Even with an external audit - think of how many projects and repositories and servers and libraries and legacy systems Apple, a 50-year-old company with 166,000 employees, could have.
Then think about how much inspection is involved in a $50,000 audit. I doubt you get more than one inspector working full time for a year. In which case they've got 45 seconds of to audit each employee's entire work output. And places like EY will bill some people out at $700/hour, so it could be an order of magnitude less than that.
So this isn't some fine-toothed-comb forensic investigation or adversarial penetration test.
In practice, if you're careful about how you do your Type 1, the Type 2 is almost as trivial. Your HR/bizops practice is much more likely to screw up and cause exceptions than anything you do in IT or engineering.
For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.
As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.
https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...