Note in security-speak the keyword is "mitigation" (you don't have x but you mitigate that by y)
Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
151–160 of 164 posts
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#152Earlier quoted context omitted.
Fully agree, the only downside is without a SOC2 you will be asked to fill out an insane 200+ questionnaire. Good news is you have all these great LLM tools you can do this work for you, and just check it over.
In my industry they still ask for the questionnaire even if you have a SOC2 report!
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#153Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#154Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#155Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#156Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#157Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#158I am a solo entrepreneur. Don't. I learned that my business is unable to pass pretty much ANY certification or corporate IT security audit. Many of the questions simply do not apply to my business ("do you have documented procedures for revoking employee access") and the default answer is NO. Get even a single NO and you're done. I gave up and these days actively discourage enterprises from even trying to sign up — t…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#159I'm not sure SOC-2 is even valuable for most smaller apps. As it's compliance is more aligned for financial apps.
It might be more valuable for you to have a security audit instead of SOC-2.