In March, a Y Combinator–backed compliance startup called Delve was accused of drafting auditor conclusions before any audit took place — a direct violation of AICPA independence rules. An investigation found that 493 of 494 SOC 2 reports examined were nearly identical, down to the same grammatical errors, with only the client name and logo changed. The AICPA is now paying attention to the entire category.
If one of your portcos has a SOC 2 report sitting on its trust page, the question is no longer do they have one? It's will it hold up?
Here's what most operating partners haven't internalized yet: the GRC platform does not get you a SOC 2.
A GRC platform does three things well. It centralizes evidence. It maps controls across frameworks. It clarifies workflows. That's real value, and a portco without one is doing it the hard way.
What the platform does not do is produce a defensible audit report. The audit report is produced by an independent CPA firm, exercising professional judgment, testing controls that the platform organized but didn't validate. When that judgment is missing — or worse, outsourced to a firm whose AICPA standing is suspect — the report is a piece of paper, not an attestation. Buyers who used to take a SOC 2 badge at face value are about to start reading the auditor's name.
This is the part that matters for a portfolio: a first-time SOC 2 Type 2 is not one decision. It's four.
The platform. Right now, this is the easiest decision of the four. Every mature platform in the category covers SOC 2 natively, and the Delve story didn't change that — Delve wasn't a platform failure, it was an auditor failure. Pick one and move on. Spending six weeks on a feature comparison is six weeks not spent on the decisions that actually determine whether the report holds up.
The readiness partner. Someone who has stood up a program before, or has a background in Governance, Risk & Controls. This is where 5–10 weeks of timeline get saved or lost. They can also assist with bringing in an auditor that understands the type of environment you operate in.
The audit firm. A CPA with real SOC 2 and sector experience, AICPA-accredited, with a list of clients you can verify. Cheaper is not better here. Cheaper is the Delve story.
The observation window. 3 months is the floor for a Type 2. Choose deliberately based on when the enterprise deals are landing. Observation periods can be done in cycles (9 & 12 months being most common) but it’s up to organizational preference and program maturity (aka # of findings to remediate).
The portcos that get all four right finish a first Type 2 in 9 to 12 months for $70K–$100K all-in. The ones that picked the cheapest platform and the cheapest auditor — and treated SOC 2 as a tool purchase instead of an operations decision — are about to discover their report doesn't survive a sophisticated buyer's diligence.
That's a deal-velocity problem, an insurance problem, and an exit problem. All from a piece of paper that looked fine until somebody actually read it.
Key takeaway
A SOC 2 report is only as good as the four decisions behind it: platform, readiness partner, audit firm, observation window. The platform is the easy one. The audit firm is the one your portfolio is about to get tested on. Ask each portco who their auditor is — and check that name against the AICPA directory before the next diligence cycle starts.
