← All posts
SOC 2 for solo foundersone-person company SOC 2SOC 2 for startups

SOC 2 for Solo Founders: Can a One-Person Company Do It?

A solo founder can pursue SOC 2, but must plan for review, control evidence, and CPA judgment that one person cannot supply alone.

A solo founder can own the program record while naming a separate reviewer for work that needs one.
A solo founder can own the program record while naming a separate reviewer for work that needs one.

A solo founder can pursue a SOC 2 report. The hard part is showing how a one-person company operates its controls and gets a real challenge when a decision needs another reviewer. You can own the program, run systems, and keep evidence. You cannot turn your own second signature, an automated check, or the CPA firm’s examination into an independent management review. Plan the roles with a qualified CPA firm before promising a buyer a report date.

Can a solo founder get a SOC 2 report?

The AICPA’s SOC 2 guidance describes an examination of a service organization’s system and controls. It does not set a universal employee count for the service organization. That means headcount alone is not the decision. This is an inference from the published criteria, not a promise that a CPA firm will accept a specific one-person design.

Start with the buyer’s exact request. Does it need a Type 1 or Type 2 report? Which service and criteria must it cover? Would a security questionnaire while you have no report meet the immediate need? The broader startup SOC 2 decision guide helps you decide whether this is the right time to start. A report is a business decision, not a milestone every solo founder must reach.

Which jobs can one person own?

One person can coordinate scope, document procedures, operate many controls, collect source records, and track follow-up. Those actions still need to match what actually happened. The AICPA Trust Services Criteria evaluate controls against relevant criteria, including access and change work. They are not a ready-made task list that excuses missing review.

Make a short role map before writing policies:

Work Solo founder can do it? What to check
Define the service and systems in scope Yes Ask the CPA firm to test the proposed boundary.
Operate cloud, identity, backup, and change procedures Yes, if the procedures are real Keep dated source records and exceptions.
Approve a policy they own Not as a separate reviewer Appoint someone who can challenge the exact text.
Review their own privileged access or code change Not as an independent check Design another review or safeguard and discuss it with the CPA firm.
Assert what the company does Yes, as management Reconcile each claim to the scope and records.
Examine controls and issue the SOC 2 report No An independent CPA firm performs this work.

This table is a planning tool. Your control design and the CPA firm’s judgment decide what is suitable for the service. Do not write a policy that promises two-person approval if the company has no way to carry it out.

How to get a real second review

List the decisions that need someone other than you. Policy approval, risk assessment review, sensitive access decisions, production changes, and periodic control oversight may need different arrangements. A single outside person should only take work they can actually understand and perform.

For each review, record:

  1. What the reviewer is authorized to decide.
  2. Their relationship to the company and why they can challenge your work.
  3. The exact record, revision, population, or period reviewed.
  4. The source material they saw.
  5. The decision date, result, exceptions, and follow-up.

A qualified external management reviewer can help where there is no second internal leader. Give them access only to the material they need, define how they report a disagreement, and record the appointment before the first approval. The policy approval guide explains why a review must bind to the exact policy revision and why approval alone does not prove that a control operates.

Keep that management reviewer separate from the CPA firm that will examine the system. The AICPA’s SOC resource library includes material on management’s role and auditor independence. Ask the firm about any proposed advisory work before assigning it. Do not assume a paid adviser, a code review bot, or a second account under your name is an independent person.

What evidence should a one-person company keep?

Keep proof from the system that performed the work. A Git commit shows a change to a file, but it does not prove a restore test succeeded or an access review happened. For each recurring or event-driven control, name the source, event date, period, owner, result, exception, and reviewer when one is required.

For example, a production change record could point to the pull request, automated test result, deployment event, and any separate review. A backup record could point to the backup platform and a dated restore test. If the founder is both operator and reviewer in a source system, record that conflict instead of changing a title to make the record look independent.

Before a Type 2 period, run a trial month of the schedule. Check whether you can still do the work during a product release, holiday, or customer incident. Missing or late work should be visible as a gap with a real fix, not backdated into a clean history. Use the SOC 2 evidence examples to plan each source record, then confirm the proposed evidence approach with your CPA firm.

Where FileGRC fits for a solo founder

FileGRC is a Git-native GRC workspace for SOC 2 work. JSON holds structured records, Markdown holds long-form work, and Git supplies the change history. Starter records are proposals for you to review, not claims that your company already operates a control.

FileGRC supports appointing an external policy reviewer and previewing the change before applying it:

npx filegrc external-reviewer-setup --scaffold > reviewer.json
npx filegrc external-reviewer-setup reviewer.json --preview --json

Fill the scaffold with the real reviewer, management appointment, start date, and independence rationale. A preview is not an appointment. The reviewer must actually accept the role and perform the reviews. FileGRC can validate records and show their Git diff, but it does not operate identity, cloud, backup, training, or other source systems. An agent can draft a record or flag a missing review; it cannot supply the second person’s judgment. The independent CPA firm still selects samples, evaluates exceptions and evidence, and issues the report.

Open source · MIT

Run your SOC 2 program as files in Git.

Keep policies, controls, work, and evidence indexes in a repository your team and agents can inspect. Add optional hosted email and Slack reminders to keep work moving.

Frequently asked questions

Can a one-person company get a SOC 2 report?

A one-person company can pursue a SOC 2 examination. There is no general headcount shortcut: management must describe its real system, operate controls, keep evidence, and work with an independent CPA firm. Ask the firm early whether the proposed controls and review arrangements support the planned report.

Can a solo founder approve their own SOC 2 policies?

Self-approval does not create an independent review. When a policy or chosen control calls for a separate reviewer, appoint a qualified person outside the company in a management review role and record their actual decision on the exact revision. The CPA firm remains separate from that role.

Does every SOC 2 control require two people?

No universal two-person rule applies to every control. Identify each control's objective and risk, then discuss where independent review or another safeguard is needed with the CPA firm. Do not label automated checks or self-review as a second person's approval.

Can an outside adviser be the reviewer and the SOC 2 auditor?

Do not assume the same person or firm can both perform management review and independently examine that work. Keep management responsibility with the company and ask the CPA firm about independence before assigning any advisory or review work.

Does FileGRC make a solo founder ready for SOC 2?

No. FileGRC organizes structured records in JSON, long-form work in Markdown, and change history in Git. Its starter records are proposals. The founder still operates controls, obtains suitable review, collects source evidence, and works with a CPA firm that judges the evidence.