Hacker News new | ask | show | jobs
by akerl_ 974 days ago
https://fly.io/blog/soc2-the-screenshots-will-continue-until... is probably what I'd recommend as the best reference for your situation.

That said, I'd suggest that ~20k isn't nuts for an auditor to walk you through the process bits, and is likely the cheap part. You're almost certainly going to lose more money in IC hours that your staff spend dealing with your first round of evidence collection than the 20k.