Blog
•
Compliance
10 Questions to Ask SOC 2 Vendors Before You Sign

There’s no shortage of compliance vendors who come in hot, offering to help you check off compliance boxes to earn a badge. We call that security theater: performative security that sells the promise of checking boxes rather than helping you secure your organization. It works because buyers often judge vendors based on speed, price, or brand recognition. Meanwhile, the one thing that actually matters (security) stays invisible.
The 10 questions below are designed to make security visible as you assess compliance vendors. Ask every compliance vendor the same 10 questions. They’ll help you evaluate on substance rather than marketing claims while also pulling back the curtain on security theater.
1. Does your pentest actually find more without adding noise?
Let’s start here: Pentests include vulnerability scans, but vulnerability scans are not pentests. Scanners like Nessus suggest you may have a weakness in your security, and pentests confirm it. The problem is both can pass an auditor looking for a check in the box. And the ultimate problem is you are the one held accountable when your security is breached and you're "compliant.”
The compliance checkbox doesn't care how the report was generated, so vendors have no real incentive to do better (unless you make them).
Pentesting today spans a spectrum:
An automated scanner dressed up as a pentest, running the same signature checks anyone can run for free
Agentic and AI-assisted testing, which is still emerging but improving fast
Human-led, human-in-the-loop testing, which remains the current gold standard because a person can chain findings together and think like an actual attacker
But the tier isn't really the point. The point is signal quality. Does the test surface real, exploitable vulnerabilities (the kind that would actually hurt you in a breach), or does it bury you in low-severity noise?
Here's why this matters more than most first-time buyers expect: Nearly every serious enterprise prospect will ask to see your actual pentest report during their security review. If what you hand them is thin, generic, or scanner-generated, it can stall or kill a deal that was close to closing, at the exact moment you have the least time to fix it.
So don't take a vendor's word for quality. Ask for proof. A vendor confident in their pentesting should be able to show you something like average findings per audit or noise reduction versus scanner-only testing.
And don't stop at the stat. Ask what happens next:
A vendor confident in their pentest quality will have quick, specific answers to all three. A vendor who gets vague is telling you something between the lines. |
2. Do I get a choice of vetted, independent auditors?
There are two real models here:
You go find and vet a CPA firm yourself, with no help from your compliance platform
Your platform hands you a curated shortlist of firms they've already vetted
A curated shortlist of independent firms is a convenience. The problem is when the "shortlist" given to you is one auditor that shares a name, lineage, or staff with the platform selling you the audit. It’s the same homework being graded by the person who wrote it.
Real choice looks like this: You're offered several genuinely independent, AICPA-listed, reputable firms to pick from. You’re not steered toward one, yet you’re not left to do all the sourcing and vendor management yourself either.
Ultimately, it’s a due-diligence question. Your future customers won't ask whether your auditor technically qualifies as independent. They'll ask if the report is credible enough to trust without redoing the work themselves. If it isn't, the audit just moves the friction to your next sales cycle.
3. Would your team or platform catch errors before they reach the auditor?
Let’s start by talking about who auditors really are. They’re CPAs. And much like you wouldn’t ask a car mechanic to read your bloodwork, it’s unfair to ask your auditor to evaluate the effectiveness of your security. That is a failure the compliance industry owns.
Here's the problem: Auditors sign off on scanner output every day because nothing in a SOC 2 report tells them to look closer. SOC 2 is just an attestation, not a certification against standardized requirements. The real risk is that a prospect's own security team catches it later during their due diligence, and the deal or the relationship ends right there, with no chance to fix it in time.
If true security is your end goal, compliance vendors should be on deck to carefully check what you submit to the auditor. They should have checks in place so that they catch the quality of your submitted evidence. Leaving that up to the auditor is unfair, yet many compliance vendors do just that. And that’s how you wind up in a scenario of having to explain to an enterprise customer why your pentest is just a Nessus scan.
4. Does 100% on the platform mean 100% with the auditor?
Again, this goes back to quality control before your evidence ever reaches your auditor.
There are three concrete failure modes here. First is coverage illusion. Integrations only cover some of your actual footprint (e.g., having MFA enabled only counts tools with native integrations. The rest silently don’t count).
Then, there’s evidence without validation. Some compliance platforms accept any PDF as evidence of a pentest, even if that PDF is a menu from the local Chinese restaurant. That’s why human validation of evidence is key, and it should happen long before an auditor gets involved.
Finally, there’s a third failure mode that's easy to miss: the SLA remediation gap. Most platforms track whether a control exists, not whether a finding from your pentest actually got fixed within its remediation window (critical, high, medium). That means your dashboard can sit at 100% while a critical vulnerability from three months ago is still open, and nobody — not the platform, not the auditor — is watching for it.
This creates an odd incentive: A vendor that tracks and surfaces every individual finding, including the ones still open, will sometimes look worse on paper than one that doesn't bother tracking them at all. That's backwards if your goal is real security. The platform showing you the gaps is doing its job. The one hiding them is just better at looking compliant.
5. Is your vCISO a true security expert who stays with me throughout my entire journey?
The term “vCISO” has become a label that everyone slaps on customer support. But a real vCISO should be a security expert, not a generalized customer support specialist. This is because only a real security expert can help you make informed decisions that help you get compliant and secure. (For example, making tradeoffs when it comes to controls so you’re prioritizing the right ones for your organization.)
Then, there are two timing questions to ask. Does the same person stay with you, or do you have to re-explain the environment each time the ticket changes hands? And how long is the vCISO actually included for? Some vendors throw in a vCISO for the first 30 days, only to offer that same support for thousands of dollars later. And “later” (3-5 months in), during the actual audit period, is when you actually need them.
6. Is your program actually tailored to me and my business?
Here's something most buyers don't know: SOC 2's common criteria trace back to the Committee of Sponsoring Organizations of the Treadway Commission (COSO), a governance framework built for large enterprises after Enron and Sarbanes-Oxley — not for a two-person startup. Somewhere along the way, the AICPA's example control list got treated as gospel across compliance platforms, so founders end up trying to prove board independence for a board that's just them and a co-founder. That's not exactly a tailored program that makes sense for a small start-up.
To be clear, "not tailored" isn't automatically a red flag. Some frameworks, like CIS controls, are broadly applicable by design and don't need much customization to make sense. The problem is specifically enterprise-governance theater getting forced onto a company it was never built for.
Be wary of vendors who offer a “customization wizard” that just toggles one or two controls and then calls itself a “bespoke solution.” Instead, look for assistance with building what your program looks like, based uniquely on your business and its needs.
7. Do you continue monitoring security after the audit?
Before digging into security monitoring, we need to differentiate it from compliance monitoring.
Compliance monitoring means your integrations keep running. That’s always continuous by default across compliance platforms. Security monitoring, on the other hand, is not. It often stops the moment your pentest is complete. And that does nothing to keep you secure after your audit.
Make sure the vendors extend their security tooling beyond the pentest (think MDM, cloud configuration monitoring, etc.). These shouldn’t power down the moment your SOC 2 report is in hand because a security questionnaire six months later asks you if you’re doing this now.
8. How many hours will this take from my team?
Every vendor claims a number, but very few show the math — and the math matters.
For example, if you have to manually configure devices by looking at screen lock, firewall, and disk encryption settings, you’re looking at 20-30 minutes for one laptop. Across an entire fleet, that’s hours for just one control category.
If a vendor quotes a number lower than that manual math, ask why. A legitimately faster number should have a real reason behind it (think MDM automation that removes the manual steps, for example). And when you're comparing numbers across vendors or against published research, make sure you're comparing the same thing. Time sitting in a remediation queue (MTTR) is a very different number from actual hands-on-keyboard time to fix something, and vendors don't always specify which one they mean.
9. Does what’s included in the price change as our company grows?
Many vendors run the classic freemium trap: the basics are free (or bundled) at an early stage, then quietly split into paid line items as you scale. And by the time you notice, you're paying for five things that used to be included.
The right question is this: Do you understand exactly what you're getting today, and how and why that changes as you grow? That's a transparency question, full stop.
Some things legitimately scale with company size, like device count for MDM, repo count for cloud and code security controls, employee count for per-seat security work. Those cost drivers make sense, and a vendor should be able to name them plainly. What shouldn't happen is your vendor unbundling features that were never actually tied to growth and calling it a "growth pricing" change.
For a first-time compliance buyer, this matters more than you might think. You have no baseline for what's normal, so a budgeting surprise 6-12 months in costs trust, right when you need to be able to trust your vendor the most.
10. Is everything you need to get compliant included in the price?
"Compliant" and "sellable" aren't the same finish line. A vendor can be technically right that you don't need a real pentest to check the compliance box and still leave you exposed, because your customers will expect one anyway. Passing the audit and passing your next enterprise security review are two different bars, and many buyers don't find out they're different until that enterprise security review happens.
The quote you get at signup is often just the starting point, not the whole journey. The costs that show up later (retests after remediation, add-on modules, vCISO time once the free onboarding window ends, third-party auditor or pentest fees) usually aren’t part of the original pitch. They're not hidden, exactly. They're just not asked about.
So ask about them. Whatever vendor you're evaluating (Oneleet included), put these in front of them before you sign:
Is the pentest actually included, or just "available" for an extra fee?
Is remediation and the retest after it free, or does every round of fixes reset the meter?
Does the vCISO cover the full journey, or just onboarding?
If something breaks during the audit, do you own the fix — or do you point me to a third-party partner?
A salesperson will always tell you "no one's ever had a problem." That's not a standard; it's a reassurance. These four points are the standard. They help you verify the claim instead of taking a vendor’s word.
Security theater survives and runs rampant because buyers simply don’t know what to ask. Use these 10 questions to pull back the curtain on security theater and let vendors’ answers — not their pitches — decide who earns your signature.
Rachel Bishop is a cybersecurity marketing leader with over 10 years of experience turning technical cybersecurity and IT concepts into compelling, audience-first stories.
Check all other articles




