How to announce SOC 2 in progress to customers
Prospects are asking about SOC 2 and you don't have a report yet. Here's what you can say, what you can't, plus email and security-page templates.
A prospect just asked if you’re SOC 2 compliant. You aren’t. You bought a compliance tool last month, wrote a few policies, and now someone on sales wants to put “SOC 2 in progress” on the website and email every customer.
Before you do anything: slow down.
“SOC 2 in progress” is a useful sentence when it is true. It is a liability when it is a vibe. The gap between those two is where companies get sloppy: they use a badge that looks official, they say “compliant” when they mean “we started,” and they announce a journey that has not actually begun.
Key takeaways
- You can describe the work. You cannot claim the result. Name the report type, the firm, and the dates. Do not say you are SOC 2 compliant, certified, or attested until a CPA has issued the report.
- “In progress” needs a start line. An engaged auditor or an observation period that has started counts. Creating an account on Vanta, Drata, or any other platform does not.
- Skip the fake official badge. The AICPA SOC logo is off limits until you have a report and you register to use it. A dated sentence beats a sticker.
- Tell the people who asked. Put the same facts on your security page. Do not treat this like a product launch.
What “SOC 2 in progress” actually means
SOC 2 is not a certification you hang on a wall. It is an attestation report issued by a licensed CPA. Until that report exists, you are not SOC 2 anything. You are preparing for an examination, or you are already in one.
Those are different states. Treat them that way.
Not in progress: you subscribed to a compliance platform. You drafted policies. You added MFA. Those are good security moves. They are not a SOC 2 status.
Readiness: you have scoped the report, closed the obvious gaps, and you are lining up an auditor. You can say you are preparing for a SOC 2 examination. You should not imply the exam has started.
In progress: a CPA firm is engaged, or the Type II observation period has a start date. Now “SOC 2 Type II examination in progress” is a sentence you can stand behind.
If you cannot name the firm or the observation start date, you are not in progress. You are getting ready. Say that.
What you are allowed to claim before the audit
This is not legal advice. It is the line we tell founders to stay on the right side of, because the risk is ordinary and boring: a buyer, a regulator, or a plaintiff’s lawyer treats your marketing as a representation.
In the US, a claim that you hold a certification or attestation you do not hold is the kind of thing the FTC treats as deceptive advertising. In a contract or a security exhibit, the same sentence can become a warranty. The AICPA also treats “SOC 2 certified” as the wrong phrase even after you have a report, because SOC 2 is an attestation, not a certification.
Say things you can prove.
| You can say | You should not say |
|---|---|
| We are preparing for a SOC 2 Type II examination. | We are SOC 2 compliant. |
| We have engaged [CPA firm] for a SOC 2 Type II examination covering Security. | We are SOC 2 certified. |
| The observation period started on [date]. We expect the report in [month]. | We are SOC 2 Type II (as a current status). |
| We operate MFA, encryption in transit and at rest, and [other facts]. | Our controls are SOC 2 attested. |
| A Type I report is planned for [month] if you need an earlier artifact. | We passed our SOC 2 audit. |
Two more rules that catch people:
Do not put a completion date on the page as if it were guaranteed. Audits slip. Exceptions appear. Write “we expect” or “we are targeting,” then update the page when the date moves.
Do not let sales paste “SOC 2 compliant” into an MSA, a security questionnaire, or a procurement portal. That is how a marketing shortcut becomes a contractual representation. If the form only has a yes/no checkbox, the honest answer is no, with a comment that an examination is underway.
How to announce it without looking like you are bluffing
You do not need a launch. You need one email to the people who asked, and one paragraph on the security page.
Reply to the prospect who raised it. Tell your champion they can forward the note to security. Update /security or your compliance portal the same day, so the next buyer finds the same words.
Skip the company-wide “we are on the SOC 2 journey” email unless customers have been asking in volume. Most of them were not waiting for this. A quiet, dated update ages better than a campaign you have to walk back.
If you post on LinkedIn, use the same facts as the email. No badge that looks like the AICPA mark. No “certified.” The post is optional. The written reply to the buyer is not.
Email template
Copy this, fill the brackets, and send it as a reply (not a newsletter).
Subject: Our SOC 2 Type II status
Hi [Name],
You asked whether we are SOC 2 compliant. The accurate answer: not yet. A SOC 2 Type II examination is underway.
Details we can stand behind today:- Report: SOC 2 Type II- Criteria: Security [add Availability / Confidentiality if they are in scope]- Auditor: [CPA firm]- Observation period: started [date]- Expected report: [month or quarter]
Until that report is issued, we will not call ourselves SOC 2 compliant or display the AICPA SOC logo.
What we can share now:- Security page: [URL]- [Questionnaire / current practices summary]- [Pentest summary or policies, under NDA if needed]
If procurement cannot wait for Type II, tell us. A Type I report can come first, and we can put a date on that.
Happy to join a call with your security reviewer this week.
[Your name]The useful line is the one that admits you do not have the report. Buyers who have read a SOC 2 before will relax when they see you know the difference. Buyers who have not will still get a date and a next step.
Security page template
Put this near the top of /security, the trust center, or your Compliance Portal. Keep it public. Keep the report itself gated later. A claim can be public. Evidence should not be.
SOC 2 Type II examination in progress
[Company] has engaged [CPA firm] for a SOC 2 Type II examination against theSecurity Trust Services Criteria. The observation period began [Month Year].We expect the report in [Month Year].
Until the report is issued, we are not SOC 2 attested and we do not use theAICPA SOC logo.
Practices we operate today (not yet independently attested):- MFA on all production access- Encryption in transit and at rest- Logging and alerting on production systems- Vendor review for processors that handle customer data
Request documents: [compliance.yourcompany.com or security@yourcompany.com]Update the expected month when it changes. A stale date is worse than no date. If you slip from March to June and leave March on the page, the next security reviewer will assume the rest of the page is equally loose.
If you do not have a CPA firm yet, do not use the template above. Write “We are preparing for a SOC 2 Type II examination” and list the practices. Inventing an auditor is the fastest way to lose the room.
SOC 2 in progress badge guidance
This is the other query behind this article, and the short answer is: most badges in this category are doing work the sentence should do.
The official AICPA SOC logo is not available to you. You need a completed SOC 1, SOC 2, or SOC 3 report, a clean opinion, and a registration with the AICPA. The logo also expires if you go more than 12 months without a new report. We wrote up the actual logo rules, including the April 2026 registration changes. If you do not have a report, stop looking for a version of that mark you can “kind of” use.
Vendor “SOC 2 in progress” badges are marketing, not AICPA marks. Vanta, Drata, Secureframe, and others will give you a sticker the moment the account exists. That is the vendor advertising that you are on their platform. It is not an auditor saying anything. Sophisticated buyers discount these on sight. Some of the badges are designed close enough to the official mark that a hurried procurement intern will screenshot them as “they have SOC 2.”
If you still want a badge:
- It has to say “in progress” in the artwork, not only in the alt text.
- You have actually engaged an auditor, or the observation period has started.
- It cannot use the AICPA wordmark, the SOC lockup, or a near-copy of either.
- Link it to the security-page paragraph, not to a homepage hero.
The better move is usually no badge. A dated sentence with a firm name outperforms a green shield. If you want a visual later, wait for the report and register for the real logo.
What this announcement will and will not do
SOC 2 in progress does not replace a report. Enterprise procurement will still send the questionnaire. Many will still ask for a Type I, a pentest, or a signed security exhibit.
What it does well: it stops your team from improvising. Everyone forwards the same paragraph. The buyer gets a date. You buy two to four weeks of a conversation that would otherwise stall on “are you compliant, yes or no.”
If the deal is real and the report is the blocker, treat this as a bridge, not the deliverable. Get an engagement letter before you spend the next quarter on a maybe. Consider Type I if they need an artifact this quarter. Type II is what they will want next. It is also the one that takes 3 to 12 months of observation, which is why people start reaching for the in-progress line in the first place.
An announcement is not a control. It is a status. Keep it true, keep it dated, and take it down the week the report lands. Then you can say something better.
The companies that handle this well sound slightly underconfident on the website and completely specific in the email. That combination is what a security reviewer is looking for. The companies that handle it badly put a badge on the homepage and hope nobody asks for the PDF.
If you want the report, not just the sentence, talk to us. We will tell you whether you are actually in progress or still getting ready.
Frequently Asked Questions
How do I announce SOC 2 in progress to customers?
Tell the people who asked, in writing, with facts you can prove: the report type, the CPA firm if you have one, the observation start date, and an expected report window. Do not blast existing customers just because you opened an account on a compliance platform. Put the same language on your security page.
Can I use a SOC 2 in progress badge for marketing?
Not the official AICPA SOC logo. That mark requires a completed report and formal registration. Vendor “SOC 2 in progress” badges are the vendor’s marketing, not AICPA’s. Use one only if it clearly says in progress and you have actually started an examination. A dated sentence on the security page is usually stronger.
Can I say I’m SOC 2 compliant before the audit?
No. You do not have a SOC 2 report until a licensed CPA issues one. Calling yourself SOC 2 compliant, SOC 2 certified, or SOC 2 attested before that is a claim you cannot back up. It is also the wrong noun: SOC 2 is an attestation report, not a certification.
When should I tell customers I’ve started SOC 2?
Once an auditor is engaged, or the Type II observation period has started. Signing up for a compliance tool is not a status. If a named prospect asked, reply as soon as you have a real timeline. If nobody asked, update the security page and wait.
Does saying SOC 2 in progress help close deals?
It buys time. It rarely closes the deal. Enterprise procurement still wants a report, a questionnaire, or both. Use the announcement to set a date, share current practices, and offer a Type I if the timeline cannot wait for Type II.
You're subscribed — thanks for signing up!