Live data from Hacker News

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

news.ycombinator.com

151–160 of 164 posts

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#151
Instead of trying to get the actual SOC 2 attestation, do a version of the homework that would get you there; basically writing documentation. The output would be documents describing different procedures or existing infra (disaster recovery, network diagrams etc) and a master spreadsheet with the "soc 2" questions (that you pick) and answers, a "security questionnaire" and this is what you send to companies when they insist.

Note in security-speak the keyword is "mitigation" (you don't have x but you mitigate that by y)

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#152
post #104

Earlier quoted context omitted.

Fully agree, the only downside is without a SOC2 you will be asked to fill out an insane 200+ questionnaire. Good news is you have all these great LLM tools you can do this work for you, and just check it over.

In my industry they still ask for the questionnaire even if you have a SOC2 report!

Yeah, I get this even with SOC2 Type 2 & ISO 27001 ... the requests never stop.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#153

Earlier quoted context omitted.

In my industry they still ask for the questionnaire even if you have a SOC2 report!

Yeah, I get this even with SOC2 Type 2 & ISO 27001 ... the requests never stop.

Just say no. Serious.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#154
There are plenty of companies and apps that can help you achieve SOC2 or ISO certification by showing your compliance score and telling what needs to be done. They provide templates and assist with setting up processes and policies that will get you to SOC2. This typically takes 4–6 months. I would suggest to go for ISO 42k1 instead of SOC2.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#158
post #95

I am a solo entrepreneur. Don't. I learned that my business is unable to pass pretty much ANY certification or corporate IT security audit. Many of the questions simply do not apply to my business ("do you have documented procedures for revoking employee access") and the default answer is NO. Get even a single NO and you're done. I gave up and these days actively discourage enterprises from even trying to sign up — t…

I know a solo founder who got SOC2 certified. He is literally the only person running the product/company and is SOC2 certified. I found that hilarious to be honest. But he is trying to play the "win enterprise deals" game but not sure how that helps when you are literally 1 person.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#159
Soc-2 Type 2 is a lot of work for solo-ent. and you might have issues meeting some of the compliance with only one employee there won't be checks and balances. We worked with a local firm and their fee was around $15k but there is ongoing verification. Also there is a process you have to follow moving forward that's probably the largest cost.

I'm not sure SOC-2 is even valuable for most smaller apps. As it's compliance is more aligned for financial apps.

It might be more valuable for you to have a security audit instead of SOC-2.

Post reply on HN