DIY SOC 2: cost, time, and where it actually breaks down.
What DIY actually changes
DIY is not a cheaper SOC 2. It is a differently-shaped one. The audit fee is identical either way, because the auditor tests the same controls regardless of how you assembled the evidence, and it is the largest line on both paths. What DIY removes is the platform contract. What it adds is hours.
| Line item | Platform-led | DIY |
|---|---|---|
| Audit firm fee | The dominant line. Not published by any firm. | Identical. The auditor does not charge less because you used a spreadsheet, and does not charge more either. |
| GRC platform | A published annual contract, in US dollars, on the vendor's AWS Marketplace listing. | Zero. This is the entire cash saving, and it is the only line DIY removes. |
| Internal time | Lower. Evidence collection is automated; the judgement work is not. | Materially higher, and concentrated on one senior person. This is what you are trading the platform fee for. |
| Light advisory | Often unnecessary. The platform's gap analysis covers the scoping mistakes. | Commonly bought anyway: a handful of consultant days at the readiness stage, to avoid scoping the whole thing wrong. |
So the real question is not which is cheaper in total. It is whether you would rather pay a published platform price or absorb several hundred hours of your most expensive engineer. Put your own hourly cost and your own platform quote into the break-even tool and it will tell you which way the trade lands for your numbers, which is the only way that question has an answer.
What DIY needs to work
A senior security or engineering lead with 30 to 40 percent free time across 6 to 9 months. Without that, DIY breaks within the first month. The lead role is non-delegable: it is the person who owns control design, evidence collection rhythm, audit-firm liaison, and exception management.
A lightweight evidence-collection system. Most DIY SOC 2 programmes use a shared drive (one folder per control), plus a ticketing-system tag convention (one tag per control), plus a monthly 30-minute evidence-review meeting with the control owner. The whole system can be set up in two days. It does not need to be elegant.
Existing reasonable security hygiene. DIY does not work on top of a mess. If access management is ad-hoc, change management is informal, and vendor reviews have never happened, the readiness gap is too large for the lead to close in 6 months.
Where DIY breaks down
| Scenario | Why DIY breaks | What works instead |
|---|---|---|
| Multi-framework programme (SOC 2 + ISO 27001 + GDPR) | Single source of truth for evidence becomes painful across three control sets. Evidence drift between frameworks generates audit-fee inflation. | Platform path. Multi-framework is the canonical case where platforms earn their fee. |
| Distributed engineering team (20+ engineers across regions) | Calendar coordination on evidence collection scales poorly. Automated collection is the only practical answer. | Platform path or a hybrid (entry-tier platform for evidence, internal lead for policy). |
| Privacy criterion in scope | DSAR handling, processor inventories, and data-flow mapping get heavy fast. Manual coordination costs more than the platform fee. | Platform path with a Privacy module, or a hybrid. |
| First-time SOC 2 with no senior security FTE | Lead role unfilled, readiness stalls, audit slips a quarter. | Boutique consultant for readiness, then DIY through the audit cycle once the lead role is permanently filled. |
The hybrid pattern
The most common real-world answer is neither path. Many teams do the policy and process work themselves and buy an entry-tier platform purely for evidence automation, which at startup and small-scale headcount is the cheapest published tier on the listing rather than the full-fat contract. The advantages are genuine on both sides: the policy work captures what the organisation actually does instead of inheriting a vendor's template defaults, and the platform handles the thing DIY does worst, which is collecting evidence consistently across people and time zones.
Cross-reference
For the platform path with break-even calculator, see the GRC platforms page. For the readiness work that DIY teams handle in-house, see the readiness cost page. For the audit-firm fee that is identical on either path, see the audit firm fees page. For the scale-up bracket where DIY breaks down, see the scale-up cost page.