Live data from Hacker News

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

news.ycombinator.com

21–30 of 164 posts

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#21
post #6

Definitely possible. Start with SOC2-aligned practices and a solid public security page — many early customers care more about transparency and good security hygiene than the certificate itself.

> many early customers care more about transparency and good security hygiene than the certificate

I work on audit compliance for a SOC2 compliant system, and as part of our own audit requirements it is non-negotiable that all of our vendors must themselves be SOC2 compliant.

I very much doubt anyone who has a SOC2 requirement is not in the same boat with respect to dependencies

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#23
post #11
post #6

Definitely possible. Start with SOC2-aligned practices and a solid public security page — many early customers care more about transparency and good security hygiene than the certificate itself.

Thank you! Could you please share some great example of public security page so I can get some inspiration?

I was also interested in that and chatgpt came up with these:

https://iozen.ai/security/

https://logpulse.io/security/ SOC2 "in progress" haha

https://get.brightidea.com/security/

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#24
post #19

Not possible in case your clients are not stupid. Any company with SOC2 and You might find auditors that would go along but any reasonable client will check your SOC2 report and quality of your auditors. SOC2 requires tons of paperwork and management and separation of duties with also mandatory roles in your company - never feasible in a one man show.

So that means that solo-entrepreneurs can't sell apps to big enterprises due to SOC2 limitation? I think that it is not fair

It isn’t fair, but few rackets are.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#25
post #19

Not possible in case your clients are not stupid. Any company with SOC2 and You might find auditors that would go along but any reasonable client will check your SOC2 report and quality of your auditors. SOC2 requires tons of paperwork and management and separation of duties with also mandatory roles in your company - never feasible in a one man show.

So that means that solo-entrepreneurs can't sell apps to big enterprises due to SOC2 limitation? I think that it is not fair

It’s a disadvantage for sure but not usually a blocker.

They often have security questionnaires you can complete instead. Or, as part of signing with them, you can promise to get SOC2 by x date (which will hopefully be easier with the funds from an enterprise contract).

I’d recommend looking online at some example security questionnaires or the types of things soc2 covers and writing an internal security doc for yourself so you know your position on everything and don’t have to scramble when it comes to it.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#26
post #25
post #19

Earlier quoted context omitted.

So that means that solo-entrepreneurs can't sell apps to big enterprises due to SOC2 limitation? I think that it is not fair

It’s a disadvantage for sure but not usually a blocker. They often have security questionnaires you can complete instead. Or, as part of signing with them, you can promise to get SOC2 by x date (which will hopefully be easier with the funds from an enterprise contract). I’d recommend looking online at some example security questionnaires or the types of things soc2 covers and writing an internal security doc for your…

Thank you for your comment!

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#27
post #23
post #11

Earlier quoted context omitted.

Thank you! Could you please share some great example of public security page so I can get some inspiration?

I was also interested in that and chatgpt came up with these: https://iozen.ai/security/ https://logpulse.io/security/ SOC2 "in progress" haha https://get.brightidea.com/security/

Thank you!

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#29
I've been through SOC 2 Type 2 in a company with ~100 people. I think it'd be in some ways simpler as a solopreneur, but still a lot of effort. You won't require as complex controls and you don't need to communicate between different parts of company, but it'll just be yourself doing it all.

On a positive side, you won't have to do 100% of SOC 2 Type 2. The only required part is security if I remember correctly. And a lot of it is best practices that need to be in place anyway. If you are using an established cloud provider a lot of it is in place through their certifications. Some of the controls can be "silly", but generally not hard to put in place. I'd try to figure out what are the minimum nr of controls required and see if that is doable. Pretty sure auditors will give a discount there if the scope is smaller.

It can be somewhat useful for the company if taken seriously, as it can point out weaknesses in processes. Although I agree with other comments that most of it is a checkbox exercise than something that provides any real guarantees to the client demanding it.

I also don't know if getting through it with Edit: Also, the auditor makes a difference. Pick one that understands small companies. A corporation auditor will get confused with "segregation of duties" if you are the only person in the company.

Post reply on HN