I wrote an article about this, and I think it's the Correct advice for virtually every startup thinking about SOC2:
https://fly.io/blog/soc2-the-screenshots-will-continue-until...
A few years before that, I wrote an article about what we learned from the consulting practice we ran building SOC2-supporting security programs for startups:
https://www.latacora.com/blog/2020/03/12/soc2-starting-seven...
I've had the experience, many times, of offering this advice in some forum and having someone try to rebut it, claiming that SOC2 is difficult, or that real customers will pick a SOC2 attestation apart with a fine-toothed comb looking for shortcuts you took, or that they built their whole security practice around SOC2. I can go all 12 rounds with someone on any of those points, but I think you can get most of my take from those two posts.