r/soc2
Getting started with SOC 2 compliance
- upvotes
- 14
- comments
- 49
Post
I'm saddled with getting us ready for soc2 compliance. I honestly dont know as much about compliance, but the responsibility has fallen on me as I'm the closest the team has to an internal security/compliance owner atm. We're small, I'd say more akin to a startup, at ~30 employeees. Cost is manageable, but from my preliminary searches Vanta and the likes are priced too high. My initial research looking into older threads and some claude queries has placed sprinto and secureframe as best suited for our situation but I'm open to any alts or recs. As for tech stack, its fairly expansive but all straightforward, AWS, slack, github, clouflare etc. And if anyone has recently gone through this whole hassle, please gimme some guidance. I've seen older threads recommmend avoiding platforms altogether in some situation but idek if it'd be worth it for me to learn and do everything from scratch
Extracted from these lines
[comment u/uri_iothreat] Most of my customers come to me after they have been sold on one of those platforms (Vanta, Drata, Securframe, Scytale, etc.), I’ve seen dozens of them.
[comment u/uri_iothreat] The thing is, these platforms cost money and create more overhead to manage than actual benefit to your SOC 2 program, so my customers understand they’ve just paid for a bunch of homework and they don’t have the time or resources to manage it and...