Blog

Why I started soc2doc

I have spent 27 years in cybersecurity. I have led more than 40 SOC 2 certifications and worked with over 150 organizations — ten-person startups, mid-market SaaS companies, and names like the Federal Reserve, American Express, and Target. Different sizes, different industries, different budgets.

The same thing kept happening at all of them.

A company works for months to get its SOC 2 report. The auditor signs. The PDF lands. Sales attaches it to every security review, the deal closes, and everyone exhales. And from that moment, almost nobody in the building can tell you what the report actually says.

Not the summary — the substance. The specific promises. That access gets reviewed every quarter, by a named role. That vendors get assessed annually. That backups get tested, policies get re-approved, incidents get handled a documented way. A first Type II report typically carries 30 to 60 of these commitments. They were written down, tested once, signed by management — and then filed.

The gap nobody owns

Here is what I kept walking into, year after year.

The person who "owns compliance" also runs IT, or engineering, or finance. They inherited a spreadsheet from someone who left. The spreadsheet disagrees with the report. The report says a control runs quarterly; the last evidence is fourteen months old. Nobody decided to stop doing it — the person who did it left, and the promise did not transfer with their laptop.

Meanwhile the company keeps making the promise. Every time sales sends the report to a prospect, every time someone answers a security questionnaire from memory, the company re-asserts commitments that no one is tracking. When a prospect's security team reads the actual report next to the questionnaire answers and the two disagree, the deal dies quietly. Nobody calls to tell you why.

Then the next audit comes, and it starts from the last report. Whatever silently stopped happening in the gap is now a finding. The scramble begins again — three weeks of reconstructing a year of evidence — and everyone privately concludes that compliance is theater.

Why the industry hasn't fixed this

It is not for lack of spending. The compliance market has never had more products in it.

Automation platforms will screenshot your cloud configurations on a schedule and light up a dashboard. Genuinely useful — and quietly beside the point, because collecting evidence is not the same as keeping promises. The dashboard doesn't know what your report committed you to. It knows what it can reach with an API key.

Consultants — my own profession, for most of three decades — know exactly what the report says. But hourly consulting ends when the invoice does, and the knowledge leaves in the consultant's head. I have been that consultant. The model bills well and transfers almost nothing.

And auditors, correctly, stay independent. Their job is to test the promises, not to help you keep them.

So the actual job — knowing every promise, keeping each one owned and evidenced, all year — falls into the space between three industries, and lands on whoever at the company lost the coin toss.

The companies that suffer most are the ones the industry serves worst: the 20-to-200-person company that needed SOC 2 to close its first enterprise deals. They cannot hire a compliance team. They are sold a dashboard and left to operate it, or quoted enterprise consulting rates for a fraction of a consultant's attention. Most end up doing what everyone quietly does — hoping the auditor doesn't look too hard, and answering questionnaires from memory.

The moment it crystallized

Across those 40-plus certifications, one exercise never failed to land. I would sit with a leadership team and read their own report back to them, promise by promise, in plain English. The room always went quiet in the same way. These were the people who signed the management assertion — and they were hearing half of these commitments for the first time.

That silence is the problem. Not malice, not laziness. Companies sign a dense, 100-page document written in auditor language, under deal pressure, and the promises inside it never get translated into something a business can actually see and run. The report is treated as the finish line when it is a starting gun.

After the fortieth time watching that silence, I stopped thinking of it as a client problem and started thinking of it as the industry's central failure. That is why soc2doc exists.

What we are building to close the gap is the next post.


← All posts