upvote
> SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1).

Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.

Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.

So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.

reply
A $50k audit is going to be team of 2 CPAs collecting evidence for 2 weeks.
reply
Literally any firm can get a SOC2 Type 1, because there's no lookback to it; the Type 1 is a pinky swear.

In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.

reply
I think companies like Deel showed that SOC2 is more show than anything else.

For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

reply
Delve. Not Deel. Very different startups.
reply
Hasn't Deel been run out of business though?

IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

reply
I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals.

Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.

reply
Right, Delve was the company I was thinking of. Thanks for pointing that out.
reply
Their website is still up, but I have a hunch you can find some other certificate mill that will give you a SOC2 certificate just as easily.
reply
A SOC2's quality entirely depends on how much you trust the auditing firm.

Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.

But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.

reply
These audits for Apple were done by EY.

As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.

https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...

reply
Not really. The more expensive the auditor, the more they'll work with you to craft something that will avoid exceptions. There's no real "rigor" involved in SOC2! The "audit" here is in audit in the accounting sense: "do your records square up?". SOC2 auditors are generally not technical people.
reply
Well you "claiming controls" to an independent CPA auditor. If a licensed CPA helps you lie -- they might lose their license (and can even get to prison), just like a tax preparer CPA can.
reply