SOC 2 compliance software: a SOC 2 audit preparation tool with the price on the page
Most SOC 2 programs stall on evidence, not on controls. Complies maps every Trust Services Criterion to an owned obligation, then collects the proof on a schedule, so audit preparation is a work plan instead of a screenshot scramble the week before fieldwork.
Last updated August 2026
SOC 2 compliance software maps your controls to the AICPA Trust Services Criteria, collects audit evidence on a schedule, and shows a live readiness score, so a 5 to 200 person company can prepare for a SOC 2 audit without a dedicated compliance hire. The criteria it maps to are the AICPA 2017 Trust Services Criteria with revised points of focus issued in 2022, which is still the current version: five categories, of which security is always in scope, with availability, processing integrity, confidentiality, and privacy added only if you commit to them. A Type 1 report checks control design at a point in time; a Type 2 report checks that the same controls operated over a 3 to 12 month window. Complies turns the CC-series common criteria into obligations with owners and due dates, pulls evidence like access reviews, change logs, and monitoring settings from AWS, GitHub, and Okta, and flags gaps in plain language before your auditor finds them. Evidence collection typically eats around 120 engineer-hours per audit cycle; Complies delegates and reuses that work. One boundary worth stating plainly: no software issues the report. A SOC 2 examination is performed by a licensed CPA firm, management writes the system description against the AICPA 2018 description criteria, and the auditor gives an opinion. Budget the CPA firm separately, commonly $5,000 to $20,000 for Type 1 and $12,000 to $40,000 for Type 2 as third-party estimates, and expect teams with a reasonable security baseline to reach Type 1 readiness in 6 to 12 weeks of part-time work. Every SOC 2 control cross-maps to ISO 27001, GDPR, HIPAA, and PCI DSS, so your next framework starts roughly 60% pre-filled. Complies publishes its price: $79, $199, and $499 a month billed yearly, against a category where almost every incumbent is quote-only.
Complies handles it with compliance evidence collection and audit readiness software, with every control cross-mapped to the other frameworks you run. For the tooling side of it, compare compliance automation software and what it actually automates.
What SOC 2 asks of you, in plain language
| Code | What it demands | How Complies helps |
|---|---|---|
| CC6.1 | Restrict logical access to systems and data to authorized users | Complies maps your SSO, IAM roles, and repo permissions to CC6.1, schedules quarterly access reviews, and flags accounts that should have been offboarded. |
| CC7.2 | Monitor systems and detect security events and anomalies | Pulls monitoring and alerting evidence from AWS and GitHub on a schedule, ties it to CC7.2, and flags coverage gaps before the auditor does. |
| CC8.1 | Put every infrastructure and software change through a controlled process | Collects pull request reviews, CI checks, and deploy logs from GitHub as recurring evidence, so change management proves itself without manual screenshots. |
| CC3.2 | Identify and assess the risks that threaten your objectives | The built-in risk register ties each risk to CC3.2 with an owner and a treatment decision, and feeds your live readiness score. |
| CC9.2 | Assess and manage the risks your vendors introduce | Tracks your vendor list with review dates, data access notes, and owners, and chases the annual vendor reviews before they go stale. |
| CC5.3 | Put your policies in writing and keep them approved and current | AI-drafted policy starting points your team edits and approves, with version history, annual review dates, and staff acknowledgments stored as evidence. |
| CC7.4 | Respond to identified security incidents on a defined process | Keeps the incident response plan approved and current, logs incidents against CC7.4 with owners and timelines, and schedules the tabletop exercise your auditor will ask about. |
Collect once, comply many times
SOC 2 shares most of its substance with the other frameworks: CC6.1 access control is ISO 27001 A.5.15, GDPR Art. 32, HIPAA 164.312(a), and PCI DSS Req. 7 wearing different labels, and the same is true for risk assessment, change management, and incident response. Complies maps each control once and marks it satisfied everywhere it applies, so finishing SOC 2 pre-fills roughly 60% of ISO 27001 and reuses your evidence wherever the second framework accepts it. Cross-mapping is included on every plan from Growth up.
| Control area | SOC 2 | Also satisfies |
|---|---|---|
| Access control | CC6.1 | ISO A.5.15 · GDPR Art. 32 · HIPAA 164.312(a) · PCI Req. 7 |
| Risk assessment | CC3.2 | ISO Clause 6.1.2 · HIPAA 164.308(a)(1) · PCI Req. 12.3 |
| Change management | CC8.1 | ISO A.8.32 · PCI Req. 6.5 |
| Incident response | CC7.4 | ISO A.5.24 · GDPR Art. 33 · HIPAA 164.308(a)(6) |
| Security awareness training | CC1.4 | ISO A.6.3 · HIPAA 164.308(a)(5) · PCI Req. 12.6 |
| Vendor management | CC9.2 | ISO A.5.19 · GDPR Art. 28 · PCI Req. 12.8 |
See the full crosswalk on the control mapping software page.
SOC 2 compliance software compared, and what each vendor will tell you before a sales call
Every platform in this category automates the same core loop: map the Trust Services Criteria to controls, pull evidence from your cloud, and hand the auditor a pack. The feature lists converge, so the real buying questions are narrower. Will the vendor tell you the price without a call, does it push you toward one auditor or let you bring your own, and does the second framework cost a second contract? Every figure below was read off the vendor's own pricing page or is labeled as a third-party benchmark with its date.
| Platform | How it handles SOC 2 | Pricing published? | Best fit |
|---|---|---|---|
| Complies | Maps the CC-series common criteria plus any added Trust Services Categories to owned obligations, cross-mapped to ISO 27001, GDPR, HIPAA, and PCI DSS. Bring your own CPA firm. | Yes. Starter $79, Growth $199, Scale $499 per month billed yearly. Self-serve signup, no call. | US teams of 5 to 200 people doing SOC 2 without a full-time compliance hire, especially with a second framework coming. |
| Vanta | The category incumbent. Deep automated evidence collection across 35 plus frameworks with a large partner auditor network. | No. Quote only. Vendr median $20,000 a year, range $7,500 to $57,236, n=372, re-verified August 2026. | Funded startups that want the most integrations and can absorb an annual contract. |
| Drata | Multi-framework GRC with continuous control monitoring; its GRC Foundation plan covers up to 50 FTEs and one pre-mapped framework. | No. Quote only. Vendr median $24,868 a year. | Growth-stage tech companies running several frameworks with a dedicated compliance owner. |
| Secureframe | SOC 2 automation sold with managed onboarding and a named customer success contact. | Partly. Fundamentals from $7,000 a year, then quoted. Vendr median $20,000 a year. | Teams that want a person walking them through the first audit cycle. |
| Sprinto | Multi-framework automation aimed at small engineering teams doing SOC 2 first. | No. Quote only. Vendr median $15,000 a year. | Small engineering teams that want fast SOC 2 readiness and will add frameworks later. |
| Thoropass | The one structurally different model here: it delivers the CPA audit through the same vendor relationship as the software, so readiness and attestation are one contract. | No. Quote only. Vendr median $25,964 a year. | Teams that would rather buy readiness and the audit together than manage two vendors. |
| Scytale | Multi-framework compliance automation sold with an audit-support motion. | Partly. Its own page is quote only, but its AWS Marketplace listing publishes $7,500 for the platform per 12-month contract, plus $2,100 per additional framework. | Teams that want tooling and audit guidance bundled and can buy through AWS Marketplace. |
| Hicomply | ISMS-first platform covering SOC 2 among more than twenty frameworks by its own count. | Yes. Essentials $6,995 and Professional $13,995 a year, annual contract. Additional frameworks about $6,995 a year each. | Teams wanting many frameworks on one published annual fee, comfortable with a UK-origin vendor. |
Two things to hold onto. First, none of these products, ours included, issues your SOC 2 report. A SOC 2 examination is performed by a licensed CPA firm and the auditor's opinion is theirs alone, so audit fees sit outside every price above. Second, the Vendr figures are third-party medians from buyers who negotiated those contracts in February 2026, not vendor list prices, and they move. Several directory sites publish very different numbers for these products with no methodology attached, so we leave those out rather than repeat them.
Six things SOC 2 compliance software has to get right
The criteria turned into work someone owns
A list of criteria is not a plan. Complies converts each CC-series criterion, plus any availability or confidentiality criteria you scope in, into an obligation with a named owner and a due date. The gap list is the work plan, and it is visible to the person who has to close it.
Evidence collected on a schedule, not in a panic
Access reviews, change approvals, monitoring configuration, and policy acknowledgments get pulled from AWS, GitHub, Okta, and Google Workspace on a recurring cadence. That is the difference between a Type 2 window that proves itself and one reconstructed from memory in month eleven.
Scoping before the checklist appears
Security is always in scope. Availability, processing integrity, confidentiality, and privacy are not, and every category you add is more controls, more evidence, and a longer audit. Complies asks what you have actually committed to customers first, so you do not carry criteria nobody asked you for.
One control library across five frameworks
CC6.1 access control is ISO 27001 A.5.15, GDPR Art. 32, HIPAA 164.312(a), and PCI DSS Req. 7 in different numbering. Complies satisfies a shared control once and marks it everywhere it counts, so the second framework starts roughly 60% pre-filled instead of at zero.
The Type 2 window watched the whole way through
A Type 2 report tests operation over 3 to 12 months, so a control that lapsed in month four is an exception in the report. Complies flags a missed access review or a stale policy while the window is still open, which is the only time it can still be fixed.
Honest about the line software cannot cross
No platform certifies you. The CPA firm performs the examination, management writes the system description, and the auditor issues the opinion. Complies gets the controls mapped, the evidence organized, and the gaps closed before fieldwork starts, and says plainly that the rest is not for sale.
Getting SOC 2 ready with Complies
Connect your stack and scope the report
Point Complies at AWS, GitHub, Google Workspace, and Okta, choose Type 1 or Type 2, and pick which Trust Services Categories beyond security you actually need in scope.
Close the gaps the map exposes
Every CC-series criterion becomes an obligation with an owner and a due date. AI-drafted policies give you starting points your team edits and approves, and the gap list becomes your work plan.
Collect evidence and hand your auditor the pack
Evidence streams in on a schedule with named owners. When the readiness score says you are there, export the organized audit pack and bring in your CPA firm.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
SOC 2 questions, answered
No, and nothing can except an audit. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee audit outcomes. A SOC 2 report is issued by an accredited CPA firm after an audit. Your auditor decides; Complies gets you ready, with controls mapped, evidence organized, and gaps closed before that audit starts.
Most startups do Type 1 first because a customer deal is waiting on it: it checks control design at a single point in time and is faster to reach. Type 2 observes the same controls operating over 3 to 12 months and carries more weight with security teams. In Complies the control set is the same, so a Type 1 flows into the Type 2 observation window without rework.
Budget the auditor separately: a Type 1 audit typically runs $5,000 to $20,000 in CPA firm fees, and Type 2 usually costs more because of the observation period. Complies Growth is $199 a month billed yearly, $2,388 a year, which covers the readiness side that incumbents like Vanta or Drata quote at roughly $7,500 to $25,000 or more per year.
Anyone quoting a fixed number before seeing your stack is guessing. Complies gives you a readiness score and a ranked gap list on day one, so the timeline becomes a plan you can staff. Teams starting from a reasonable security baseline, SSO in place and infrastructure in AWS, commonly reach Type 1 readiness in 6 to 12 weeks of part-time work.
SOC 2 compliance software maps your internal controls to the AICPA Trust Services Criteria, collects the evidence that those controls operate, and tracks the gaps until you are ready for a CPA firm to examine you. In practice that means an obligation per criterion with an owner and a due date, automated evidence pulls from your cloud and identity providers, policy versioning with acknowledgments, and a readiness view your team and your auditor can both read. It does not perform the audit or issue the report.
SOC 2 audit preparation is four jobs in order: scope the report, close the control gaps, run the evidence, then package it. Decide Type 1 or Type 2 and which Trust Services Categories beyond security you genuinely need. Map every in-scope criterion to a real control with an owner. Operate those controls long enough to have evidence, which for Type 2 means the whole observation window. Then hand the auditor an organized pack rather than a shared drive. Complies tracks all four as dated obligations so nothing is discovered late.
A working SOC 2 audit checklist covers scope decisions, the control set, evidence, and readiness. Concretely: chosen report type and Trust Services Categories, a written system description, an approved policy set, a risk assessment, access control and access reviews, change management, logging and monitoring, incident response, vendor management, security awareness training, and a documented gap list with owners. Our SOC 2 compliance checklist article walks each item with what auditors typically sample.
They are the AICPA criteria your controls are examined against, currently the 2017 Trust Services Criteria with revised points of focus issued in 2022. There are five categories: security, availability, processing integrity, confidentiality, and privacy. Security, delivered through the CC-series common criteria, is in scope for every SOC 2 examination. The other four are optional and you add them because you committed to them contractually or a buyer asked. Each category you add expands the control set and the evidence burden, so scope deliberately.
It depends on which constraint binds you. If budget and speed of purchase matter most, a self-serve platform with published pricing gets you started the same day and avoids a procurement cycle, which is why Complies runs $79 to $499 a month with every framework cross-mapped from Growth. If you want the deepest integration catalog and a large partner auditor network, Vanta and Drata lead there, at quote-only contracts that third-party medians put around $20,000 to $25,000 a year. If you would rather buy the platform and the audit from one vendor, Thoropass is the outlier that does that.
They ask for the report, not a badge. A prospect's security team requests your current SOC 2 report under NDA, because SOC 2 reports are confidential and there is no public registry to check. They read the auditor's opinion, the exceptions in section 4, the complementary user entity controls they would have to operate on their side, and how subservice organizations were handled. If your report is older than a year they will also ask for a bridge letter, which is management's word rather than an audited document.
Name the owner of every control before fieldwork and make sure that person can explain how it works and show the evidence without hunting. Walk each owner through the criteria their control maps to, dry-run the two or three questions an auditor asks about it, and make sure the evidence in the pack is the same evidence they would produce live. Most exceptions come from a control that genuinely operated but nobody could prove on the day. Complies keeps the owner, the criterion, and the evidence on the same record for exactly this reason.
A spreadsheet is a reasonable starting point and a bad system of record. The AICPA publishes the criteria, not a controls list, so any Excel list you download is somebody's interpretation of what satisfies them. Our SOC 2 controls list article sets out the common criteria with a typical control and the evidence an auditor samples for each, which is the part a spreadsheet cannot carry. The reason teams outgrow the spreadsheet is ownership and recurrence: a cell does not chase a quarterly access review.
Yes, and doing them on one control library is meaningfully cheaper than running two programs. Access control, change management, risk assessment, incident response, and vendor management map across both, so SOC 2 work typically pre-fills around 60% of ISO 27001. What does not carry over is the ISO management machinery: scope, Statement of Applicability, internal audit, and management review. Complies includes all five frameworks cross-mapped from Growth at $199 a month, so a second framework is not a second invoice.
SOC 2 Type 1 vs Type 2: Differences, Costs, and Which to Do First
SOC 2SOC 2 Audit Cost: Real Price Breakdown for 2026
SOC 2SOC 2 Controls List: All 33 CC1 to CC9 Common Criteria
VENDORSVendor Risk Assessment: Risk Rating and Template
Start your SOC 2 readiness today
Growth includes every framework, cross-mapped, at $199 a month.