SOC 2 Timeline: Each Phase and What Slows It Down
SOC 2 takes as long as it takes to close your control gaps, run the observation window (for Type 2) and complete the audit. There is no single number: the gap work, the window and the auditor's schedule each add time.
A better question is which phase you control. Below are the phases in order, what determines each one's length, and how to build a calendar that doesn't slip.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What are the phases of a SOC 2 project?
Every project passes through the same stages, even when lengths differ:
- Scoping and gap assessment. Decide systems, criteria and report type, then compare current practice against the controls.
- Remediation. Write policies, set up access controls and change management, and fix the gaps found.
- Tooling and evidence setup. Connect systems, schedule recurring tasks and confirm evidence is collected.
- Observation window (Type 2 only). Controls run while the auditor's samples accumulate.
- Audit fieldwork. The auditor requests evidence, tests samples and asks follow-up questions.
- Report drafting and review. You review the draft, correct factual errors and receive the final report.
A Type 1 skips the window. That's why it can be faster to a first report, as the Type 1 vs Type 2 guide explains.
What makes each phase longer?
Most delays trace back to a small set of causes:
- Broad scope. Every extra system, office or data flow adds evidence and interviews. Trim scope to what supports the service.
- Missing basics. No single sign-on, no code review rule or unclear ownership means remediation is real engineering work, not paperwork.
- Unstable team. Turnover during the window creates onboarding and offboarding evidence you have to get right.
- Slow evidence. If an engineer has to hunt for logs each time, fieldwork drags. Automating exports pays off here.
- Auditor availability. Reputable firms book up. Ask early when they can start and how long fieldwork usually runs.
A compliance platform such as Vanta or Drata can help with evidence collection, but it can't shorten a window the auditor requires.
How do you build a realistic schedule?
Work backward from the date you need the report, then add margin for the phases you don't control. For example, say a customer wants a report before a contract renewal in the autumn. List the fixed dates: renewal, the earliest auditor start, the minimum window your auditor will accept. Then count backward to see when remediation must be finished.
If the numbers don't fit, you have three levers: narrow the scope, choose Type 1 as a first step, or give the customer interim assurance (policies, a completed questionnaire and a dated audit plan) and ask for time. Don't compress the observation window by cutting corners on controls. A report full of exceptions is worse than a later one.
Get the auditor's own estimates in writing, since firms vary in fieldwork length and review time.
A sample planning table you can adapt
Build a simple table with these columns: phase, owner, dependency, start date, target finish and risk. Fill it in like this:
- Scoping: compliance owner; depends on customer requirements; risk is scope creep.
- Remediation: engineering lead; depends on the gap list; risk is competing product work.
- Evidence setup: operations or IT; depends on tool selection; risk is missing integrations.
- Window and fieldwork: auditor and compliance owner; depends on stable controls; risk is exceptions.
Review it every two weeks and treat any phase that slips as a decision: cut scope, add people, or move the date. Start with the readiness checklist to size the remediation phase honestly.
Can you speed it up without lowering quality?
Some tactics genuinely help:
- Fix scope first, then tools.
- Enforce controls through systems (required reviews, single sign-on) rather than reminders.
- Use one person as the auditor's single contact, so requests aren't lost.
- Pre-collect evidence in a shared folder organized by control.
- Run a mock walkthrough before fieldwork.
Others backfire: rushing policy writing with generic text, or starting the window before controls run reliably. Both invite exceptions. Also plan for after the report: annual renewal means the effort repeats, so build habits that make the next cycle cheaper. If you're also weighing a European framework, compare notes in ISO 27001 vs SOC 2.
What Good Looks Like
You have a dated plan that works backward from the report deadline, names an owner per phase and includes the auditor's own written estimates.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
How long does a SOC 2 Type 1 take?
It depends mainly on how many gaps you must close and how quickly an auditor can start. With no observation window, it's shorter than a Type 2. Get a gap assessment first; it tells you how much remediation stands between you and an audit date.
How long is the SOC 2 Type 2 observation period?
The window is set with your auditor, and lengths vary by firm and by customer expectations. Ask your auditor what they'll accept for a first report and what your customers expect. Don't plan around a fixed number you haven't confirmed.
What is the biggest cause of SOC 2 delays?
Unfinished remediation is the most common. Teams start the audit clock before controls such as access reviews and change approvals run consistently. Slow evidence collection and limited auditor availability come next. A gap assessment early on exposes most of them.
Can we get SOC 2 in a few weeks?
Only for a narrow scope with controls already in place, and usually only a Type 1. A Type 2 needs an observation window, which cannot be skipped. Be wary of anyone promising a fixed short timeline without reviewing your systems.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
SOC 2 Type 1 or Type 2 First? How to Decide
Should a startup start with SOC 2 Type 1 or go straight to Type 2? Compare what each proves, when buyers accept each, and how to sequence the audits.
SOC 2 Readiness Checklist: 12 Things to Fix Before the Audit
A practical SOC 2 readiness checklist for startups: scope, policies, access, change control, vulnerability handling, vendors and evidence, in order.
ISO 27001 or SOC 2? A Guide for US Startups Selling in Europe
Which security framework should a US startup selling to European customers pursue first, ISO 27001 or SOC 2? Differences, overlap and a decision guide.
What a SOC 2 Audit Costs a Small Company: A Worksheet
Break down SOC 2 costs for a small company: auditor fees, readiness work, compliance software, testing and staff time, with a worksheet to get real quotes.
Vanta vs Drata vs Secureframe: Best SOC 2 Automation Platform
Comparing Vanta, Drata, and Secureframe: API evidence collection, auditor networks, true costs, and when each platform is the wrong choice.
What SOC 2 Actually Asks of Engineering, and What It Doesn't
A plain answer to what a SOC 2 audit checks in your engineering org, what evidence auditors actually want, and what's commonly over-built for it.