We take a company from nothing to SOC 2 Type 1 audit-ready in 40 days. The standard answer is three to six months. The difference is not that we work harder. It's how many companies have to hand the work to each other before an auditor sees it, and how much of the work in between is being done by hand that shouldn't be.
That's a sales claim, so here is the arithmetic behind it.
The prep is about 160 hours
Scrut puts consultant-led SOC 2 prep at 160 hours minimum: gap assessment, control design, and evidence collection, with a penetration test running alongside. That's four weeks of one person's full attention. The Trust Services Criteria haven't changed much in years, and the controls a first-time company needs are well understood and, for most companies, few.
Four weeks of work does not become six months because the work is hard. It becomes six months because it's split across five companies that each schedule it independently.
Five vendors, five queues
Look at how a fragmented readiness project is staffed. A compliance platform tracks your controls. A consultant runs the gap assessment and tells you what's missing. A separate vendor books your pen test into their queue. Your own engineers gather evidence between sprints. An independent auditor waits at the end for all of it to show up.
Cherry Bekaert puts the readiness phase alone at one to two months from initial engagement to final delivery of a control set when a third party runs it, before fieldwork begins at all. Each handoff inside that window is a place to wait: the consultant flags a gap, you fix it, the platform needs re-checking, the pen test is now three weeks out, and the finding it surfaces reopens a control the consultant already signed off on. Every vendor owns its slice and bills for it. Nobody owns the date you go to market.
The billing follows the same shape. A boutique CPA firm charges $20,000 to $50,000 for the examination itself. Around it sit a readiness or gap assessment at $5,000 to $15,000, a compliance platform at $10,000 to $30,000 a year, a penetration test at $10,000 to $20,000 for an application-and-infrastructure scope, plus security training and device management, each from its own vendor with its own invoice. A 50-to-100-person SaaS company's first-year program lands between $50,000 and $110,000 with a platform doing the evidence work, and $78,000 to $170,000 without one.
The $16,000 to $30,000 you pay an outside consultant to run the prep is a line item you can see. The weeks your launch slips while five vendors get in sync are not. For most startups SOC 2 exists to unblock a specific enterprise deal, so every slipped week is a week that deal sits unsigned.
What the 40 days actually look like
We run readiness as one team on one platform, so the 160 hours schedule against each other instead of against five separate calendars.
Days 1 to 5. Scope and gap assessment: which of the Trust Services Criteria apply to your setup, and where it falls short today. The penetration test kicks off in the same week rather than sitting in another vendor's queue.
Days 5 to 20. Remediation and evidence collection run together, because the people confirming a control is in place are the ones who can put it there. Pen test findings land while there's still time to fix them, and when one does, the person who found it is on the same channel as the person who owns the control. It closes that week instead of bouncing between two companies' ticket queues.
Days 20 to 35. Control design is closed out, findings are retested, and the evidence package is assembled against the criteria the auditor will actually ask about.
Days 35 to 40. The package goes to the independent auditor with nothing waiting on a handoff that hasn't happened yet.
Not everything parallelizes. You can't collect evidence for a control you haven't designed, findings need a retest after remediation, and the auditor still comes last. That sequencing is why it's 40 days and not four weeks. What's gone is the waiting, not the work.
What the automation does, and where it stops
A large share of readiness is clerical. Pulling configuration state out of cloud accounts. Recognizing that one control answers the same question in SOC 2, ISO 27001, and the security questionnaire a prospect sent last week, and mapping it once instead of three times. Drafting a policy that describes the environment you actually run rather than a template with your logo on it. Reading a repository for the findings worth a ticket. Turning a 300-row vendor questionnaire into per-item answers with the evidence already attached.
That work is well matched to agents, and we use them for it. It's also the work that, done by hand between sprints, is what actually eats the calendar in a six-month readiness project.
What matters is where the automation stops, and we built the platform so that it stops in the same place every time.
Every action an agent takes runs inside a Compliance Run and lands as an ordered receipt: what the action was, what it touched, the outcome, and a linked audit event. Reads don't generate receipts; changes do. When an auditor asks how a particular piece of evidence got into the package, the answer is a record with a sequence number, not an archaeology project.
Then there's the gate. A control that rests on human judgment cannot be closed out by an agent. The run holds it as waiting on operator approval, and the run cannot complete until an active, named operator has actually completed that review. If no operator is assigned to your organization, the run blocks rather than proceeding. That's a property of the system, not a policy we ask people to remember. Controls backed by a live automated signal are held to the matching standard: the signal has to report a current satisfying result, not a screenshot someone took six weeks ago.
We're specific about this because the failure mode is easy to picture. A language model will happily generate a plausible access-control policy for a company it has never looked at, and a plausible answer about an environment it hasn't inspected. Assembling, cross-referencing, and drafting from real system state are things it does well. Judging whether your access model is sound, deciding whether a finding is exploitable, or writing your penetration test results are not on that list, and we don't use it for them. The automation is there to delete the clerical hours, not to have an opinion about your security.
Where fragmented readiness goes wrong
The common failure is mundane. A project runs two months late because the penetration test came back late and read like a template, which is what happens when testing is offshored to whoever is cheapest that quarter. A US firm that refuses to offshore its own testing lays the tradeoff out plainly: background checks and certification validation get harder, time-zone gaps stretch the schedule, and the report often isn't delivered by the people who did the work. You save on the quote and pay it back in weeks, and in a document your auditor has to squint at. The handoff is its own exposure, too. A third party was involved in 30% of breaches in Verizon's 2025 DBIR, double the year before.
The worse failure is a clean report. The controls come back marked ready and the company treats the letter as the finish line. A SOC 2 Type 1 report is "as of a point in time", the day the controls were confirmed as designed, and even a Type 2 looks backward over a window that has already closed. The distance between passing the audit and being hard to breach is a well-documented blind spot. IBM puts the average breach at $4.44 million and 241 days to identify and contain. Verizon has attackers leaning harder on vulnerability exploitation, up 34% and now a fifth of breaches, concentrated in zero-days against perimeter devices and VPNs, the tooling an audit never opens. One flaw in a file-transfer tool is how MOVEit reached more than 2,550 organizations and 66 million people in 2023. A report that your controls were fine in March is not a claim about the exploit published in July.
The operators are the part you're actually buying
Everything the automation hands off goes to our own operators. They are US-based Sythe employees. Not a contractor marketplace, not a subcontracted testing shop, and no part of it offshored, including the penetration test.
The same people who collect the evidence and sit across from the auditor run the penetration test and the continuous scanning underneath it. The operator who finds a vulnerability is the one who writes it up, the one who talks to the engineer fixing it, and the one who retests the fix. The operator who approves a control is a named person who has looked at your environment, because the platform won't let the run close otherwise.
This is also what makes the 40 days safe rather than reckless. Parallelism is only available to a team that knows what an auditor will accept before it asks for it. You can start the penetration test in week one and run evidence collection next to remediation because the people doing both have done it before and aren't guessing. A cheaper stack has to serialize, because each vendor has to wait to find out whether the last one got it right. Compressing a schedule with junior people and a template is how you get the two-month overrun described above, not how you avoid it.
It's a flat annual fee with the frameworks and the testing already inside it, so there's no gap-assessment change order and no surprise line item when the auditor asks for one more artifact. We've made the cost version of this argument before. This one is about the calendar.
When 40 days is the wrong number
Some of the fragmentation in the market is deliberate and correct. Your auditor has to be independent, and should be; a team that preps you can't also issue your attestation, and we don't. Specialized tools are good at their one job.
Forty days also assumes a company modern and small enough to lack a decade of legacy sprawl, and one that can give the work real attention while it's happening. Automation helps least exactly where systems are old and undocumented, which is where the clerical work stops being clerical. A 2,000-person shop with on-prem systems isn't getting ready in 40 days, from us or from anyone else, and we'll say so on the first call rather than sell you a date we can't hit. If you've already built the internal muscle and want to own the coordination yourself, the piece-by-piece approach can pencil out.
Count the handoffs
The controls are the same whether you're ready in 40 days or in six months. What differs is how many companies stand between you and the auditor, how much of the work in between is being retyped by hand, and how many times your evidence changes hands before it gets there. Before you sign the next vendor, count those. They predict your date better than anything in the Trust Services Criteria does.
If the deal you're trying to close won't wait six months, talk to us.
Sources: Cost of a SOC 2 audit, component breakdown (Scrut); SOC 2 Type 1 vs. Type 2 and examination timeline (Cherry Bekaert); risks of offshore penetration testing (GDT); limitations of SOC 2 audits in preventing breaches (Advisor Perspectives); Cost of a Data Breach 2025 (IBM); 2025 Data Breach Investigations Report (Verizon); MOVEit / CL0P advisory, CVE-2023-34362 (CISA); MOVEit breach impact tally (Cybersecurity Dive).
