Independent reference.Not affiliated with the AICPA or any audit firm.See methodology.
Pillar / Internal vs external (no-platform path)

DIY SOC 2: cost, time, and where it actually breaks down.

DIY does not mean unaudited. The audit firm is non-negotiable. DIY means in-house readiness, in-house evidence collection, in-house policy work. This page sets out what that path costs, where it works, and where it does not.
Section 01

What DIY actually changes

DIY is not a cheaper SOC 2. It is a differently-shaped one. The audit fee is identical either way, because the auditor tests the same controls regardless of how you assembled the evidence, and it is the largest line on both paths. What DIY removes is the platform contract. What it adds is hours.

The same programme, two shapes
Line itemPlatform-ledDIY
Audit firm feeThe dominant line. Not published by any firm.Identical. The auditor does not charge less because you used a spreadsheet, and does not charge more either.
GRC platformA published annual contract, in US dollars, on the vendor's AWS Marketplace listing.Zero. This is the entire cash saving, and it is the only line DIY removes.
Internal timeLower. Evidence collection is automated; the judgement work is not.Materially higher, and concentrated on one senior person. This is what you are trading the platform fee for.
Light advisoryOften unnecessary. The platform's gap analysis covers the scoping mistakes.Commonly bought anyway: a handful of consultant days at the readiness stage, to avoid scoping the whole thing wrong.

So the real question is not which is cheaper in total. It is whether you would rather pay a published platform price or absorb several hundred hours of your most expensive engineer. Put your own hourly cost and your own platform quote into the break-even tool and it will tell you which way the trade lands for your numbers, which is the only way that question has an answer.

Section 02

What DIY needs to work

A senior security or engineering lead with 30 to 40 percent free time across 6 to 9 months. Without that, DIY breaks within the first month. The lead role is non-delegable: it is the person who owns control design, evidence collection rhythm, audit-firm liaison, and exception management.

A lightweight evidence-collection system. Most DIY SOC 2 programmes use a shared drive (one folder per control), plus a ticketing-system tag convention (one tag per control), plus a monthly 30-minute evidence-review meeting with the control owner. The whole system can be set up in two days. It does not need to be elegant.

Existing reasonable security hygiene. DIY does not work on top of a mess. If access management is ad-hoc, change management is informal, and vendor reviews have never happened, the readiness gap is too large for the lead to close in 6 months.

Section 03

Where DIY breaks down

ScenarioWhy DIY breaksWhat works instead
Multi-framework programme (SOC 2 + ISO 27001 + GDPR)Single source of truth for evidence becomes painful across three control sets. Evidence drift between frameworks generates audit-fee inflation.Platform path. Multi-framework is the canonical case where platforms earn their fee.
Distributed engineering team (20+ engineers across regions)Calendar coordination on evidence collection scales poorly. Automated collection is the only practical answer.Platform path or a hybrid (entry-tier platform for evidence, internal lead for policy).
Privacy criterion in scopeDSAR handling, processor inventories, and data-flow mapping get heavy fast. Manual coordination costs more than the platform fee.Platform path with a Privacy module, or a hybrid.
First-time SOC 2 with no senior security FTELead role unfilled, readiness stalls, audit slips a quarter.Boutique consultant for readiness, then DIY through the audit cycle once the lead role is permanently filled.
Section 04

The hybrid pattern

The most common real-world answer is neither path. Many teams do the policy and process work themselves and buy an entry-tier platform purely for evidence automation, which at startup and small-scale headcount is the cheapest published tier on the listing rather than the full-fat contract. The advantages are genuine on both sides: the policy work captures what the organisation actually does instead of inheriting a vendor's template defaults, and the platform handles the thing DIY does worst, which is collecting evidence consistently across people and time zones.

Cross-reference

For the platform path with break-even calculator, see the GRC platforms page. For the readiness work that DIY teams handle in-house, see the readiness cost page. For the audit-firm fee that is identical on either path, see the audit firm fees page. For the scale-up bracket where DIY breaks down, see the scale-up cost page.

Section 06

FAQ

Can you really do SOC 2 without a consultant?+
Yes, for an under-50 employee SaaS with strong existing security hygiene and a senior security or engineering lead with 30 to 40 percent free time. Above 50 employees, or with low maturity, the cost in internal hours typically exceeds a light consultancy engagement.
Can the audit firm be skipped?+
No. SOC 2 is an attestation issued by a licensed CPA firm under AICPA standards. Without that attestation, the report is not a SOC 2 report. The audit fee is non-negotiable. DIY refers only to readiness, evidence collection, and policy work.
What policies do we actually need?+
At minimum: information security policy, access management policy, change management policy, incident response policy, vendor management policy, business continuity policy, acceptable use policy, data classification policy. Most platforms ship templates; CPA firms will provide a list before the engagement starts. Policies do not need to be long; they need to reflect actual practice.
How do we collect evidence without a platform?+
A shared drive (Google Drive or Notion) with a folder per control, a tagging convention in the ticketing system (one tag per control), and a 30-minute monthly evidence-collection rhythm with the responsible owner. The pattern works at small scale; at 50+ employees the manual coordination burden grows faster than the team.

Updated 2026-07-15