How a 20-Person SaaS Company Got SOC 2 Ready in 90 Days with Outsourced IT
Ninety days after deciding to outsource the work, a 20-person SaaS company had every SOC 2 Security control implemented, evidence collecting automatically, and an auditor scheduled. The founders wrote none of the policies and configured none of the tools. This post walks through how that happened, using a composite client drawn from ScaleIt engagements. The sequence is the same for a 5-person team or a 120-person one; only the scope changes.
The starting point will look familiar. The company had grown fast on out-of-the-box settings: MFA available but not enforced, access granted in Slack threads, offboarding done from memory, no written policies, laptops managed by whoever owned them. Then a six-figure enterprise deal stalled on a security review, and SOC 2 stopped being a someday project.
The Decision: Outsource the Program, Keep the Deal Moving
The company weighed hiring for the work against handing it to a managed IT provider. In-house meant recruiting for a security-and-compliance skill set the company had never hired for, on a deal timeline measured in weeks. Outsourcing meant a team that had run the sequence before, starting inside the same month. They chose the second path, and the engagement was scoped to one outcome: controls implemented and evidence flowing in 90 days, with the audit window starting immediately after.
Days 1 to 15: Scope and Gap Assessment
The first two weeks produced two artifacts:
- A scope decision: the first report would cover the Security criteria only, the auditor-mandatory category, matching what the stalled deal's security review asked for
- A gap assessment mapping the expected controls against what the company actually did, built from read-level access to the identity provider, cloud console, and billing records
The assessment surfaced the standard list: unenforced MFA, a departed contractor with live credentials, no access-approval records, unmanaged laptops, and policy templates downloaded a year earlier and never operationalized. None of it was exotic. Every item had a known fix and a place in the sequence.
Days 15 to 60: Closing the Gaps
The middle six weeks were ordinary IT work, sequenced by audit weight rather than convenience:
- Access consolidated behind the identity provider, with roles replacing one-off grants so permissions follow the job instead of accumulating per person
- MFA enforced across the company, with enrollment tracked and stragglers closed out individually
- Offboarding rebuilt as a checklist ending in a verification pass, then run retroactively against every past departure
- Device management deployed to every laptop: disk encryption, screen lock, and patching under policy instead of personal preference
- Policies written to describe what the company now actually does, each with an owner and a review date
The founders' total time commitment during this stretch was a weekly review call and a handful of approval decisions. The configure-for-scale principle did real work here: roles, groups, and access policies were built for the company the client plans to become, so the compliance push doubled as the identity cleanup the company would have needed anyway.
Days 60 to 90: Evidence on Autopilot and Audit Prep
The final month connected a compliance automation platform to the cloud provider, identity provider, code repository, and device management tool. From that point evidence collected continuously, and drift showed up as a dashboard flag to fix rather than an audit finding to explain. The engagement closed out with auditor selection, a readiness review against the Trust Services Criteria, and a decision on the report path: a Type I report early to unblock the waiting deal, with the Type II observation window running behind it.
Day 90 was not a completed audit. It was every control operating, every piece of evidence filing itself, and an auditor booked. The audit itself runs on the calendar the report type dictates; the 90 days is what determines whether that calendar starts now or after months of internal churn.
What the Company Gained
- The stalled enterprise deal moved forward on the strength of the Type I report and a documented program behind it
- Founder and engineering time stayed on the product through the entire push
- The IT baseline most companies wish they had: enforced MFA, role-based access, verified offboarding, managed devices
- An annual renewal that is maintenance rather than a second project, because the controls are how the company now operates
Are you facing a security questionnaire with a deal behind it? ScaleIt runs this sequence as part of managed IT, from gap assessment through the audit. Book a free call and we will map your 90 days.
A composite client based on ScaleIt engagements. Cross-referenced against the AICPA Trust Services Criteria and Vanta's SOC 2 documentation on 2026-09-03.