A client asked for your SOC 2 report. It's been on the roadmap for a year or two, and now it's attached to a renewal, so it just moved to the top of the list.
This is for the MSP owner who has to go find out what that involves, and especially for anyone who already bought Vanta or Drata, opened the questionnaire, and quietly stopped. You'll learn what the engagement costs in owner hours, how to scope it so you're not paying for criteria you don't need, why the big platforms don't fit a managed services shop, and the order to do Type 1 and Type 2.
Can an MSP use Vanta or Drata?
Technically yes, but it's a bad fit, because neither platform was built for managed services.
Both are good tools for the buyer they were designed around: a compliance specialist inside a software company. That person recognizes every question on the form, because the form describes the business they work in.
An MSP owner doesn't recognize the questions, so every requirement takes three times as long to answer.
Three specific things break. The questions ask about software you don't build. The CPA firm that performs the examination isn't included in the subscription, so the price you see isn't the price you pay. And when a question doesn't apply to your business, no one at the platform will tell you what to put.
The questionnaires assume you ship code
A generic SOC 2 platform asks about your software development lifecycle, your release process, and the cloud product you own. You don't have any of those, so you have to decide for yourself whether patch management counts as change management, and whether client onboarding counts as provisioning.
Nobody checks your answer. You either guess right or you fail the examination months later.
That guessing is what kills the project, and it kills it in one of two ways.
An owner buys the platform and hands it to a staff member. That person can't answer the questions either, and won't say so, so the login sits unused. The owner finds out nine months later.
Or the owner does it personally, hits a question that doesn't describe the business, and goes looking for help. What they find is a knowledge base and an automated email. Nobody will confirm whether an answer is good enough, so the work stops.
Both paths end the same way. The subscription renews, the requirements stay blank, and SOC 2 slides another year.
What an MSP-specific approach looks like
The fix is to ask MSP questions instead of SOC 2 questions.
Cyber Verify presents a requirement in language that describes your business. Something like: do you have a customer onboarding policy? Alongside it comes the reason the question is being asked, what the best practice is, and sample answers from other MSPs.
You answer as an MSP, and the platform maps your answer to the SOC 2 trust services criteria on the back end. The translation stops being your job.
MSPAlliance has certified MSPs since 2004, so the questions come from two decades of watching how managed services businesses actually run.
Scope it before you price it
The expensive mistake here is overscoping, and it's easy to make, because scope is what drives the bill.
SOC 2 has five Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Only Security is required. The other four are optional, and you add one because you made a specific commitment to a client, not because it came with the package.
Most MSPs need Security on its own. Availability belongs in scope if your agreements promise uptime. Processing Integrity is aimed at organizations that process transactions on a client's behalf, which most MSPs don't do.
Services work the same way. Scope covers your managed services line and the commitments in your agreements, so a low voltage division or a hardware resale practice doesn't automatically come along.
Ask any provider to quote Security-only first, then price each additional criterion separately. If they can't break it out that way, they're scoping for their own convenience rather than yours.
Do Type 1 first
Type 1 reports on whether your controls are designed correctly at a point in time. Type 2 reports on whether they operated correctly over a period.
Start with Type 1 unless a client demand forces your hand. It gets your policies written, your evidence organized, and your team used to the process while the stakes are lower.
Type 2 as a first move is possible, and sometimes a customer requires it. It's harder to schedule, because Type 2 needs a review period of at least 90 days before reports can be issued. That adds a full quarter to the timeline however fast you work.
If you do Type 1 and want Type 2 soon after, do it inside 12 months so the evidence stays fresh. A provider may credit what you paid for Type 1 toward the Type 2.
A letter of intent showing you've started will sometimes satisfy a customer's auditor, which buys you a year.
What the work actually takes
Expect roughly 100 requirements in total.
For a first year, plan on 50 to 60 hours of your time. Less if your policies are already implemented. More if you're starting from scratch.
Most Type 1 engagements run four to five months. Faster is possible but rare. One 30-person MSP put four people on it and finished in six weeks, which is unusual enough that nobody should plan around it.
The loop is simple. You submit a requirement. The team reviews it and either approves it or sends it back with a note on what to fix. If you can handle the correction yourself, you do. If not, you ask a person.
Once you're 80 to 90 percent through readiness, a CPA firm comes into the same platform and performs the examination remotely. By then most of your work is done, and your remaining role is reviewing the reports the team drafts. Reports are typically issued about four weeks later.
Those first-year hours are unavoidable, because you're writing policies that don't exist yet. Year two costs a fraction of that, since you're updating documents rather than creating them.
Don't chase a perfect report
There's no such thing as a perfect SOC 2 report, and a couple of exceptions isn't a bad outcome.
Some MSPs have asked to have an exception found, because their clients were suspicious of results that came back spotless. A report with nothing in it suggests the examiner didn't look hard.
If you've ever walked a client through their own compliance work, you've already made this argument to them. Every organization has deficiencies. The question an auditor is really asking is whether you know about yours, wrote them down, and understand why they're there.
An audit that surfaces two honest exceptions tells a better story than one claiming none.
What to ask before you buy any platform
Whoever you choose, get answers to these first:
- Are the questions written for MSPs, or translated from a software company template?
- Who performs the actual examination, and is that firm's fee included in the price?
- Is this a fixed fee, or are there billable hours on top?
- What's the support response time, and does a person answer?
- Can the scope be limited to my managed services line?
- What happens in year two, and how far does the time commitment drop?
The second and third questions are where platform pricing and total cost separate. A subscription that covers the software still leaves you to find and pay a CPA firm yourself.
Cyber Verify prices the engagement as a fixed fee covering the platform, the team's time, and the CPA firm's fees, split into 12 monthly payments by default. No billable hours. Support runs on a one hour response target, Monday to Friday, 9 to 5 Eastern, with chat in the portal.
Cyber Verify works with a pool of CPA firms and introduces one based on availability when your readiness is nearly complete.
Getting started
Scope the services you want covered. Decide whether a client deadline forces Type 2 or whether you can start with Type 1. Then get a quote showing total cost including the examination, so you're comparing a real number against platform-only pricing.
Book a demo to see the platform and get a scoped quote for your services.