SOC 2 Compliance: Everything Startup Founders Need to Know ✅

Rob Walling· 10 min· 2,076 words· 9 min read· English ·Watch on YouTube

This is the full transcript of SOC 2 Compliance: Everything Startup Founders Need to Know ✅, published on YouTube by Rob Walling. Every paragraph carries the moment it was spoken, so you can click any line to jump straight to that point in the video, search the whole thing for a word, or copy it out.

0:00sock 2 compliance just might be the most boring topic on the planet or I think it's probably at least tied for first but if you're going to go after Enterprise sales it's absolutely something you want to learn about and in this video I'm going to be talking about everything startup Founders need to know about sock2 compliance I'm Rob Walling I've started six companies five of them bootstrapped written four books on entrepreneurship and invested in more than 125 startups you might be wondering what is sock 2 compliance and it's something that you need if you want to move Upstream to higher and higher ticket Enterprise deals these deals can

0:33change your business right it's going to take your growth from growing twenty fifty dollars per account to 500 or 5 000 per account the thing is as you go after these larger customers they have stricter and stricter security policies that you need to adhere to and so today I'm going to dive in to Sock 2 compliance and in order to keep things interesting and on point I've invited a startup founder friend to join me his name is Ruben Gomez of signwell you've probably heard me mention sign about many times on this channel but he received sock 2 compliance last year and so while I have Theory and research and

1:07experience through my portfolio companies he has actually gone through the process himself so he's going to be an invaluable resource for us today there's quite a few steps to get sock to compliance there's two different types of sock 2 compliance you have to hire a CPA to do an audit there's a lot to it and that's why we want to give you an overview of the steps in this video but to get started I asked Reuben why he considered getting sock 2 compliant in the first place we being uh e-signature solution we deal with a lot of really you know private and sensitive data for organizations then early on it was

1:39self-serve but we wanted to reach larger organizations where being sock to compliant is important if you want to close those larger mid-market and Enterprise deals do you think you could get those Enterprise deals without sock 2 like can you implement your own internal policies yeah you you can definitely get some of those there might be some deals that would be really hard hard to get or impossible to get without it but in some cases you can I've talked to some Founders that have not had it and have been working through getting some deals and usually what you have to do is just get a custom contract uh with

2:14an attorney drop that up get them to be okay with it so there's extra work even if you can get some deals without it with it for us it just makes certain deals really easy you know they'll come to you with like these questionnaires and all these all these requirements on the security side sometimes we could just give them our stock to report and it just cuts down on a ton on the work next I asked Reuben about the difference between sock 2 type 1 and type 2. so type 1 is basically just a lot less in depth a lot less controls and requirements and compared to type 2 type

2:482 is will take a lot longer to get it'll be a lot more expensive and there are a lot more controls involved in type two so it's just more in depth and larger organizations sometimes will will want type 2 which one did you choose and why we went with type 2 because we knew that we were going to go mid-market in Enterprise so we wanted to jump to that I do know some people that do type 1 after talking with some Auditors and some people that done it it just seemed like it was easier and better for us to go straight to type 2 and not you know

3:22spend all that time on it obviously cost is a big concern for any startup founder and so I asked Reuben how much he spent getting soft 2 compliant how much did it wind up costing you I would say around 40 000 total I wouldn't say that 40 000 is what it it'll cost everybody that's just including stuff that was maybe unique to us on the technical side right so I'm bundling all that in so it was somewhere around 12 000 for the compliance software that we use that helped cut down on a lot of time called vanta let's say 15 000 for Auditors they try to hack into to your system tell you

4:01all the vulnerabilities for penetration testing included and then you know our time of course and probably the rest was development technical like internal costs paying your team members and such uh we actually outsourced a ton of that work so somebody who was helping us we had a super simple setup on just AWS ec2 like one you know everything bundled into one server it's not part of the requirements but there's some very high level things they don't dictate like technically you need to do these things what they say is like you need to have some sort of redundancy you know worry about availability and all that stuff so

4:41we went about it a certain way not just for sock 2 but also for you know for running our business and scaling yeah I had heard some estimates General like 20 to 30 000 all in and so it makes sense that if you may have had more engineering work to do yeah I could see that pushing it to 40 pretty easily in addition to money time is a huge Factor the amount of effort so I wanted to ask Reuben how long it took sign well to become sock 2 compliant that also I think varies a bit depending on what you have to do for us we have to do more

5:15technical stuff so I would say the non-technical stuff probably about two weeks two and a half weeks or so and that that's pretty fast I think using um it helps to use something like the software that we use that custom there are a lot of different solutions out there nowadays and then on the technical side we probably had about two-ish months of work on top of that so I don't know all together maybe around three months we were all set and the way that it works is that you get to a point of where you can start a monitoring period Then start monitoring you in the first

5:50year instead of going an entire year to where they monitor you you can choose to do just like a short monitoring period like a three month monitoring period and then get your stock to report so it's not like you'll be ready in a month or two months and then you know they they audit you or anything like that you actually have to be ready start your monitoring period and then um you know they'll take like a month and a half to to review everything and give you your report and that's type two right I've heard estimates like type one you could get in a month or two and then type two was

6:24more like three to twelve months or something that was kind of a range I got that off the internet so take it for what it's worth yeah no that sounds that sounds about right type one would be much faster and then you know that's partly due to what's uh required the differences between part type one type two there are also five categories in in type two so uh depending most people just do one category or a lot of people do one category which is security we we did a security availability and confidentiality so all three so a little bit more work there even on the policy

6:55side training for everybody we also bundled in HIPAA HIPAA compliance at the same time because there was so much overlap with those three categories it added a little bit of time but not that much time and of course a question on all of our minds I wanted to find out from Reuben if all of it was worth it now that you're through it and you've spent the money you spent the time time would you say it was worth it yeah for us it has been like I said it's definitely helped us close uh some bigger deals it's also just made it easy for you know for for other deals that we

7:31probably would have gotten but we would have spent a lot more time doing it as we wrapped up the conversation I was curious if Reuben thought that he would have been able to become compliant without a service like vanta so I know that you need to pay a CPA and accountant to do the audit right there's no way around that and you need to create the documentation or pay someone to do it you need to have all the technical work done or pay someone to do it aside from that and I know you used vanta the software this kind of like checklist software that monitors and

8:00does all the stuff that you've said could you have accomplished it without a vanta you know product like Fanta or is it kind of a a necessity or maybe a no-brainer at this point to use a service like that even though you said it was ten or twelve thousand dollars yeah so you definitely could have done it people were doing it before these you know these uh systems existed it's similar to like when gdpr came out we hired somebody that was an expert in that and it was just some very manual thing they had a bunch of spreadsheets they wanted access to systems so I would

8:30imagine it would be the same sort of thing it would just take longer to do it I feel like it's kind of a no-brainer if you have the money to do it that way I'd have a difficult time going without a system like that not just because the the software they put into all your systems they do all the monitoring they spit out reports make it faster and easier on that side of things but they also handle onboarding for employees off-boarding they give you templates for policies they for us they recommended Auditors and Auditors that knew the system they recommended people for penetration testing all that stuff and

9:03you can actually ask them questions when you're when you're in the middle of it like oh I don't have an otter yet but this is what we're doing how do you think we should handle it they'll you know they'll not try to say well you need to talk to an accountant or you know somebody else they'll they'll just answer your questions they're actually helpful yeah and for folks watching you know vanta is the one used but there are a lot of them they're secure frame drata or drata I'm not sure how to pronounce that sprinto audit board and many others awesome thanks Reuben thanks for joining me yeah

9:37of course thanks talk to compliance is obviously a very big topic and it would be very difficult to cover all the nuances in a YouTube video like this that's why at microcomp we've created an article all about sock 2 as well as a checklist that you can reference if you head to microconf.com and click latest in the top navigation you will find that article if sock 2 is something you're thinking about you're probably looking to sell to Enterprise customers which can be hard especially when you're bootstrapped or mostly bootstrapped Enterprise customers will have a lot of questions that you want to be ready for and in order to do that and be prepared

10:13check out this next video to make sure you are ready thanks so much for joining me today I'll see you in the next video

Where these words come from. This is the caption track YouTube holds for this video, written automatically by YouTube rather than by the creator. We read it, tidied the line breaks and laid it out so it can be read. The plain text version is at https://viewrankai.com/tools/youtube-transcript/qfqkEZUumcc.txt.

All rights in this video belong to Rob Walling. Watch it on YouTube. If this is your video and you would rather this page did not exist, tell us and we will remove it.