For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.
IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.
Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.
As a German I remember that they were banned from doing certain audits in Germany until earlier this year due to their involvement in the wirecard scandal. So at least my personal believe that their audits are done rigorously is nonexistent.
https://edition.cnn.com/2023/04/03/business/wirecard-ey-ban-...