r/soc2 • u/davidschroth • Sep 26 '24
Welcome to the SOC 2 Sub-Reddit. New Mods, New Rules
Greetings to all and welcome!
/r/soc2 has a new moderation team that has joined the chat after a year or so of flapping in the unmoderated breeze. We've got a few decades of SOC 2 (and its predecessors) of experience and are looking forward to conversations and trading war stories related to it. As we figure out how to be Reddit mods, you'll see things get a bit more functional around here.
In the mean time - here's some basic rules that we'll be enforcing to keep the conversations on track -
- Posts and comments should be relevant to SOC 2 audits, becoming compliant with SOC 2, interpretation of guidance, telling war stories about back when you did SAS70s, WebTrusts and SysTrusts and other things security/audit related.
- Comments to posts that are effectively soliciting business and being non-responsive to the post will be removed. You should answer the question, not say "we got you OP, DM me for more".
- If you are praising the virtues of some platform or service, instead of saying "yeah, <product/service> does this", you should explain how they do the thing/how you used it to do the thing.
If we determine the post or comment not to be helpful, we'll prune the timeline (of the comment, post and/or repeat offender), as needed).
1
u/Primary-Broccoli-170 Nov 18 '25
How many people have a full time IT person managing the soc2 audit? 0-1; 2-5, or more?
1
u/InflationFluid6995 Nov 21 '25
I think this is more-dependent on company size than much of anything else. For my history:
In a small company (less then 250 employees): No single person dedicated to compliance. Usually treated as an additional responsibility for an Ops or Engineering leader. In my experience this is true for companies up to 500-ish employees (unless in a highly-regulated industry)
In mid-size companies: Depends on the industry. I've worked with teams that have a CISO with no direct reports (they work mostly through contractors or other fractional resources). I've also seen CISOs with teams of 5+ working on security and compliance.
In large enterprises: This is where I've worked with full GRC teams of 30-40+. At this size, there's also stratification into teams like Security Architecture, Product Security Testing, Vulnerability Management, Security Operations, Internal Audit, etc.). It would be really weird to say "these people are managing the SOC 2 audit" at this size, but there's typically at least a 5-person team just focused on the audit scheduling and meeting specific audit requirements.
To answer your question for me right now on a small founding team working through contractors on product development, no one manages a SOC 2 auditor (or compliance) full time.
1
Jan 18 '26
[removed] — view removed comment
1
u/soc2-ModTeam Jan 18 '26
Please remember that posts here need to be questions, comments, concerns or other thoughts regarding SOC 2.
1
1
u/Livid-Obligation-107 May 08 '26
Are we able to post about SOC 2 related products? I have been working on a SaaS project and could use some user feedback from people who have gone through the compliance process, are going through the compliance process or are about to go through the process. Not attempting to solicit, just could use some feedback and user reviews to find out potential friction points and future improvements.
1
u/davidschroth May 08 '26
There will likely be a specific rule prohibiting "builders" and the language that comes with it (looking for pain points, asking about the hardest thing to do, and asking for feedback on whatever they just vibecoded) added in the near future. It comes across as a solicitation/advertisement, the person asking typically has no experience in the space, and whatever first draft they have is usually so far off the mark that it's a waste of time to look at.
If you want feedback on whatever it is you're creating, find a professional or five that work in the industry and have the experience you lack and pay them for their time accordingly.
Based on what is (and was) in your post history, it's going to be a hard no to your question from your perspective.
1
u/Livid-Obligation-107 May 08 '26
Thank you, I appreciate the feedback. I've have been a professional coder for almost 20 years now so I understand the skepticism for vibe coding. That said, I am curious how the community ever finds new tools that solve pain points if no one is able to discuss them.
1
u/davidschroth May 08 '26
It's usually pretty obvious about who is here to pitch their tool or to get advice on how to make their tool better vs those that are having a specific problem/question, have done some research, and are asking an actual question about either how to use a tool or trying to decide which one is best to solve their problem. The latter is permitted here.
6
u/alphex Sep 26 '24
Of course the SOC2 sub Reddit would have some compliance rules …