Compliance platforms have changed SOC 2 in five years. Evidence that used to be collected in screenshots now flows from APIs. But the marketing has also created a dangerous idea: that the platform gets you SOC 2. It does not. Here is a sober look at what these tools do well, where people get burned and what changed in 2026.
What the platforms actually do
- Integrations: connect to your identity provider, cloud accounts, code repository, ticketing and HR systems and pull configuration and user data continuously.
- Tests: run automated checks (MFA enabled, branch protection on, encryption at rest, backups configured) and flag failures.
- Policy templates: a library of policies with acknowledgement tracking.
- Evidence store: a place where auditors can log in and collect evidence during fieldwork.
- Task management: owners, due dates, reminders for recurring controls.
For a Type 2 observation period this is valuable: the platform proves a control ran every day without anyone taking screenshots.
What they cannot do
- Define your scope. Which systems, criteria and subservice organisations are in the report is a judgement call.
- Write your system description. Section III of the report is yours, and auditors notice templated prose.
- Perform the risk assessment. A list of generic risks with default ratings is not a risk assessment.
- Run controls that need humans: access review decisions, vendor due diligence, incident tabletops, change approvals.
- Issue the report. Only a licensed CPA firm can. The platform may introduce you to one; it cannot replace one.
What changed in 2026
In April and May 2026 the AICPA published guidance for peer reviewers and ethics guidance on SOC engagements that use third-party platforms. Reviewers are now told to examine how firms rely on platform outputs, whether timelines are realistic and whether reports across clients look suspiciously identical. Agreements giving a platform influence over scope, fees or marketing are treated as independence threats. In practice: a CPA firm that simply accepts the platform's green ticks is exposing itself and its clients. Expect more questions from good auditors, not fewer, even if your dashboard is all green.
Choosing a platform as a European company
- Data residency: where is your evidence stored, and can you sign a DPA that works under GDPR?
- Frameworks: if you will also need ISO 27001, NIS2 or Cyber Essentials, check that the platform maps controls across them rather than duplicating work.
- Integrations with your stack: European HR, payroll and identity tools are not always covered.
- Auditor independence: you should be free to choose any CPA firm. Read the partner terms.
- Price over three years: platform subscriptions outlast the first report.
Platform, consultant, auditor: three different jobs
| Role | Who | Responsible for |
|---|---|---|
| Platform | Vanta, Drata, Secureframe, Sprinto and others | Collecting and monitoring evidence |
| Readiness partner | BALTUM or similar | Scope, system description, risk assessment, policies, internal audit, preparing your team |
| Auditor | Independent licensed CPA firm | Examination, opinion, the report |
The roles must stay separate. A consultant who also signs the report, or a platform that also sets the audit fee, is a structure your customers' security teams will eventually question.
Our recommendation
Use a platform if you are going for Type 2 and have more than a handful of systems; skip it for a quick Type 1 if budget is tight. Connect it in week one of readiness, not after. Let the platform collect, let people decide, and let an independent CPA firm examine. BALTUM works with all major platforms and with none exclusively. Ask us which setup fits your stack.