Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
51–60 of 164 posts
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#52I was part of several third party risk management audits from a corporate perspective. We regularly audited and questioned SMBs (and big corps) with regards to their security posture. We knew that small shops wouldn’t be able to be fully compliant to SOC2 Type 2 or have an ISO27001 certified environment. If it was clear that our business wanted the product, we either tried to help the company with the questionnaire o…
Can this also be done for HIPAA and FERPA, or for those compliance requirements is the process the way to go and just filling out the questionnaire would not be sufficient?
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#53Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#54I'm currently at a small startup trying to do ISO 27001. A big issue we run into is that there simply aren't enough people . For example, the processes are built around having one person who writes code, and another person who reviews the written code. That's obviously impossible as a solo dev. You also need an internal auditor, who obviously needs to be separate from the operations team. If I recall correctly the mi…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#55I'm currently at a small startup trying to do ISO 27001. A big issue we run into is that there simply aren't enough people . For example, the processes are built around having one person who writes code, and another person who reviews the written code. That's obviously impossible as a solo dev. You also need an internal auditor, who obviously needs to be separate from the operations team. If I recall correctly the mi…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#56Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#57SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously.
There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in which that happens is a purchase order made contingent on your SOC2 Type I attestation, where the revenue from that purchase order more than pays for the attestation.
Do not ever do a SOC2 speculatively, in the hopes that it will improve your sales prospects. Plenty of successful firms don't have SOC2s. If you're losing sales where SOC2 is a factor, you didn't have those sales to begin with.
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#58I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups who don’t have these certifications or budget. Start by pre-filling your own CAIQ v4 with an earnest “we don’t do this” or “we haven’t even thought about this” attempt: https://cl…
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#59Earlier quoted context omitted.
Can this also be done for HIPAA and FERPA, or for those compliance requirements is the process the way to go and just filling out the questionnaire would not be sufficient?
SOC2 is, at the end of the day, a voluntary compliance standard. HIPAA and FERPA requirements are federal law. Waiving those requirements would not just mean accepting additional liability, but would normally make your customer ineligible to receive federal funds, which are typically a substantial chunk of revenue.
Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
#60Not possible in case your clients are not stupid. Any company with SOC2 and You might find auditors that would go along but any reasonable client will check your SOC2 report and quality of your auditors. SOC2 requires tons of paperwork and management and separation of duties with also mandatory roles in your company - never feasible in a one man show.
So that means that solo-entrepreneurs can't sell apps to big enterprises due to SOC2 limitation? I think that it is not fair
It's important to really understand how unserious SOC2 is.