Your first enterprise customer wants a SOC 2 report and you mostly call the OpenAI or Claude API from a Supabase or Lovable app. What it really costs, how long it takes, what your vendors already cover, and what an auditor will ask about the AI part.
I read security the way an attacker reads it: follow the incentives, find where it breaks. And on SOC 2, the incentives are loud. Almost every cost figure you'll find online is published by a company that sells audits, compliance software, pen tests or consulting. None of them is lying, exactly, but each one frames the problem so that its product is the answer. So in this guide I label every number with who published it.
The other thing none of the top results does is write for the startup most of you actually are in 2026: a small team that doesn't train models, calls the OpenAI or Claude API, and runs on Supabase, Vercel or Lovable. That changes what SOC 2 means for you more than any other factor. Everything here comes from the vendors' own trust and docs pages and from CPA firms' published guidance, read on 27 September 2026. For full transparency: aliteq itself runs on Supabase and Cloudflare, was built with AI coding tools, and has no SOC 2 report. I'm not selling you one.
Do you actually need SOC 2?
No law requires it. SOC 2 is a voluntary attestation under the AICPA's Trust Services Criteria, so the only reason to get one is that a customer asks. When one does, find out what they actually need before you spend anything: a finished report, a filled-in security questionnaire, or a promise with a date.
That last point comes up again and again from founders on Hacker News. In a 2026 thread from a solo founder, the consistent advice was not to start an audit speculatively. Some buyers accept your security policy and a completed questionnaire for now, and some "we need SOC 2" requests turn out to be a polite no.
The pressure is real, though. In A-LIGN's 2026 benchmark, a survey of 1,043 companies by an audit firm, 80% of companies using AI said customers now ask them risk questions about it. If you sell an AI feature to businesses, the questionnaire is coming whether or not you pursue the report.
What SOC 2 checks, in one minute
A SOC 2 report is a CPA firm's opinion on your controls, measured against up to five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security is the one every report must include. A Type 1 report checks that your controls are designed properly on a single date. A Type 2 report checks they actually worked over a period of months.
There is no AI rulebook inside SOC 2 yet. Schellman, one of the larger audit firms, notes that the AICPA hasn't published concrete AI requirements. What changed is how auditors examine you. Aprio, another CPA firm, frames it by your role: a company that only calls a model through an API is a "user" of AI, and the auditor scales expectations to that. That's good news. You don't have to prove anything about how GPT or Claude were trained.
What it costs in the first year
For a 5–50 person company, plan on four lines: the audit fee, a compliance platform, a pen test, and your own team's time. Compliance vendors' own estimates for the whole first year range from about $20,000 to $80,000. Drata, which sells a platform, estimates about $28,000 for a 25-person startup.
First-year SOC 2 budget, line by line. Most published ranges come from companies that sell audits or compliance software. · aliteq research
Line by line, from the sources I could verify:
The audit fee.SOC2Auditors.org, an ad-supported directory of audit firms, puts a specialist CPA firm's Type 2 at $15,500–$50,000 and a Type 1 at $10,000–$35,000. Full-service firms run $30,000–$80,000 for a Type 2, and the Big Four $65,000–$200,000. For a 1–10 person SaaS with simple systems, it suggests budgeting $7,000–$10,000 for a Type 2.
The compliance platform. Vanta, Drata and their rivals don't publish prices. Vendr's buyer data for Vanta shows $12,000–$28,000 a year for companies with 1–50 employees, and a median of $20,000 across 373 purchases.
The pen test. SOC 2 does not require one, as Drata's own guide says plainly, but most auditors expect some form of security testing. A typical small-scope test runs about $5,000–$15,000; a thorough one $15,000–$30,000 or more.
Your time. SecureLeap, a consultancy, estimates 40–150 internal hours when a platform does the busywork. Konfirmity, which sells managed compliance, estimates 550–600 hours if you manage it yourself. Both are sellers, so treat these as rough.
Founders on Hacker News tell the same story: one described about $30,000 and 100 hours of work over six months back in 2020, and another put a first audit at $15,000–$20,000 in 2026. The repeated lesson is that the auditor's fee is rarely the expensive part. The platform and the hours are.
Build your own number here. Every range in the estimator is the sourced range above; the only input that's yours is what an hour of your team costs.
SOC 2 cost + timeline estimator
Year one
$34.9k–$102k
Year two and later: roughly 40–70% of year one (vendor-reported).
Time to report
9–15 months
Includes the 6-month window. There is no AICPA minimum; 3 months is the practical floor.
Audit fee
specialist CPA, Type 2
$15.5k–$50k
Compliance platform
Vanta/Drata-class, per year
$12k–$28k
Pen test
basic
$5k–$15k
Readiness assessment
skipped
—
Stack upgrades
none selected
—
Your team's time
40–150 h × $60/h
$2.4k–$9k
Ranges from SOC2Auditors.org (directory), Vendr (buyer data), Drata, The Pun Group (CPA firm), Fractional CISO, SecureLeap and Cherry Bekaert (CPA firm); stack prices from Supabase, Vercel and Lovable pricing pages. Checked 27 Sep 2026. Most are published by companies that sell audits or compliance software. An estimate, not a quote.
How long it takes
A Type 1 report takes about three to six months from the day you start. A first Type 2 takes six to twelve months or more, because its observation window has to actually pass on the calendar. The AICPA sets no minimum window; three months is the shortest auditors typically accept, and most reports cover twelve.
Phase by phase, per Cherry Bekaert (CPA firm). The window is the part you can't compress. · aliteq research
Cherry Bekaert, a CPA firm, breaks it down: one to two months of readiness, one to six months fixing policies and gaps, a few weeks to two months of Type 1 fieldwork or a three- to twelve-month Type 2 window, then about three to four weeks to issue the report. In CBIZ's 2024 benchmark of 193 SOC 1 and SOC 2 reports, the average report landed 69.9 days after the end of the audit period.
My advice if a deal is waiting: start with a Type 1, tell the buyer the Type 2 window has begun, and give them a date.
What your AI stack already covers, and what it doesn't
Your vendors' SOC 2 reports cover their controls, not yours. In audit terms they are "subservice organizations": your report usually carves them out and instead tests how you monitor them. So their reports are evidence you collect and review, and some of them sit behind a paid plan.
Supabase's docs say it plainly: "Customers wishing to also be SOC 2 compliant need to go through their own SOC 2 audit, verifying that security controls are met on the customer's side." Here is what each vendor publishes on its own pages:
Read on each vendor's own trust, docs and pricing pages, 27 September 2026. · aliteq research
Your stack's evidence, in full
SOC 2
OpenAI API
Type 2 (Security, Availability, Confidentiality, Privacy)
Anthropic API
Type 1 and Type 2, 2026 bridge letter
Supabase
Type 2, assessed annually
Vercel
Type 2 (Security, Confidentiality, Availability)
Lovable
Type I (2026) and Type II listed, bridge letter
How you get the report
OpenAI API
Request on trust.openai.com
Anthropic API
Request form on trust.anthropic.com
Supabase
Dashboard download, Team plan (from $599/mo) or Enterprise
Vercel
Trust portal; security collateral on Pro ($20/mo) and Enterprise
Lovable
On request via the Lovable Trust Center
DPA
OpenAI API
Incorporated into the services agreement
Anthropic API
Incorporated into the commercial terms
Supabase
Part of the terms; acceptance counts as signing the SCCs
Vercel
Published DPA is written for Enterprise; ask about Pro
Lovable
Included on Business and Enterprise plans
Trains on your data?
OpenAI API
API: no, unless you opt in
Anthropic API
Commercial and API: no by default
Supabase
Not a model vendor
Vercel
Not a model vendor
Lovable
Free and Pro: yes unless you opt out (since 9 Sep 2026); Business and Enterprise: excluded by default
HIPAA BAA
OpenAI API
Case by case via baa@openai.com
Anthropic API
Yes, with some features excluded
Supabase
Team or Enterprise plus a paid add-on (price not published)
Vercel
Pro add-on at $350/month
Lovable
None found; terms bar HIPAA data without a separate agreement
OpenAI API
Anthropic API
Supabase
Vercel
Lovable
SOC 2
Type 2 (Security, Availability, Confidentiality, Privacy)
Type 1 and Type 2, 2026 bridge letter
Type 2, assessed annually
Type 2 (Security, Confidentiality, Availability)
Type I (2026) and Type II listed, bridge letter
How you get the report
Request on trust.openai.com
Request form on trust.anthropic.com
Dashboard download, Team plan (from $599/mo) or Enterprise
Trust portal; security collateral on Pro ($20/mo) and Enterprise
On request via the Lovable Trust Center
DPA
Incorporated into the services agreement
Incorporated into the commercial terms
Part of the terms; acceptance counts as signing the SCCs
Published DPA is written for Enterprise; ask about Pro
Included on Business and Enterprise plans
Trains on your data?
API: no, unless you opt in
Commercial and API: no by default
Not a model vendor
Not a model vendor
Free and Pro: yes unless you opt out (since 9 Sep 2026); Business and Enterprise: excluded by default
HIPAA BAA
Case by case via baa@openai.com
Yes, with some features excluded
Team or Enterprise plus a paid add-on (price not published)
Pro add-on at $350/month
None found; terms bar HIPAA data without a separate agreement
Two things in that table catch AI startups out.
The plan tier is a real cost line. To hold the vendor reports your auditor wants to see, you may need to upgrade: Supabase's report only downloads on the Team plan, from $599 a month. Vercel shares its security collateral from the $20 Pro plan, and a HIPAA BAA there is a $350-a-month add-on. The estimator above includes these as optional lines.
Lovable's training default changed this month. Lovable's docs now read: "As of September 9, 2026, customer data from Free and Pro plans may be used to train, develop, and improve Lovable's AI models". Business and Enterprise workspaces are excluded by default, and Free and Pro users can opt out under Account settings, Preferences, AI model training. To be fair to Lovable, this covers your own prompts, code and project files, not the data your app's end users submit, which stays in your project's database. But an enterprise questionnaire will ask whether any vendor trains on your data, and "yes, unless we opted out" is an answer you want to change before it's asked. Opting out only applies going forward. If you build on Lovable, the Lovable security checklist covers the app-side fixes.
When you receive each vendor's report, read its "complementary user entity controls": the controls the vendor assumes you run. CBIZ counted an average of 8.9 per SOC 2 report. Ignoring them is an easy way to earn a finding in your own audit.
What auditors ask about your LLM feature
There are still no AI-specific SOC 2 criteria, but auditors now map your AI feature onto the existing ones. For a startup that only calls an API, expect questions on how you manage the model provider as a vendor, prove it doesn't train on your data, control model changes, log prompts safely, protect API keys, test for prompt injection, and decide what data may go into prompts.
This list is compiled from published auditor guidance (Aprio, Baker Tilly, Linford & Co., Wolf & Co.) and compliance vendors' checklists:
Your LLM provider as a vendor. A vendor risk assessment for OpenAI or Anthropic, their SOC 2 or ISO report on file, and a review of the controls they expect you to run. This is the vendor-management criterion (CC9.2).
Proof they don't train on your data. The signed or incorporated DPA, the provider's training policy, and your retention or zero-data-retention setting where you have one. Both OpenAI and Anthropic offer zero data retention only with their approval.
Change management for model versions. Pin the model version you call, and treat a model swap like a code change: a ticket, a review, a way to roll back. I'd go one step further and put your system prompts under the same review. That part is my advice, not an audit requirement.
Logging, with redaction before anything is written. Auditors expect inference logs with the model version, a redacted or hashed prompt and the outcome, so you can investigate an incident without storing customers' secrets in your logs.
Prompt-injection testing. A documented set of adversarial prompts you run against your feature, with the results and what you changed.
What data may go into prompts. A written rule on which data classes can be sent to a model, and a list of the AI tools your staff use, so nobody pastes customer records into a personal chatbot.
Incident response for bad output. What counts as a severity-one model failure, and who gets paged.
If you train or fine-tune your own models, expect more: dataset lineage and drift monitoring. If you only call an API, those don't apply. Pin and record the model version instead.
Start with a Type 1 if a deal is waiting. It checks your controls on one date, so you can have a report in three to six months, then begin the Type 2 window straight away. Whether a buyer accepts a Type 1 for a first contract is their call, so ask; renewals and regulated buyers tend to insist on the Type 2.
Most reports cover a twelve-month period, and a buyer's own auditors generally want your window to overlap theirs. Thomas Ptacek made a sharp case in Fly.io's essay on SOC 2: the report spreads because your customers' auditors ask them for it, so the right time to get one is when answering each prospect's questions by hand costs more than the audit.
The Delve lesson: a report is only as good as its auditor
In March 2026 an anonymous post alleged that Delve, a fast-growing compliance startup, had produced hundreds of near-identical SOC 2 reports through a small set of audit firms. TechCrunch reported the allegations; Delve disputes them and says final reports are issued by independent licensed auditors, not by Delve. No court has ruled on them.
Weeks later, the AICPA's Journal of Accountancy published guidance telling peer reviewers to watch for firms relying too heavily on third-party SOC platforms, with identical reports, risk assessments, sample sizes and testing. It doesn't name any company.
What that means for you, twice over. When you buy your own audit, a price that looks too good and a promise that looks too fast are both reasons to look closer. And when you review your vendors' reports, check that the auditor is a licensed CPA firm you can look up, and read the report rather than filing it. Exceptions aren't a red flag in themselves: in CBIZ's benchmark, more than half of SOC 1 and SOC 2 reports (54.9%) had at least one.
A realistic plan for a small team
This is the order I'd work in, based on the phases above. It is a plan, not a guarantee.
Ask the buyer exactly what they need: a report, a questionnaire, or a date. Answer the questionnaire now either way.
Fix the basics an auditor looks at first: access control, Row Level Security, keys out of the browser, backups.
Collect your vendors' reports and DPAs, upgrading plans where the report sits behind a tier, and opt out of any vendor training on your data.
Pin model versions, put model and prompt changes through review, and redact prompts before they're logged.
Pick a licensed CPA firm and, if it saves you the hours, a compliance platform. Get quotes; published ranges are only a guide.
Get a Type 1, then start the Type 2 window immediately and give your buyer the date it ends.
Quick answers
Is SOC 2 legally required for an AI startup?
No. SOC 2 is a voluntary attestation. It becomes necessary when a customer asks for it. HIPAA business associate agreements and GDPR data processing agreements, by contrast, are legal requirements when they apply to you.
Do I need SOC 2 if I only use the OpenAI or Claude API?
If your customers ask for it, yes. OpenAI's and Anthropic's reports cover their own controls, not yours. You collect their reports as evidence and get your own report covering your application, access controls and processes.
How much does SOC 2 cost for a small startup?
Compliance vendors estimate about $20,000 to $80,000 for the first year all-in. A specialist firm's Type 2 audit fee alone runs about $15,500 to $50,000, and 1–10 person teams with simple systems may budget $7,000 to $10,000 for the audit. Platforms, pen tests and your team's time are the rest.
How long does SOC 2 take?
About three to six months to a Type 1 report and six to twelve months or more to a first Type 2, because the Type 2 observation window has to pass. There is no official minimum window; three months is the shortest typically accepted.
Does using Supabase, Vercel or Lovable make my app SOC 2 compliant?
No. Their reports cover their platforms. Supabase's docs say customers who want to be SOC 2 compliant need their own audit. You still need your own controls, and you'll need their reports as evidence.
Does SOC 2 have AI-specific requirements?
Not yet. Auditors apply the existing criteria to your AI feature: vendor management for your LLM provider, data handling and training settings, change management for model versions, logging and access to API keys.
Should I get a pen test for SOC 2?
SOC 2 doesn't require one, but most auditors expect some form of security testing, and enterprise buyers often ask for one. A typical small-scope test runs about $5,000 to $15,000.
Next in this section: what an AI feature changes in an enterprise security questionnaire, and how to answer it honestly. Until then, the Security & Compliance hub collects everything so far.
Use this in your own page
Teaching this? Paste the live version into your course, blog or answer. Free, no sign-up; the credit line links back here.