SOC 2 Year Two: Who Keeps Your Report Alive?
Somebody has to own your SOC 2 program between audits. By name, with hours on their calendar. If you cannot say who that person is right now, you have already met the problem this article is about.
Year one is a project: a deadline, a consultant, everyone paying attention. Year two is maintenance, and maintenance is where reports die. The second audit almost always moves from a short observation window to a full twelve months, which means a control that quietly lapsed in month three becomes a finding your auditor writes up nine months later. There is nothing you can do about it retroactively. Nothing.
Key takeaways
- Somebody has to own the program between audits, by name, with hours on their calendar. If you cannot say who that is right now, you have already met the problem.
- The second audit typically covers twelve months instead of three or six, so the duration of the test doubles or quadruples exactly as organizational attention drops.
- There is no partial credit and no retroactive fix. A control that lapsed in month three is an exception nine months later, because the auditor tests whether it operated when it was supposed to.
- What lapses is never the technical control. It is the recurring human tasks: access reviews, offboarding inside your SLA, vendor reviews, the annual risk assessment, and change approvals.
- Budget roughly 40 percent of your initial spend every year, plus four to eight hours a week of a named person's attention in steady state. A platform is a smoke detector; it does not put out fires.
The year-two cliff is a math problem
Most companies run their first SOC 2 Type II over a three or six month observation window. That is a sensible choice. It gets a report into customers' hands quickly, and it limits how long you have to hold everything together. It also means your team only had to sustain the controls for a quarter or two, immediately after an intensive readiness push, with help still on call.
The second audit typically covers twelve months. Auditors expect it, and so do the customers reading your report; a company on its second cycle that shows up with another six month window invites an awkward question about what happened during the other six. So the duration of the test doubles or quadruples at exactly the moment your organization's attention drops to a fraction of what it was during readiness.
Here is the part teams consistently miss. A Type II audit tests operating effectiveness across the entire window, and there is no partial credit. Take the example we see most often. Your access review control says user access is reviewed monthly. Your team runs it January through April, skips May (the person who owned it left, and nobody picked it up), then resumes June through December. Eleven out of twelve months. A 92 percent completion rate. Still an exception in your report.
You cannot go back in November and perform May's review, because the evidence would be dated November. The auditor is not testing whether access is currently reviewed; they are testing whether the control operated when it was supposed to, and in May it did not.
One exception will not sink an audit. Auditors expect the occasional miss, and a well-written management response helps. But exceptions accumulate, and every customer who requests your report reads them. A report carrying four or five operating exceptions across access management, change management, and vendor review starts costing you deals in security review. You bought SOC 2 to be a clean answer to "can we trust you." A littered report answers that question worse than some buyers' own questionnaires would.
What actually lapses (it is the boring stuff)
The controls that fail in year two are almost never the technical ones. Encryption stays on because nobody turns it off. MFA stays enforced because the identity provider enforces it. What lapses are the recurring human tasks, the ones that depend on a specific person remembering to do a specific thing on a specific cadence:
- Monthly or quarterly access reviews, especially after the person who ran them changes roles
- Offboarding inside your stated SLA (the contractor whose accounts survived 45 days past their end date)
- Annual vendor security reviews, which pile up in a spreadsheet nobody opens
- The annual risk assessment and policy review dates, which pass silently
- Change tickets that ship without the documented approval your change management policy promises
Notice the pattern. Every one of these worked fine during the first observation window, because during the first window someone was actively watching. The control did not break. The ownership did.
Nobody is triaging the alerts
If you run a compliance automation platform (Vanta, Drata, Secureframe, or similar), you might assume the tooling solves this. It does not, and the way it fails is instructive.
The platform does its job: it monitors your infrastructure continuously and flags drift. An engineer spins up a database without encryption tags, a new hire misses security training, a laptop falls out of MDM compliance. Each event generates an alert. In month two after your report, there are six open alerts. By month five there are forty. By month eight the compliance dashboard is a wall of red that everyone has learned to scroll past, the same way teams learn to ignore a flaky test suite.
Then audit season arrives, and the team discovers that the platform faithfully recorded eleven months of unremediated drift. The monitoring worked perfectly. Nobody owned acting on it. We see some version of this in most second-year engagements that come to us after a rough audit, and the root cause is never the tool. It is that triage was nobody's job.
A platform is a smoke detector. It is very good at detecting smoke. It does not put out fires, and it definitely does not care whether anyone is home to hear it.
What year two actually costs
Budget roughly 40 percent of your initial SOC 2 spend, every year, for as long as you hold the report. That is the planning number we give clients as of August 2026, and in our experience it holds up across company sizes.
Worked example. Say year one all-in was $60,000: readiness consulting, the compliance platform subscription, a penetration test, and the audit fee itself. Year two should be planned at about $24,000. The audit fee recurs (often slightly discounted for a returning client), the platform subscription renews, the annual pen test recurs, and you no longer pay for readiness but you do pay for whatever keeps the program running between audits.
The money is the smaller half of the cost. The larger half is time: in steady state, expect four to eight hours a week of someone's attention for triaging platform alerts, running the recurring reviews, chasing engineers for change ticket hygiene, and collecting evidence as you go rather than in a panicked sprint before fieldwork. That is roughly 10 to 15 percent of a full-time role, rising to a lot more in the six weeks before the audit if evidence was not collected continuously.
Companies that skip this line item do not actually save the money. They convert it into exceptions, into a three-week evidence scramble, and occasionally into a lost enterprise deal, which costs more than every option below combined.
Who keeps it alive: three honest options
Option one: a real internal owner. Not "the CTO will handle it." A named person with 10 to 15 percent of their time formally allocated, a calendar of every recurring control task, authority to chase engineers who let tickets drift, and a standing weekly slot for alert triage. If you have an operations-minded person who wants the responsibility and your environment does not change fast, this works well, and it is the cheapest option. To be plain about it: if this describes you, you do not need to hire us, and we will tell you that on the first call. The failure mode we are warning against is unassigned ownership, not internal ownership.
Option two: fractional security leadership. A vCISO owns the cadence and the judgment calls (which exceptions matter, how to respond to auditor questions, when a control should change because the business changed) while your team still executes the tasks. This fits companies that have hands to do the work but nobody senior enough to direct it, or that need the same person to also handle customer security reviews and roadmap decisions.
Option three: outsource the operation. With compliance as a service, the triage, evidence collection, recurring reviews, and auditor management move to us; your team's involvement drops to approvals and the tasks only an employee can do (nobody can offboard your users for you). This is the right fit when the internal owner keeps not materializing, when you are juggling SOC 2 alongside other frameworks, or when the math favors it: a fraction of the cost of the engineering time you would otherwise burn, and the retainer is typically well inside that 40 percent maintenance budget.
The wrong option is the default one, which is nobody. That choice gets made silently, one skipped access review at a time, and you find out what it cost when you read the draft report.
Frequently asked questions
How much work is SOC 2 year two, really?
Plan on roughly 40 percent of your initial spend annually, plus four to eight hours a week of a named person's time in steady state. The recurring work is alert triage, access reviews, offboarding checks, vendor reviews, change ticket hygiene, and continuous evidence collection. If evidence is collected as you go, audit prep is a few days; if it is not, it is a multi-week scramble that pulls engineers off roadmap work.
When does the next observation window start?
Usually the day after the previous one ends. If your first report covered January through June, the second window typically runs July through the following June, so you are being audited against it right now whether anyone is managing it or not. Auditors and customers both look for continuous coverage; a gap between windows reads as a period when you were not maintaining controls, and sophisticated buyers will ask about it directly. This is exactly why the ownership question cannot wait until you schedule the next audit: the window opened the moment the last one closed.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.