Hacker News new | ask | show | jobs
by saluki 29 days ago
Soc-2 Type 2 is a lot of work for solo-ent. and you might have issues meeting some of the compliance with only one employee there won't be checks and balances. We worked with a local firm and their fee was around $15k but there is ongoing verification. Also there is a process you have to follow moving forward that's probably the largest cost.

I'm not sure SOC-2 is even valuable for most smaller apps. As it's compliance is more aligned for financial apps.

It might be more valuable for you to have a security audit instead of SOC-2.