Founders have a lot on their minds. Usually, SOC 2 doesn’t top the list.
Until they receive the dreaded email or text from their first enterprise prospect:
"Hey, was chatting with my boss. She reminded me we can only partner with vendors that have SOC 2. Just making sure - you all have that, right?"
At this point, they’re frantically prompting: “How do I get SOC 2 compliance fast?” and “How to get SOC 2 with no consultant?”
They decide that, with Claude or ChatGPT’s help and a free SOC 2 compliance checklist, they can get pretty far. Yet even with LLMs on their side, there will inevitably be parts of SOC 2 prep they can’t tackle themselves.
One big one most founders don’t see coming is training.
While there isn’t a SOC 2 training requirement, per se, it’s one of the major things auditors look for (we’ll share specifics later). And creating employee security training, deploying it, and continuously verifying that people have completed it takes work and expertise.
Below, we explain where training fits into SOC 2, the challenges that founders usually face trying to do it themselves, and how you can knock it out quickly to close whale customers faster.
But before we get too far down that road, you need to know what SOC 2 is and whether you truly need it. Here's a primer.
What’s SOC 2?
SOC 2 is a standard set forth by the AICPA (American Institute of Certified Public Accountants) that verifies whether a vendor stores, processes, and transmits its customers’ data – and their customers’ data – safely.
The reason preparing for SOC 2 is so arduous, and why audits take so long, is that every company has different processes and, therefore, different controls to meet the five SOC 2 Trust Services Criteria:
1. Security. Are your systems protected against unauthorized access? That covers outside attackers and internal employees. Think: firewalls, MFA, access controls, and the ability to detect and respond when something goes wrong.
2. Availability. Is your system up and reachable when your customers need it? As you can imagine, this matters a lot if your tool is something a customer’s operations depend on.
3. Processing Integrity. Does your system do what it says it does, completely, accurately, and on time? Companies that perform calculations or transactions on a customer’s behalf, like payments, payroll, or analytics, need to pay special attention to this one.
4. Confidentiality. Is information that’s been designated confidential (say, contracts, source code, business plans, IP) restricted to the people who should see it? Access controls and encryption are the major components here.
5. Privacy. Do you collect, use, retain, and dispose of personal information the way your privacy notice describes? Because this one is specifically about PII, it’s where SOC 2 starts to overlap with GDPR and CCPA.
Security is listed first here because it’s the only one that’s mandatory. The other four are technically optional.
For startups strapped for cash and resources, it makes sense to pursue Security Criteria first, then add the other four as your business model, contractual obligations, or customer expectations change.
Ahead of an audit, your CPA will ask you which systems and Trust Services Criteria you want them to review. They’ll ask to see documentation of your various controls, tests you’ve run, and proof that you’re continuously educating your employees on your security policies. It’ll take a few months for the auditor to run their audit and then prepare their findings.
Do startups need SOC 2?
You need a SOC 2 report when your customers start asking for it, and that timing depends entirely on who you’re selling to.
If you’re selling into healthcare, fintech, or government, your buyers handle super sensitive data and are heavily regulated themselves. They’ll definitely ask for SOC 2 (and often HIPAA or other frameworks too) from day one. Doesn’t matter if you’re pre-seed or Series C. You have to clear their vendor security review, and SOC 2 is usually a non-negotiable.
Most enterprise tech companies will expect SOC 2, too. Procurement, IT, and eng teams want to see it before signing.
Plus, discerning mid-market companies (even other startups) see a SOC 2 report as a sign that you’re taking security seriously.
So, if you want to sell to any of these businesses, you’ll need it. Once you’ve decided you need SOC 2, there’s one more choice to make: which of the two report types to pursue.
SOC 2 Type I or Type II: which should you get?
There are two kinds of SOC 2 reports you can get: Type I and Type II.
A SOC 2 Type I report states that you have the right internal controls in place (i.e., they satisfy the Trust Services Criteria) at the time of an audit.
For startups hoping to sell to enterprise customers and pursuing SOC 2 compliance for the first time, SOC 2 Type I is a good way to prepare.
Per one CISO’s LinkedIn comment:
“A SOC 2 Type I is a very reasonable ‘first certification’ for startups. It requires them to start thinking about security and compliance, in a more rigorous way than most have done before. Building a policy set that addresses all of the necessary SOC 2 domains is not the difficult part...figuring out how to secure the organization is, which requires addressing all of the areas required for SOC 2.”
Showing a prospect you’ve earned a Type I report can also be enough to keep an enterprise deal moving (they can see you’re on your way to Type II).
One Redditor points out, “Type I is cheaper and faster than Type II. Most buyers will accept it while you work toward Type II, which requires a 3-12 month monitoring period.”
A SOC 2 Type II report states that you have the right internal controls in place (i.e., they satisfy the Trust Services Criteria) and you’re actively using those controls for a period of time. You choose how long that time period is. Typically, it’s in increments of three months (3 months, 6 months, 9 months, a year).
What are SOC 2 training requirements?
Technically, SOC 2 has no training requirement. Search the Trust Services Criteria, and you won’t find one.
But training is effectively mandatory, because it’s how you satisfy several of the Common Criteria (CC) in the Security category:
CC1.4
CC1.4 requires that you attract, develop, and retain people competent to carry out their security responsibilities.
By now, employees know full well they shouldn’t reuse passwords, but spammy emails and texts are getting harder to identify with AI and deepfakes in the picture.
Gartner predicts 40% of social engineering attacks will target executives and the broader workforce by 2028. Keeping your team competent against threats like these is a moving target, which is why one-and-done training doesn’t cut it.
CC1.5
CC1.5 requires that you hold those people accountable for those responsibilities.
In other words, it’s not enough to offer training. You have to show that specific employees completed it, and that there are real consequences when they don’t.
CC2.2
CC2.2 requires that entities “internally communicate information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.”
A control only works if the person following it understands it. Access reviews fail when admins don’t grasp least privilege, incident response plans are useless if the on-call engineer can’t find them, etc.
A comprehensive security awareness training program – that is uniquely tailored to your organization’s policies – with completion records is one of the primary things auditors expect you to have and produce.
And remember: For a Type II report, auditors need proof that training continued throughout the entire monitoring period. Every new hire was trained when they joined, and everyone assigned new training during the 3- to 12-month period of your audit completed it on schedule.
Why is SOC 2 compliance training so hard?
We’ve already given some hints, but here are four areas where founders struggle with SOC 2 training requirements on the DIY path:
1. You’re not an expert
Startups often don't know what their training even needs to cover. Figuring out the right topics, mapping them to your actual policies, and keeping it all current is a lot of work, and it’s usually not a core expertise for a startup team member.
Unless, maybe, you’re operating in a more regulated space and have a GRC person on your team. Even then, it’s going to be a boatload of work for them to create, edit, publish, and track the content (more on that last piece in #4).
2. You have to buy another tool
A new LMS isn’t cheap, and it takes a while to implement. Worst of all, it’s not user-friendly. Everyone at a startup is busy, and now you’re asking them to:
- Create a new login (that they won’t use again until next year)
- Learn how to use the LMS (not rocket science, but still)
- Sit through hours of training (that can be pretty boring)
One Redditor at a 150-person B2B startup complained about how they’re only at 20% compliance with three weeks left in their SOC 2 audit:
“Our soc 2 auditor keeps asking for documentation proving everyone completed security awareness training. leadership asking why HR cant get this done. standard lms setup. hour long video courses. sent slack reminders. mentioned in all hands.
the format just doesn’t work for how remote teams actually operate. nobody has an uninterrupted hour. they live in slack and zoom. opening an lms tab and watching compliance videos feels like assigning homework.”
To get people to comply, you need to make training short, engaging, and accessible (i.e., deliver it in a tool that they already use).
3. Off-the-shelf training isn’t tailored to your security policies
Yes, Vanta and Drata offer security and awareness training. But those are generic courses that don’t necessarily map to your specific security controls.
Which means you’re still going to come up with your own customized training. That costs money if you work with a consultant. And if you decide to go the route of Mr. Claude, you open yourself up to risk.
An auditor may not find your courses acceptable, and you will have gone through the whole auditing process only to have to fix what’s wrong and go through it again (more time and money).
4. Tracking is tough
To pass an audit, you can’t just say you trained your team, you have to prove it. And auditors are picky.
The evidence I would look for would be:
1. Active employee listing (always include where this was generated from, it should be the HR system).
2. Sample of employees showing when they completed it and what they completed. This should also be from the LMS system.
3. Timing configuration: if your training system is set up on a frequency timer, employees have xx days to complete, then managers are notified, then closed after xy days. I have seen certain processes and LMS statements set up this way. I don’t typically request this evidence, but for a first-time review of the process and setting it up from the internal side, this helps drive a higher completion %.
Unless you’re able to easily cross-reference HR and LMS data and your LMS has built-in tracking, you’re looking at some serious spreadsheet wrangling.
AI-powered training platforms can help you get SOC 2 compliant faster
If you’re starting to sweat at the thought of drafting security and compliance training from scratch or paying tens of thousands of dollars for a firm to do it for you, consider using an AI-powered tool.
It already has the security background you don’t, and you can feed it your organization’s policies so the training it produces is fully customized to your needs.
Some platforms, like Herd, help you overcome all the other challenges that DIY SOC 2 training presents, too:
- Delivering training in bite-sized chunks over Slack, so it doesn’t feel overwhelming.
- Automatically recording completions with a timestamp, so you don’t have to juggle spreadsheets.
- Reminding employees to complete their assigned training so you don’t have to bug them yourself.
- Re-running training periodically, so you don’t have to remember to set up annual training or deploy new training when a policy changes.
SOC 2-ready in a week with Herd
Outfox Health, a healthcare company, used Herd to spin up customized SOC 2 training. Within five minutes, Herd was ingesting information about Outfox’s business, policies, and users, correlating it to the most up-to-date SOC 2 standards, and sending curated training programs to every employee on Slack.
They got to a 100% training completion rate within a week.
Per Outfox’s CEO, Beth Ann Lopez:
“We were flooded with options in the training space. Herd was the only one that provided time-to-value and a clear win within minutes. Seeing how fast the engine could create tailored trainings to our organization, plus save me personally over 20-30 hours of management and administration time, we were blown away by the results.”
All her team had to do was hand the records to their auditors.
Outfox successfully completed its first SOC 2 audit, and they’re still using Herd to stay compliant. Every year, the tool automatically sends out new training, and whenever anyone joins the company, they have a SOC 2 training ready and waiting for them to complete in Slack.
SOC 2 training doesn’t have to be a drag
Yes, you’ll have to create your policies first, and yes, Herd only handles the training piece of the SOC 2 puzzle. But for startups on the DIY path, Herd is a way to dramatically cut your time to SOC 2 audit readiness and to stay compliant over time.
Plus, you can use Herd to design training for HIPAA, ISO 27001, and other frameworks you might need to comply with in the future.
Don’t let training be the thing standing between you and your next enterprise deal. Get started with Herd →




