distilled thought · compliance

SOC 2 Without the Theater

distilled thoughtSep 10, 2026

A short, distilled take from practice — notes rather than a long-form essay.

SOC 2 has a bad reputation for a good reason: too often it's a performance. Screenshots get collected, a report gets issued, and the day after the audit closes nothing is safer. It doesn't have to work that way.

Design controls you'd keep anyway

The best compliance programs are just good security with a paper trail. If a control exists only to satisfy an auditor, it will rot. If it exists because it genuinely reduces risk, the evidence is a byproduct of doing the work.

Automate the evidence, not the intent

Pull evidence from the systems of record — your identity provider, your cloud, your ticketing — instead of asking humans to screenshot their way to a deadline. Continuous evidence beats a frantic quarter-end scramble every time.

Make the auditor an ally

A good auditor wants what you want: a program that actually works. Bring them the honest picture and the report reflects real security instead of costuming for it. Multiple exception-free Type 2s later, I'm convinced the shortcut is just doing the thing properly.

The goal isn't to pass an audit. It's to build something you'd trust with your own data.