IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.
As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.
https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...