Most 90-day SOC 2 plans on the internet quietly skip the part where the auditor needs a multi-month observation window. So before the plan itself, the honest framing: in 90 focused days a team of two to ten people can realistically finish scoping, write and adopt policies, get core controls running, and gather a clean evidence set. That is the readiness phase, and it is the part you control.
What happens after is on a different clock. A Type I can follow fairly quickly, since it looks at control design at a point in time. A Type II requires the auditor to observe your controls operating over a defined period — commonly three to six months or more — and then to perform testing and write the report. Plan on additional months after day 90, not instead of them.
Month 1 — Scope it, then write the foundations
The single biggest time sink for small teams is starting work before knowing what’s in scope. Spend the first week deciding, in writing:
- Which Trust Services Criteria apply. Security is mandatory. Add Availability if you make uptime commitments, Confidentiality if you handle customer data under NDA-like terms, and Privacy or Processing Integrity only if they genuinely reflect your promises. Adding criteria you don’t need adds months of work.
- Which systems are in scope. Name the production environment, the code repositories, the identity provider and the third-party services that touch customer data. Everything else is out of scope, and saying so explicitly saves arguments later.
- Who owns it. One named person, even part-time. Shared ownership across founders reliably means no ownership.
With scope fixed, draft the foundational policies: information security, access control, acceptable use, incident response, change management, vendor management, risk assessment, and business continuity. Two rules make this fast. First, write what you actually do, not aspirational practice — auditors test against your own words. Second, start from templates rather than a blank page; this is where tools like ComplyEasy or any decent template library earn their place.
By the end of month 1 you want a documented scope, an owner, and a set of approved policies with dates and version history. A gap analysis at this stage is also worth running, because it tells you which of the remaining 60 days matter most.
Month 2 — Implement the controls and document them
Policies without matching practice fail an audit faster than no policies at all. Month 2 is about making the words true and leaving a paper trail. The controls that come up almost universally for small teams:
- Access control and reviews. Enforce SSO and MFA, remove shared accounts, apply least privilege on production and cloud accounts, and run your first documented user access review. Record who reviewed what, when, and what changed.
- Onboarding and offboarding. A written checklist that covers account creation, device setup, security training acknowledgement, and — critically — timely revocation when someone leaves. Offboarding evidence is a very common finding.
- Vendor management. Build an inventory of subprocessors and SaaS vendors that touch customer data, note what data each one sees, and record a risk tier plus a review of their security posture (usually their own SOC 2 or ISO report).
- Change management. Pull requests with peer review, protected main branches, and a traceable path from change to deploy. Most engineering teams already do this; the work is proving it.
- Risk assessment. One documented pass identifying your real risks, their likelihood and impact, and what you’re doing about each. It does not need to be elaborate. It does need to exist and be dated.
- Monitoring, logging and backups. Alerting on your production environment, retained logs, and a backup process you have actually tested at least once.
- Security awareness training. A short annual training with recorded completion for every employee and relevant contractor.
As you go, capture evidence at the moment the work happens — a screenshot, an exported list, a ticket link. Reconstructing this in month 3 costs several times as long.
Month 3 — Evidence, then an internal readiness review
Month 3 is consolidation. Map every control to the evidence that proves it, and store that evidence in one place with clear dates and owners. A single organised repository beats a perfect one you can’t navigate; keeping findings, tasks and supporting documents together is the main reason we built ComplyEasy the way we did.
Then run an internal readiness review, ideally with fresh eyes:
- Walk each policy statement and ask “can I show this happening?”
- List every gap with an owner and a date, and close the ones that are cheap to close now.
- Confirm your evidence is dated, attributable and complete for the period you intend to be observed.
- Write down anything still open, with a plan. Auditors are far more comfortable with a known, tracked gap than a surprise.
Also use month 3 to start conversations with audit firms. Scoping, proposals, contracting and scheduling take weeks on their own, and you want the auditor engaged before your observation period begins rather than after — otherwise you may repeat evidence collection for a window that counts.
What happens after day 90
At the end of 90 days a disciplined small team should have: a defined scope, adopted policies, implemented controls, organised evidence, a closed-out readiness review, and an auditor selected. That is genuinely the hard part.
Then the calendar takes over. If you go for a Type I, the auditor examines control design at a point in time and you can have a report relatively soon. If you go for a Type II — which is what most enterprise buyers eventually want — the observation period runs its full three to six-plus months, the auditor tests during and after it, and the report follows. Total elapsed time from day one to a Type II report is usually somewhere between six and twelve months, and no tool changes that.
A common, sensible pattern: complete readiness in 90 days, start a Type II observation window immediately, and use the Type I report or your readiness documentation to unblock deals in the meantime.
Common ways the 90 days go wrong
- Scoping too broadly. Every extra criterion or system multiplies work. Narrow first; expand at renewal.
- Writing policies nobody follows. Aspirational documents create findings.
- Leaving evidence to the end. Retroactive evidence is slow and sometimes impossible.
- Engaging the auditor too late. Their scheduling is often the long pole.
- Treating it as a one-off. Access reviews, training and vendor reviews recur; build the cadence now.
Start your 90 days with a clear gap list
Run a free gap analysis, get a scored list of what's missing, and work through it month by month. Free plan, no card required.
Want the fundamentals first? Read SOC 2 compliance for startups.