HackproofHacks
Compliance, explained plainly

How to Get SOC 2 Compliant: Timeline, Steps, and Common Blockers

Getting SOC 2 compliant takes six to nine months for most first-time companies pursuing a Type II report: roughly one to two months to close control gaps, three to six months of observation period where the controls have to actually run, and four to eight weeks for the audit itself. The steps are readiness assessment, gap remediation, evidence collection through the observation window, the independent penetration test, and the audit.

The timeline surprises almost everyone the first time. It is not the audit that takes months, it is the fact that a Type II report requires your controls to run correctly for a real observation period before an auditor can even test them.

Here is the sequence that actually gets a first-time company through it, along with where teams typically get stuck.

The realistic timeline

Three phases determine the timeline, and only one of them is compressible. Gap remediation, fixing whatever your readiness assessment finds, usually takes four to eight weeks. The observation period is fixed by the report type: a Type II report needs a minimum of three months of evidence, though most auditors and enterprise buyers expect six to twelve. The audit fieldwork itself, once the observation period ends, typically takes four to eight weeks.

Rushing the remediation phase does not shorten the timeline much, because the clock on the observation period cannot start until the controls it is measuring actually exist.

The steps, in order

Six steps, roughly in sequence, though scoping and remediation often overlap in practice.

  1. 1

    Scope the audit

    Decide which Trust Services Criteria apply beyond the required Security criterion, and which systems and products are in scope. Scoping too broadly adds audit cost and control burden without adding customer value.

  2. 2

    Run a readiness assessment

    A gap assessment, often done internally or with a compliance consultant, that compares your current controls against the Trust Services Criteria and produces a punch list of what's missing.

  3. 3

    Remediate the gaps

    Implement the missing controls: access reviews, logging, encryption, vendor management, incident response procedures, and anything else the readiness assessment flagged. This is usually the fastest phase and the one teams underestimate.

  4. 4

    Start the observation period

    The controls now have to run, and produce evidence, for the length of your chosen window. This is where most of the calendar time goes, and it cannot be compressed by working harder.

  5. 5

    Get the independent penetration test

    Scheduled with enough lead time before the observation window closes to fix whatever it finds and show the auditor that remediation actually happened, not just that a report exists.

  6. 6

    Go through the audit

    The CPA firm reviews the evidence collected during the observation period, including the penetration test report, and issues the SOC 2 report.

Where teams get stuck

  • Treating the penetration test as a checkbox scheduled the week before the audit, leaving no time to fix what it finds and no evidence of remediation for the auditor to review.
  • Scoping the observation period too short and then discovering the auditor or the buyer expects twelve months, not three, which forces a restart of the clock.
  • Building controls that exist on paper but that nobody actually follows, which the auditor's sampling during the observation period will surface.
  • Assuming SOC 2 is a one-time project instead of an annual cycle. The report has a shelf life, typically twelve months, and the whole cycle repeats.

How a penetration test fits into this timeline

Book it to land in the first half of the observation period, not the last few weeks. That gives you time to remediate any findings and gives the auditor a clean before-and-after story: vulnerabilities were found, fixed, and the fix was verified with a retest, all inside the window the report covers.

Frequently asked questions

Can we get SOC 2 compliant in under three months?

For a Type I report, possibly, since it only requires controls to be correctly designed as of one date, not observed over time. For a Type II report, no. The observation period alone requires a minimum of three months, and most auditors and enterprise buyers expect six to twelve.

Do we need a compliance consultant, or can we do this ourselves?

Plenty of technical teams run the readiness assessment and remediation themselves, especially with automated compliance tooling. A consultant or GRC platform earns its cost mainly on evidence collection and audit coordination, which gets tedious at scale, not on the technical control work itself.

How much does SOC 2 compliance cost overall?

Audit fees for a first Type II report commonly run from the low five figures upward depending on scope, plus the cost of any compliance tooling and the penetration test. The biggest cost for most teams is engineering time spent building and maintaining the controls, not the audit fee itself.

What happens if the auditor finds a control failure during the observation period?

It does not automatically fail the audit. Auditors expect some exceptions and evaluate how you responded: whether the issue was caught, fixed, and documented. An exception with a clear remediation trail is a normal part of a Type II report, not a disqualifier.

Related guides

Related services

Ready to scope your test?

Book a free 30-minute scoping call. We agree the scope, timeline, and a fixed price up front, with no obligation and no surprises for your deadline.