You Bought Vanta or Drata. Do You Still Need a Consultant?
Short answer: for your first audit, probably yes. After that, often no. Vanta and Drata are genuinely good at what they were built for, which is continuous monitoring of controls that have an API behind them. But a SOC 2 audit is more than monitored controls, and the parts the platform doesn't touch (your risk assessment, your scoping decisions, your system description, the conversation with the auditor) are exactly the parts first-timers get wrong. If you have someone in-house who has owned a SOC 2 program end to end, skip the consultant. Most companies buying their first compliance platform don't.
Nobody neutral answers this question. The platforms say the software is enough. Consultants say you'll fail without them. Both are selling something, and so are we, so we'll try to earn credibility the only way that works: by conceding real ground first.
Key takeaways
- Compliance automation won the evidence-collection argument. Anything with an API is monitored better by a connector than by a human, and a consultant who tells you to skip the platform is billing you for work the software does better.
- Five things are still human-authored: the risk assessment, Trust Services Criteria scoping, the system description, exception handling, and answering the auditor in walkthroughs.
- First-audit preparation still runs 300 to 500 hours even with a platform. Tooling moves those hours around more than it removes them.
- Skip the consultant if someone in-house has personally owned a SOC 2 program, your scope is simple, engineering has slack to absorb remediation, and a slipped quarter costs you nothing.
- After year one the calculus changes. A clean first Type II is a template for year two, and scaling outside help down is the correct outcome rather than a churn problem.
First, the ground we'll happily concede
Compliance automation won the evidence-collection argument years ago, and it wasn't close.
Anything with an API, the platform monitors better than a human ever will. Connect it to AWS, GitHub, Okta, your MDM, and your HR system, and it checks continuously that MFA is enforced, laptops are encrypted, terminated employees lose access, infrastructure changes go through pull requests, and backups actually ran. The old way was a consultant emailing you a spreadsheet and asking for screenshots every quarter. A connector checking hourly beats a human checking quarterly on every axis: coverage, freshness, and cost.
The platforms also do real work beyond monitoring. Policy templates get you from zero to a reviewable draft fast. Employee onboarding flows handle security training attestations and policy acknowledgments without anyone chasing signatures. The auditor portal means your audit firm pulls evidence directly instead of trading Dropbox links.
We recommend one of these platforms in nearly every SOC 2 engagement we run. If a consultant tells you to skip the platform so they can collect evidence by hand, that's a consultant billing you for work software does better. Walk away.
So the question isn't platform versus consultant. It's what's left over once the platform has done its job.
What the dashboard does not do
Five things, and every one of them is human-authored.
1. Your risk assessment
SOC 2's Common Criteria (CC3 series) require an actual risk assessment: identify the risks to your commitments, rate them, and tie controls to them. The platform ships a risk register module, which is a place to put a risk assessment, not a risk assessment. Auditors read these documents and ask questions from them in walkthroughs. A templated register that lists generic risks you don't have, and misses the concentration risk in your one production database or your dependency on a single payment processor, is an easy way to fail an interview you should have passed.
2. Scoping your Trust Services Criteria
Security is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional, and which ones you include is a business decision driven by what your customer contracts promise, not a software setting. Toggle on Availability without thinking and you've committed to capacity monitoring, disaster recovery testing, and backup restoration evidence for the entire observation window. The platform will cheerfully monitor whichever criteria you enable. It will not tell you whether enabling them was wise, and descoping mid-window is an awkward conversation with your auditor.
3. Your system description
Section 3 of a SOC 2 report is a narrative: what your service does, where its boundaries sit, which components are in scope, which subservice organizations (your cloud provider, your payment processor) you rely on, and what controls your customers are expected to operate on their end. It's entirely human-authored, it's one of the most common sources of audit exceptions and revision cycles we see, and no automation writes it. Someone who has drafted thirty of them will produce in a week what a first-timer produces in a month of back-and-forth with the audit firm.
4. Exception handling
Something will fail during your observation window. It always does. An engineer quits and offboarding takes six days against your three-day policy; an access review slips a quarter. What separates a clean report from an ugly one is how the deviation gets written up: what happened, the root cause, the management response, and whether the auditor treats it as an exception with a note or a finding that spooks your customers' security reviewers. Knowing what a given audit firm will accept, and when to push back on a proposed exception, comes from having sat through a lot of audits. The dashboard has no opinion.
5. Answering the auditor
Walkthroughs, sampling requests, follow-up questions about why a control operated the way it did. The platform gives the auditor read access to your evidence. It does not sit in the interviews, and the interviews are where inexperienced teams volunteer problems they didn't need to volunteer.
The hours nobody puts on the pricing page
Even with a platform doing the collection, first-audit preparation typically runs 300 to 500 hours of human work. That range matches what we see across first-time SOC 2 clients, and tooling moves hours around more than it removes them.
Where do they go? The platform tells you, on day one, that MFA isn't enforced in three of your SaaS tools and a quarter of your repos lack branch protection. Surfacing the gap took seconds; fixing it is engineering time, and handling the two staff engineers who push back on the new deploy controls is management time. Policies need tailoring so they describe what your company actually does, because an auditor comparing a boilerplate policy against observed practice will find the daylight. Then the risk assessment, the system description, vendor security reviews, access review cleanup, and a dry run before the window opens.
Do the arithmetic. At a loaded cost of $100 an hour, 300 to 500 hours is $30,000 to $50,000 of internal time, mostly senior engineering time, which has an opportunity cost the invoice never shows. You were always going to pay for audit expertise; the only open question is the currency. Pay in your engineers' hours while they learn on the job, or pay fees to someone who has done it before. Sometimes the first answer is right. Which brings us to the case against hiring us.
The honest case for skipping the consultant
Plenty of companies get through a first SOC 2 with a platform and no outside help, and if the following describes you, we'd tell you to keep your money:
- Someone in-house has owned a SOC 2 program before. Not "worked at a company that had SOC 2," but personally scoped it, wrote the system description, and sat across from the auditor.
- Your scope is simple: one framework, Security criterion only, one product on one cloud provider, no subservice complexity beyond the usual suspects.
- Engineering has slack to absorb remediation without blowing up the roadmap, and your timeline can flex if the observation window needs to move.
- You're starting with a Type I (a point-in-time report) rather than jumping straight to a Type II, so the cost of a misstep is a redo, not a failed twelve-month window.
There's also a fair critique of our side of the market to weigh: a consultant is a coordination layer, and if your in-house lead is strong, that layer is overhead. Some firms pad engagements with evidence-collection hours the platform already covers, or park a junior on your account after the partner sold the deal. The platforms' own onboarding content and auditor networks have improved enough that a diligent, simple-scope team can reasonably self-serve.
If two or more of those bullets don't describe you, though, the math flips fast. Multi-framework scope (SOC 2 plus ISO 27001 or HIPAA), a customer contract with a hard deadline, or nobody in-house who has done this before: that's when the 300 to 500 hours land on people with day jobs, and the expensive failure mode isn't the consultant's fee, it's a blown observation window and a renewal conversation with your biggest customer that starts with an apology.
If you do buy help, buy the right kind
The consultant worth paying for in 2026 does the human-judgment work from the list above and almost nothing else. Scoping and TSC selection before you sign the audit engagement letter. The risk assessment, written from interviews with your team rather than a template. The system description, drafted and defended through the audit firm's review. Exception strategy when something breaks mid-window. A seat next to you in the walkthroughs.
What that shouldn't look like is a big-firm readiness assessment that re-documents what your dashboard already knows, at 40 hours of billable discovery. The model we think fits the platform era is fractional and ongoing: a compliance as a service arrangement where an experienced practitioner runs the program on top of your platform, or a vCISO if you need someone who also owns security strategy beyond the audit. The platform is the system of record; the human is the judgment. You need much less of the human than you did in 2019, which is precisely why paying for the right hours matters more.
One more honest note: after year one, the calculus changes. A clean first Type II with a documented program is a template for year two. Many of our clients scale us down significantly after the first cycle, and that's the correct outcome, not a churn problem.
A quick decision test
Ask these four questions. If any answer is no, budget for help; if all four are yes, self-serve with confidence.
1. Can someone on staff write the system description this month without seeing an example first?
2. Has anyone in-house negotiated an audit exception before?
3. Can engineering absorb several hundred hours of remediation and evidence work this quarter without missing commitments?
4. If the audit slips a quarter, does nothing bad happen to a sales pipeline or a contract?
That's the whole decision. The platform is almost certainly worth buying either way.
Frequently asked questions
What do the platform, the auditor, and a consultant cost in total?
As of August 2026, the contracts we review for a first SOC 2 Type II at a typical 20-to-100-person company usually land around $10,000 to $30,000 a year for the platform (framework count and headcount drive the spread), $15,000 to $40,000 for the audit firm, and $15,000 to $50,000 for consulting help depending on how much of the program you outsource. Call it roughly $40,000 to $100,000 all-in for year one with all three, and meaningfully less in year two once the program is built. That band is narrower than the $30,000 to $150,000 from the soc2auditors.org 171-firm dataset our cost breakdown uses, and the difference is the population: this is what we personally see in contracts at 20-to-100-person companies, so it excludes both the sub-scale corner cutters and the enterprise tail. Our own observation, not a survey; where the two disagree at the edges, trust the survey. One inconsistency of our own worth naming rather than hiding: the audit-firm figure above is drawn from contracts we review, while our auditor selection guide states a higher first-year Type II range drawn from what boutique and regional CPA firms quote. Both are our own observations, of populations we have not reconciled into a single number, so treat either as a planning band rather than a price. Skipping the consultant saves the middle line but shifts those hours onto your team, so price your engineers' time into the comparison honestly.
Can't Vanta's or Drata's own services team do this instead of a consultant?
Partially. Both vendors offer implementation support and maintain partner networks, and their customer success teams are genuinely good at configuring the platform, which is most of what a simple-scope company needs. But their job is platform adoption and renewal, not your audit outcome: they generally won't author your risk assessment or system description, they won't negotiate exceptions with your audit firm, and they won't sit in your walkthroughs. For a single-framework, Security-only scope with a capable internal owner, vendor onboarding plus a communicative auditor is often enough. For multi-framework scope or a hard deadline, it isn't.
We used a consultant for year one. Do we still need them for year two?
Usually not at the same level, and a good one will say so unprompted. Year two is mostly operating the program: keeping monitoring green, running the access reviews, refreshing the risk assessment, and updating the system description for whatever changed. Many clients drop from a build engagement to a few hours a month of advisory, and re-expand only when scope grows (a new framework, an acquisition, a major architecture change). If your consultant proposes the same fee for year two as year one with nothing new in scope, ask them to walk you through exactly which hours do what.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.