How a 20-Person SaaS Company Got SOC 2 Ready in 90 Days with Outsourced IT

Ninety days after deciding to outsource the work, a 20-person SaaS company had every SOC 2 Security control implemented, evidence collecting automatically, and an auditor scheduled. The founders wrote none of the policies and configured none of the tools. This post walks through how that happened, using a composite client drawn from ScaleIt engagements. The sequence is the same for a 5-person team or a 120-person one; only the scope changes.

The starting point will look familiar. The company had grown fast on out-of-the-box settings: MFA available but not enforced, access granted in Slack threads, offboarding done from memory, no written policies, laptops managed by whoever owned them. Then a six-figure enterprise deal stalled on a security review, and SOC 2 stopped being a someday project.

The Decision: Outsource the Program, Keep the Deal Moving

The company weighed hiring for the work against handing it to a managed IT provider. In-house meant recruiting for a security-and-compliance skill set the company had never hired for, on a deal timeline measured in weeks. Outsourcing meant a team that had run the sequence before, starting inside the same month. They chose the second path, and the engagement was scoped to one outcome: controls implemented and evidence flowing in 90 days, with the audit window starting immediately after.

Days 1 to 15: Scope and Gap Assessment

The first two weeks produced two artifacts:

The assessment surfaced the standard list: unenforced MFA, a departed contractor with live credentials, no access-approval records, unmanaged laptops, and policy templates downloaded a year earlier and never operationalized. None of it was exotic. Every item had a known fix and a place in the sequence.

Days 15 to 60: Closing the Gaps

The middle six weeks were ordinary IT work, sequenced by audit weight rather than convenience:

The founders' total time commitment during this stretch was a weekly review call and a handful of approval decisions. The configure-for-scale principle did real work here: roles, groups, and access policies were built for the company the client plans to become, so the compliance push doubled as the identity cleanup the company would have needed anyway.

Days 60 to 90: Evidence on Autopilot and Audit Prep

The final month connected a compliance automation platform to the cloud provider, identity provider, code repository, and device management tool. From that point evidence collected continuously, and drift showed up as a dashboard flag to fix rather than an audit finding to explain. The engagement closed out with auditor selection, a readiness review against the Trust Services Criteria, and a decision on the report path: a Type I report early to unblock the waiting deal, with the Type II observation window running behind it.

Day 90 was not a completed audit. It was every control operating, every piece of evidence filing itself, and an auditor booked. The audit itself runs on the calendar the report type dictates; the 90 days is what determines whether that calendar starts now or after months of internal churn.

What the Company Gained

Are you facing a security questionnaire with a deal behind it? ScaleIt runs this sequence as part of managed IT, from gap assessment through the audit. Book a free call and we will map your 90 days.

A composite client based on ScaleIt engagements. Cross-referenced against the AICPA Trust Services Criteria and Vanta's SOC 2 documentation on 2026-09-03.