ComplianceBenchmark3 min readUpdated September 2026

SOC 2 Timeline: Each Phase and What Slows It Down

SOC 2 takes as long as it takes to close your control gaps, run the observation window (for Type 2) and complete the audit. There is no single number: the gap work, the window and the auditor's schedule each add time.

A better question is which phase you control. Below are the phases in order, what determines each one's length, and how to build a calendar that doesn't slip.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What are the phases of a SOC 2 project?

Every project passes through the same stages, even when lengths differ:

  1. Scoping and gap assessment. Decide systems, criteria and report type, then compare current practice against the controls.
  2. Remediation. Write policies, set up access controls and change management, and fix the gaps found.
  3. Tooling and evidence setup. Connect systems, schedule recurring tasks and confirm evidence is collected.
  4. Observation window (Type 2 only). Controls run while the auditor's samples accumulate.
  5. Audit fieldwork. The auditor requests evidence, tests samples and asks follow-up questions.
  6. Report drafting and review. You review the draft, correct factual errors and receive the final report.

A Type 1 skips the window. That's why it can be faster to a first report, as the Type 1 vs Type 2 guide explains.

What makes each phase longer?

Most delays trace back to a small set of causes:

  • Broad scope. Every extra system, office or data flow adds evidence and interviews. Trim scope to what supports the service.
  • Missing basics. No single sign-on, no code review rule or unclear ownership means remediation is real engineering work, not paperwork.
  • Unstable team. Turnover during the window creates onboarding and offboarding evidence you have to get right.
  • Slow evidence. If an engineer has to hunt for logs each time, fieldwork drags. Automating exports pays off here.
  • Auditor availability. Reputable firms book up. Ask early when they can start and how long fieldwork usually runs.

A compliance platform such as Vanta or Drata can help with evidence collection, but it can't shorten a window the auditor requires.

How do you build a realistic schedule?

Work backward from the date you need the report, then add margin for the phases you don't control. For example, say a customer wants a report before a contract renewal in the autumn. List the fixed dates: renewal, the earliest auditor start, the minimum window your auditor will accept. Then count backward to see when remediation must be finished.

If the numbers don't fit, you have three levers: narrow the scope, choose Type 1 as a first step, or give the customer interim assurance (policies, a completed questionnaire and a dated audit plan) and ask for time. Don't compress the observation window by cutting corners on controls. A report full of exceptions is worse than a later one.

Get the auditor's own estimates in writing, since firms vary in fieldwork length and review time.

A sample planning table you can adapt

Build a simple table with these columns: phase, owner, dependency, start date, target finish and risk. Fill it in like this:

  • Scoping: compliance owner; depends on customer requirements; risk is scope creep.
  • Remediation: engineering lead; depends on the gap list; risk is competing product work.
  • Evidence setup: operations or IT; depends on tool selection; risk is missing integrations.
  • Window and fieldwork: auditor and compliance owner; depends on stable controls; risk is exceptions.

Review it every two weeks and treat any phase that slips as a decision: cut scope, add people, or move the date. Start with the readiness checklist to size the remediation phase honestly.

Can you speed it up without lowering quality?

Some tactics genuinely help:

  • Fix scope first, then tools.
  • Enforce controls through systems (required reviews, single sign-on) rather than reminders.
  • Use one person as the auditor's single contact, so requests aren't lost.
  • Pre-collect evidence in a shared folder organized by control.
  • Run a mock walkthrough before fieldwork.

Others backfire: rushing policy writing with generic text, or starting the window before controls run reliably. Both invite exceptions. Also plan for after the report: annual renewal means the effort repeats, so build habits that make the next cycle cheaper. If you're also weighing a European framework, compare notes in ISO 27001 vs SOC 2.

Executive Capability Standard

What Good Looks Like

You have a dated plan that works backward from the report deadline, names an owner per phase and includes the auditor's own written estimates.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Map the six phases and note which ones your team controls and which depend on the auditor or the window.
2. Do Manually:Build the planning table in a spreadsheet and review it every two weeks with the compliance owner and engineering lead.
3. Delegate:Assign one person to be the auditor's single point of contact and to keep the evidence folder organized by control.
4. Automate:Schedule recurring evidence exports and control checks so evidence builds up during the window without extra effort.
5. Buy:Bring in a compliance platform or a readiness advisor when remediation work is larger than your team can absorb alongside product work.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Vanta

Fits when slow evidence collection is your main bottleneck; confirm in a demo which of your systems it connects to.

Visit Vanta→
Drata

Fits when you want ongoing tracking during the observation window; confirm in a demo how it covers your stack.

Visit Drata→

Frequently Asked Questions

How long does a SOC 2 Type 1 take?

It depends mainly on how many gaps you must close and how quickly an auditor can start. With no observation window, it's shorter than a Type 2. Get a gap assessment first; it tells you how much remediation stands between you and an audit date.

How long is the SOC 2 Type 2 observation period?

The window is set with your auditor, and lengths vary by firm and by customer expectations. Ask your auditor what they'll accept for a first report and what your customers expect. Don't plan around a fixed number you haven't confirmed.

What is the biggest cause of SOC 2 delays?

Unfinished remediation is the most common. Teams start the audit clock before controls such as access reviews and change approvals run consistently. Slow evidence collection and limited auditor availability come next. A gap assessment early on exposes most of them.

Can we get SOC 2 in a few weeks?

Only for a narrow scope with controls already in place, and usually only a Type 1. A Type 2 needs an observation window, which cannot be skipped. Be wary of anyone promising a fixed short timeline without reviewing your systems.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides