven to twelve months. Anyone promising a Type 2 in ninety days is describing a Type 1.
Five Mistakes That Cost Small Businesses the Most
- Scoping in criteria nobody asked for. Adding Availability and Confidentiality "to be safe" can add 30 to 50 percent to audit fees for zero commercial return. Ask the customer what they actually require.
- Buying the platform before fixing the process. The tool reports on controls; it does not create them. Sequence readiness first.
- Downloading policy templates and not editing them. The fastest route to a qualified opinion is a policy library describing a company you are not.
- Skipping the readiness assessment. It is the cheapest insurance in the project. A control that fails during fieldwork can restart your observation period and delay the report by months.
- Treating it as a one-time project. Reports expire annually. Controls that decay after the window close produce exceptions in next year's report, which buyers read closely.
The Commercial Case
Frame this against the deal that triggered it. A $40,000 first-year programme that unblocks a $150,000 contract pays for itself before the report is even issued — and every subsequent enterprise deal moves through security review measurably faster, because the questionnaire gets answered with an attachment instead of a project.
The mistake is treating SOC 2 as a cost centre. For a small B2B company it is the document that makes you procurable by buyers who would otherwise never reach a contract stage with you at all.
Frequently asked questions about SOC 2 for small businesses
Can a 10-person company pass a SOC 2 audit?
Yes. The Trust Services Criteria say nothing about headcount. Auditors assess whether your controls are appropriate for the size and complexity of your business, so a ten-person company is judged against a ten-person company's risk profile. Small teams often pass more easily than mid-size ones because there are fewer systems, fewer people with access, and fewer exceptions to explain.
What is the minimum realistic budget for a SOC 2 audit at a small business?
For a company under 25 people scoping to the Security criterion only, a realistic all-in year-one budget is roughly $30,000 to $55,000. The CPA auditor's fee is typically only 35 to 40 percent of that; the rest is compliance tooling, readiness work, penetration testing, and your own team's time. Budgets below about $20,000 usually mean something material has been left out. Get a scoped estimate.
Should a small business do SOC 2 Type 1 first or go straight to Type 2?
Do Type 1 first only if a specific deal is blocked right now and the buyer will accept it as an interim step. Type 1 can be issued within weeks of controls being in place, which unblocks procurement. If no deal is waiting, skip it: Type 1 adds a separate audit fee for a report most enterprise buyers will not accept as a substitute for Type 2.
What is the smallest defensible scope for a SOC 2 audit?
The Security criterion, often called the Common Criteria, applied to the single production system that handles customer data, plus the infrastructure and people supporting it. Security is the only criterion required in every SOC 2 report. Availability, Confidentiality, Processing Integrity and Privacy are optional and should only be added when a customer contract or your own product claims demand them.
How many policies does a small business need for SOC 2?
Most small businesses need roughly 12 to 20 policies covering areas such as information security, access control, change management, incident response, vendor management, business continuity, and acceptable use. Auditors test whether the policies match what you actually do, so a short accurate policy is worth more than a long borrowed one.
Can we pass SOC 2 if our IT is outsourced or we use contractors?
Yes. Outsourcing is normal and does not disqualify you. Contractors with access to production are treated like employees: they need background checks where applicable, signed confidentiality agreements, security awareness training, and the same onboarding and offboarding evidence. Outsourced providers are handled through vendor management, meaning a documented risk review and, where available, a copy of their own SOC 2 report.
Do we need a compliance automation tool like Vanta or Drata?
Not strictly, but below about 50 employees it usually pays for itself. The value is continuous evidence collection: automated records of access reviews, device compliance, and cloud configuration that would otherwise consume days of manual work each quarter. The tool does not create controls or replace readiness work, so buying one without fixing the underlying process simply automates the collection of evidence that you are not compliant.
How do we handle segregation of duties with a very small team?
Auditors accept compensating controls when headcount makes true separation impossible. If the same engineer writes and deploys code, the compensating control is a mandatory peer review before merge, an immutable deployment log, and a second person, often the founder, reviewing that log on a documented schedule. Document the constraint and the compensating control rather than pretending separation exists.
About Avantcert. Avantcert is an ISO and compliance certification consultancy that has guided 3,000+ organisations across 40+ markets to certification, with gap analysis, implementation and accredited audit readiness. See our SOC 2 consulting service or request a free quote.