← Back to blog
SOC 2July 6, 2026

How to Get SOC 2 Without Vanta (Step by Step)

Vanta is optional. Here is what is not. A step-by-step path to a real SOC 2 report without paying $7,000-$20,000 a year for a GRC platform.

Vanta is optional. Here is what is not.

Every SOC 2 guide online assumes you are buying a GRC platform first. But Vanta, Drata, and Sprinto are tools for collecting evidence faster — they are not a legal requirement for the audit itself. An auditor cares whether your controls exist and work, not which software dashboard you used to prove it.

If you are pre-revenue or early stage, skipping the platform and managing the process manually can save $7,000-$20,000 a year without changing the outcome of your audit.

The simple explanation

A SOC 2 audit checks two things: that you have written policies describing how you handle security, and that you actually follow them. A GRC platform automates the second part by connecting to your tools and logging evidence continuously. Without one, you do the same logging manually — spreadsheets, screenshots, and a shared drive instead of a dashboard.

It takes more manual effort. It does not make the audit less valid.

The step-by-step path

1. Write your policies first

Before anything else, you need the core policy set — Access Control Policy, Incident Response Plan, Risk Assessment Policy, Data Backup Policy, and Information Security Policy at minimum. These are the documents the auditor reviews before checking evidence.

2. Decide Type I or Type II

Ask your enterprise client which one they require. Type I is a point-in-time check and faster to complete. Type II requires 3-12 months of evidence and is what most enterprise procurement teams actually want.

3. Set up manual evidence collection

Create a shared folder structure organized by control area. Screenshot access reviews monthly, log incident records as they happen, save onboarding/offboarding checklists, and keep training completion records. Consistency matters more than sophistication here.

4. Run a penetration test

This is a fixed, unavoidable cost regardless of platform — typically $3,500-$7,000. Get quotes from at least two vendors before committing.

5. Choose a CPA audit firm

Look for firms that specifically list SOC 2 audits for startups, not just enterprise clients. Smaller firms often charge less and move faster than the big names GRC platforms recommend by default.

6. Complete background checks and device management

Most auditors expect basic background checks on employees with system access, and some form of device management (even a manual checklist for a small team) covering encryption and screen lock policies.

7. Submit for audit

Once your observation period is complete (for Type II) or your controls are in place (for Type I), the auditor reviews your policies against your evidence and issues the report.

What this means for your startup

Going manual trades convenience for cost savings. For a team of 1-10 people, the evidence collection is manageable without automation — it is a few hours a month, not a full-time job. Once you have closed enough enterprise deals to justify the recurring platform fee, switching to Vanta or Drata later is straightforward, since the underlying controls do not change.

The one step you cannot shortcut

Regardless of platform or no platform, the written policies are non-negotiable. Every auditor requires them before reviewing any evidence, and writing them from scratch — or paying a consultant $5,000-$15,000 to do it — is usually the single biggest bottleneck in the entire process.

AuditPass generates the full policy set for SOC 2, ISO 27001, GDPR, and HIPAA in 60 seconds, with your company details and correct control references already filled in. It replaces step 1 above entirely, whether or not you use a GRC platform for the rest.

Will an auditor accept manually collected evidence?+
Yes. Auditors evaluate whether evidence is complete, consistent, and covers the required observation period — not the tool used to collect it. Spreadsheets and screenshots are accepted as long as they are organized and dated.
How much time does manual evidence collection take per month?+
For a small team, typically 2-5 hours a month once a routine is established — access reviews, incident logging, and backup verification are the main recurring tasks.
Can I switch to a GRC platform later without redoing the audit?+
Yes. Adopting Vanta or Drata after your first audit does not require repeating the process — it simply automates evidence collection going forward for your next audit cycle.
Do I still need a CPA auditor without a GRC platform?+
Yes, always. A SOC 2 report can only be issued by a licensed CPA firm. This requirement exists regardless of which platform, or no platform, you use to manage the process.

Skip the $15,000 policy-writing bottleneck

Generate your full SOC 2 policy set in 60 seconds for $299 — with or without a GRC platform.

Ready to get your policies?

Generate audit-ready compliance documents in 60 seconds for $299.