What is a SOC 2 kickoff call?
A SOC 2 kickoff call is the first meeting with your auditor, where you confirm scope, trust criteria, the report type and observation window, timeline, evidence expectations, and how you'll share information — setting the plan before fieldwork begins.
The full answer
The kickoff call is where a SOC 2 engagement officially starts. After you have chosen an auditor, this first meeting aligns everyone on what is being examined and how. Because SOC 2 reports are attestations issued by licensed CPA firms under the AICPA's SSAE No. 18 standard, getting scope right at kickoff prevents surprises later in fieldwork.
Expect to nail down scope and report type. You will confirm which systems are in scope, which trust services criteria apply — security is required, with availability, confidentiality, processing integrity, and privacy optional — and whether you are doing a Type 1 or a Type 2. For a Type 2 you set the observation window, usually three to twelve months, with three months the shortest most auditors accept.
You will also agree on logistics: the overall timeline, who owns evidence on your side, the format evidence should take, and how you will share it. If your auditor has a confirmed integration with a GRC platform like Vanta, Drata, or Secureframe, kickoff is when you connect it so they can pull evidence directly and shorten later phases.
Come prepared with your system description, a rough control list, and questions about anything ambiguous. To line up a firm and get a fixed-scope quote before your kickoff, request a quote based on your specific environment.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Can I speed up a SOC 2 audit?
Yes, partly. You can compress readiness and fieldwork with a GRC platform, a Type 1 or 3-month Type 2 first, and fast evidence responses — but a Type 2 observation window still has to run its full length.
Can a SOC 2 Type 2 observation period be 3 months?
Yes. Three months is the shortest observation window most auditors will accept for a SOC 2 Type 2, so a 3-month period is valid and common for a first report. Longer windows give buyers more assurance.
Do SOC 2 audits happen on-site or remotely?
Almost always remotely. Most SOC 2 audits are conducted entirely over video calls, screen shares, and secure evidence uploads, since the evidence is digital. On-site visits are rare and usually only relevant if you run your own physical data centers.
How long does a SOC 2 audit take?
A SOC 2 Type 1 usually takes one to three months end to end, while a Type 2 adds an observation window of three to twelve months. Readiness prep, not the audit itself, is often the longest phase.
How long does the SOC 2 report take after fieldwork ends?
Most SOC 2 reports are drafted and delivered within a few weeks of fieldwork ending, though timing varies by firm and how quickly you clear any open evidence items. There is no AICPA-set deadline for delivery.
How many internal hours does a SOC 2 audit take my team?
There is no official figure. Most internal effort is front-loaded during readiness, not the audit itself. Expect a designated owner to spend meaningful part-time hours over the prep window, plus lighter time answering auditor questions during fieldwork.
Sources: AICPA SSAE No. 18 attestation standards; SOC 2 engagement kickoff market practice (2026). Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.