Live data from Hacker News

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

news.ycombinator.com

71–80 of 164 posts

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#71
Has no one yet found a way to vibe-code this into a viable self-service solution?

and yes I do understand there is a IRL-auditing authority piece to all of this too.

Perhaps there this is a play here in the market to create a new auditing firm that 99% automates all this for startups? sans fraud certs of course.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#73
post #57

Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…

> in lieu of filling out security questionnaires.

Isn't that no longer an issue in AI era?

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#74
post #57

Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…

Plus, even when you have SOC2 (+pen test, +ISO 27001), you'll still have to fill out questionnaires!

But it is a bit easier if you can copy/paste from your existing documents than scramble to make up stuff ;)

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#75
post #57

Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…

+1 and to add to that…this is the correct answer for basically any kind of “enterprise” requirement from a customer as a solo-founder

Don’t make anything harder on yourself before you have to and then at the point that you have to (like needing an authority to operate certificate for a classified network) you’ll have the resources to be able to get what you need

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#76
post #74

Earlier quoted context omitted.

Plus, even when you have SOC2 (+pen test, +ISO 27001), you'll still have to fill out questionnaires!

But it is a bit easier if you can copy/paste from your existing documents than scramble to make up stuff ;)

LLMs FTW

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#77

Avoid it for as long as you can. I worked at a startup that sold to enterprises. We had 6 employees. The CEO / sales was able to work around the SOC2 requirement every time.

My company had 6 employees, I was the CTO and I can't imagine getting SOC2 certified without using Vanta - that was back in their early access/beta days.

I had no choice - we had so many security assessments spreadsheets sent by potential customers, that getting SOC2 saved us time in the long run.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#78
Ugh, it's hard. You can outsource as much as possible and minimize your surface area, those are the two approaches I have used, but the auditor expense is the biggest blocker. A few years back you could find auditors for $5-6k, but I think the security/audit service providers have eaten a lot of that market.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#80

Avoid it for as long as you can. I worked at a startup that sold to enterprises. We had 6 employees. The CEO / sales was able to work around the SOC2 requirement every time.

My company had 6 employees, I was the CTO and I can't imagine getting SOC2 certified without using Vanta - that was back in their early access/beta days. I had no choice - we had so many security assessments spreadsheets sent by potential customers, that getting SOC2 saved us time in the long run.

I like the people at Vanta just fine but it really squicks me out to see people doing Vanta because it's the simplest way for them to clear this dumb hurdle --- that implies that they don't understand SOC2 and are just taking Vanta's word for it.

The problem is, Vanta will ask (suggest? come perilously close to demand?) you do a lot of engineering work that is absolutely not necessary for a SOC2 attestation. Worse still: whatever controls you attest in your SOC2, you're practically locked into. If Vanta has you set up some cloud detection capability, and it turns out as you mature your security organization that it wasn't necessary or even useful, you have a fight on your hands with your Type II auditor about why you stopped doing it.

Post reply on HN