New data from compliance platform Drata suggests SOC 2 is increasingly becoming a baseline security requirement for B2B organisations, with adoption extending to smaller and earlier-stage companies.
Around 70% of Drata customers now have SOC 2, according to the company’s new SOC 2 By the Numbers report, which examines anonymised and aggregated data across its customer base.
The report looked at adoption, readiness timelines, integrations and the frameworks organisations pursue after obtaining their first SOC 2 report.
Drata said adoption is strongest in the Americas, where security and procurement teams frequently request SOC 2 reports during the sales process. Adoption is highest among software and services companies, followed by professional services, financial organisations and other sectors where customer data and service availability are particularly important.
The company also reported steady quarter-on-quarter growth in new SOC 2 accounts, which it linked to increased vendor scrutiny and third-party risk requirements.
However, Drata cautioned that its findings should not be treated as representative of the wider business population, as its customers are already likely to be investing in compliance.
“Treat the patterns as directional signals about how compliance-mature teams operate, rather than a census of the industry,” the company said.
The findings also suggest SOC 2 requirements are affecting smaller companies earlier in their development.
Drata said seed-stage and early-revenue businesses can encounter SOC 2 requirements as soon as they begin handling sensitive information or selling to enterprise customers, with buyers increasingly asking either for an existing report or a credible timeline for obtaining one.
According to the data, emerging companies with SOC 2 demonstrated higher readiness, greater use of the Drata platform and more active adoption of Trust Centers than companies of a similar size without the framework.
The findings challenge the assumption that larger organisations are necessarily better positioned to achieve SOC 2 readiness.
Drata said larger enterprises often face greater complexity because of the number of systems, stakeholders and processes within scope, while smaller organisations may have fewer systems and controls to manage.
As a result, smaller teams frequently achieve high readiness levels and complete the process more often, according to the report.
The company stressed, however, that readiness is not the same as completing a SOC 2 audit.
High readiness within Drata indicates that an organisation has controls in place, policies documented and evidence flowing into the platform. A SOC 2 Type II report, which Drata said is the form most commonly requested by enterprise buyers, also requires an observation period of around six to 12 months in which controls are operated and tested before an auditor can issue an opinion.
Because that period cannot begin until an organisation is ready, Drata argued that companies delaying SOC 2 preparation could also delay their ability to present a completed report to customers.
Existing security practices can also influence how quickly organisations progress.
Companies that already have measures such as access controls, logging and incident response processes in place have less work to complete before reaching readiness, according to the report.
Drata also identified a group of smaller and emerging organisations that do not yet have a SOC 2 report but appear relatively close to being ready.
Common remaining gaps include incomplete governance, vendor risk and incident response policies, evidence that is generated but not consistently documented or retained, and weaknesses in monitoring or third-party management.
For these organisations, Drata said completing SOC 2 may not require major changes to their technical architecture, but rather improvements to documentation, integrations, monitoring and specific areas of control coverage.
Integrations Linked to Compliance Maturity
The strongest indicator of SOC 2 maturity identified in Drata’s data was the number of systems connected to an organisation’s compliance programme.
According to the report, integration footprint was a stronger predictor of maturity than company size, geography or industry.
SOC 2 customers were found to connect more systems across areas including source control, cloud infrastructure, identity, HR, collaboration, ticketing and security.
GitHub, AWS and Slack were among the most commonly used integrations.
Drata said connecting these systems can automate evidence collection, keep readiness information current and help organisations identify control drift earlier.
The effect may be particularly significant for smaller companies, where a relatively limited set of integrations can reduce the amount of manual compliance work required.
Integrations can also support organisations operating across several regulatory or security frameworks, allowing evidence and shared controls to be reused across standards including SOC 2, ISO 27001, HIPAA and PCI DSS.
The report also highlighted vulnerability remediation and production configuration as areas where organisations encounter comparatively high failure rates.
Drata attributed this partly to the difficulty of keeping technical controls current across rapidly changing cloud infrastructure and software environments.
While organisations may be able to create policies relatively easily, maintaining up-to-date technical evidence and monitoring can prove more difficult.
The report suggested teams performing more strongly in these areas typically maintain tighter links between vulnerability scanning tools, cloud infrastructure, source code systems and their wider control monitoring processes.
Drata also found that organisations commonly expand into additional compliance frameworks after completing SOC 2.
ISO 27001 was among the frameworks most frequently adopted alongside SOC 2, while health technology companies commonly combine it with HIPAA and fintech or payments-focused organisations may also adopt PCI DSS.
Companies operating in markets where ISO 27001 is more commonly requested may begin with that standard before adding SOC 2 when targeting US customers, while US-focused companies can follow the opposite route when expanding internationally.
Recommended reading
- OpenAI and Anthropic Called to White House Over AI Hacking Risks
- NCSC Publishes Interim Guidance on Agentic AI Security
- Anthropic and OpenAI Models Implicated in New Cyber Testing Breaches
- OpenAI Model Goes Rogue In Testing, Hacks Hugging Face
Drata said mature organisations increasingly use a shared control environment that maps individual controls and evidence across several frameworks rather than maintaining entirely separate compliance programmes.
For larger enterprises, the report suggested the challenge increasingly shifts away from whether to obtain SOC 2 towards harmonising controls, evidence and reporting across multiple business units and frameworks.
For smaller and growing companies, meanwhile, Drata argued that SOC 2 is increasingly becoming an early operational and commercial consideration rather than a compliance exercise reserved for later stages of growth.
“A SOC 2 Report Is Just the Beginning,” the company said.
Drata said organisations generally continue collecting evidence, testing controls and responding to security questionnaires after receiving an initial report, while additional frameworks may be introduced as the business expands.
The company said organisations that manage this process most effectively tend to favour automated integrations, continuous monitoring and repeatable compliance processes over manual evidence collection and point-in-time preparation.





