Live data from Hacker News

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

news.ycombinator.com

91–100 of 164 posts

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#91
post #43

I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups who don’t have these certifications or budget. Start by pre-filling your own CAIQ v4 with an earnest “we don’t do this” or “we haven’t even thought about this” attempt: https://cl…

Do you genuinely use em-dashes in your regular writing ? I'm just curious because whenever I type I simply press -

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#92
post #57

Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…

I will add a few more things to this: - Document your data and security and share that with customers instead. You can say "We don't have SOC2 at the moment but here is all our security and data policy". It works 99% of the time for me. - Very few companies truly have policy to reject a vendor if they don't have SOC2. Those are usually large enterprise or companies in sensitive areas such as Finance/Healthcare etc. E…

> It works 99% of the time

I would add the caveat "...as long as you have no competition." If you're in a market where alternatives exist, and they have the certification, you're definitely transparently losing sales.

From the enterprise side, I can tell you vendor certification takes an order of magnitude more time/money/effort when the vendor says "we don't have cert X but here's a mountain of drivel you can paw through to try to assess risk." And not just once, but every single year during vendor reviews. It's just not worth it unless you're legitimately bringing something irreplaceable to the table -- to the point where even our executives know to google "companyname SOC2" before even engaging in a conversation.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#94
I'm a solo entrepreneur running a b2b saas product I built. I do not have a soc2 certificate (or any certificate). I have never lost any sales (that I know of) because of it.

I've sold to customers that pay $2XX,XXX annually and it was never an issue. I wouldn't worry about it, but be prepared to answer security questionnaires.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#95
I am a solo entrepreneur. Don't.

I learned that my business is unable to pass pretty much ANY certification or corporate IT security audit. Many of the questions simply do not apply to my business ("do you have documented procedures for revoking employee access") and the default answer is NO. Get even a single NO and you're done.

I gave up and these days actively discourage enterprises from even trying to sign up — these kinds of discussions can take a lot of your time and the expected value is negative, because sooner or later those kinds of questionnaires will be required (quite often the engineer talking to you doesn't even know this).

SOC2 falls into that category: you are unlikely to pass, and even if you do, enterprise customers will pull out their own questionnaires out of, well, let's just call it their store backrooms, and you will fail those. Waste of time.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#97
post #80

Earlier quoted context omitted.

My company had 6 employees, I was the CTO and I can't imagine getting SOC2 certified without using Vanta - that was back in their early access/beta days. I had no choice - we had so many security assessments spreadsheets sent by potential customers, that getting SOC2 saved us time in the long run.

I like the people at Vanta just fine but it really squicks me out to see people doing Vanta because it's the simplest way for them to clear this dumb hurdle --- that implies that they don't understand SOC2 and are just taking Vanta's word for it. The problem is, Vanta will ask (suggest? come perilously close to demand?) you do a lot of engineering work that is absolutely not necessary for a SOC2 attestation. Worse st…

In my experience it was as simple as connecting to AWS and tagging resources in Terraform. I got it all done in around 3 weeks. So maybe yes, if somebody doesn’t know about SOC2 then Vanta might be getting in the way but it in my case it literally solved all my problems in a month or so

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#98
Agree with tptacek for the speculative case — chasing SOC 2 without a deal on the table is expensive theater.

That said, there's a real inflection point where it flips. We've run SOC 2 for companies where the trust-establishment effort alone was costing 2-3 sales cycles per quarter. At that point the audit pays for itself fast. also, we can get that audit down substantially below 20k...

The signal to watch: if you're losing deals to a competitor who has it, or spending more time on security reviews than closing, that's your major signal.

Also, if your sales cycle becomes "days" or weeks instead of months, thats another major signal. A third-party certification is a stamp of approval that cuts through red tape and BS.

I'm a vCISO and founder at MARFI Systems, currently finishing a doctorate in cybersecurity at GWU and have helped numerous companies from 1-man startups to 500+ unicorns. Happy to jump on a call and help provide some clarify around security and compliance.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#99
post #55

Earlier quoted context omitted.

We are a team of 1 developer and 1 sales/marketing and are fully certified. You can hire an external auditor for the internal audit. We have AI code reviews, so we don’t need an extra developer.

Let me guess: certified by Sprinto?

No, we are EU based and used a local certifier.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#100
post #57

Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…

As someone who had to cobble together a soc2 program - this is mostly true. At a large enough firm, soc2 is useful as a base level of operations integrity which lots of small firms lack.

If you have not reached that level as a firm, a good and recent pen test does the trick.

Post reply on HN