FAQs

Frequently Asked Questions

Everything you need to know about security and privacy compliance, from SOC 2 and ISO 27001 to GDPR, NIS 2, and beyond.

Questions about SOC 2 compliance and certification

SOC 2 is an audit report (not a certification) issued by a licensed CPA firm validating your security controls. It's widely adopted in North America, particularly within the SaaS industry, and helps build trust with enterprise customers by demonstrating your commitment to data security and privacy.

SOC 2 Type 2 takes 4.5-6 months total from kickoff to final report. This includes 6-8 weeks for implementation and a minimum 3-month observation period (industry standard for first-time reports). Your time investment is approximately 15-20 hours total.

SOC 2 costs approximately EUR 10,000-15,000 all-in for Year 1, including the compliance platform, audit coordination with independent auditor partners, penetration testing, and security tools. This investment typically pays for itself with one enterprise deal worth EUR 50,000-200,000+ ARR.

Type 1 is a point-in-time assessment that proves controls exist at a specific date, while Type 2 evaluates controls over an observation period (minimum 3 months for first-time reports) to validate they work consistently. Enterprise customers expect Type 2. Type 1 is rarely accepted as sufficient. We recommend going straight to Type 2.

SOC 2 evaluates organizations against five Trust Services Criteria: Security (required), Availability (for SLAs), Privacy (for PII), Processing Integrity (for financial transactions), and Confidentiality (for trade secrets). Most SaaS companies need Security + Availability.

SaaS companies selling to enterprises, especially those with 500+ employees, typically need SOC 2. Start now if enterprise customers are requesting it, you're losing deals to compliant competitors, or security questionnaires consume 5+ hours per prospect.

You can accelerate the implementation phase from 8 weeks to 6 weeks, but the minimum 3-month observation period for first-time Type 2 reports is industry standard and cannot be shortened. Plan to start 5 months before you need the report.

No, you'll still receive security questionnaires, but your report proves your answers aren't just marketing claims. Expect a 50-70% reduction in effort, not 100% elimination. A third-party auditor has validated your security controls.

No. AWS, GCP, or Azure SOC 2 reports cover their infrastructure, not your application. You still need your own SOC 2 report that demonstrates your security controls on top of their infrastructure.

Technically forever, but practically 12 months. Customers expect an annual report, and after 12 months your report is considered stale. You'll need to renew annually to maintain credibility.

Penetration testing is not strictly required by AICPA standards, but it's strongly recommended and expected by most enterprise customers. Security questionnaires typically ask for pen test results regardless of your SOC 2 status, making it a practical necessity.

No, SOC 2 is an attestation, not a certification. A CPA firm examines your controls and issues a report stating whether your controls meet the Trust Services Criteria. Unlike ISO 27001, there's no certificate to display.

Yes, but it adds 200+ hours of manual work for evidence collection, policy writing, and control tracking. A compliance platform automates evidence collection, provides policy templates, and streamlines the audit process significantly.

Want to dive deeper?

Explore our comprehensive learning resources for each compliance framework.

AICPASOC

SOC 2

Everything you need to know about SOC 2 compliance, from basics to certification.

20 articles

ISO27001

ISO 27001

Complete guides to ISO 27001 certification, ISMS implementation, and maintenance.

22 articles

GDPR

GDPR

Comprehensive guides to GDPR compliance, data protection, and privacy requirements.

26 articles

CyberEssentials

Cyber Essentials

UK Cyber Essentials certification guides and technical control requirements.

16 articles

ISO42001

ISO 42001

AI management system certification and responsible AI governance guides.

12 articles

NIS 2

NIS 2

EU NIS 2 Directive compliance for essential and important entities.

20 articles

Other platforms check the box

We secure the box

Get in touch and learn why hundreds of companies trust Bastion to manage their security and fast-track their compliance.

Get Started