frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

What's the hardest part of getting SOC 2 done in practice?

1•asdxrfx•1d ago
Hi HN,

I’m curious to hear from founders, engineers, and consultants who’ve gone through (or are going through) SOC 2. On paper it sounds straightforward: controls, evidence, audit, but in practice it seems to get messy quickly.

Some things I’ve heard people struggle with: translating abstract controls into real engineering workflows; knowing what level of evidence is “enough”; keeping things updated once the audit is over; coordinating between engineering, security, and ops; dealing with tools vs. spreadsheets vs. consultants

For those who’ve done it: - What part took the most time? - What was more painful than expected? - What did you wish you had known before starting?

Not trying to sell anything, genuinely trying to understand where the real friction is.

Thanks!

Comments

solarengineer•1d ago
It is actually OK to state that you are researching for ideas. This is HN, after all.

Try the HN search. There have been so many discussions about SOC2 over the years. https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Edit: Looks like you are the lumoar guy. So you already know what has been discussed. Please share clearly in the future.

Getting started with Claude for software development

https://steveklabnik.com/writing/getting-started-with-claude-for-software-development/
1•steveklabnik•47s ago•0 comments

NotepadNext – Cross-platform reimplementation of Notepad++

https://github.com/dail8859/NotepadNext
1•ethanpil•1m ago•0 comments

Kafka Inc

https://libertiesjournal.com/online-articles/kafkainc/
1•Caiero•1m ago•0 comments

FlashInfer-Bench: Building the Virtuous Cycle for AI-Driven LLM Systems

https://arxiv.org/abs/2601.00227
1•matt_d•3m ago•0 comments

A modular marketing command center built with autonomous workflows

https://flippa.com/12205760-vect-ai-is-an-autonomous-marketing-command-center-where-ai-agents-pla...
3•WoWSaaS•3m ago•0 comments

Predict Your House Price

https://www.bloomberg.com/opinion/newsletters/2026-01-06/predict-your-house-price
1•feross•4m ago•0 comments

Show HN: Sumoffy (macOS) – Offline Document Intelligence You Can Trust

https://rokontech.gumroad.com/l/sumoffy
1•rokontech•5m ago•0 comments

Vect AI: treating marketing execution as software, not a stack of tools

https://vect.pro/
2•MMAFRAZ•7m ago•1 comments

US says it will discuss Greenland ownership with Denmark next week

https://www.bbc.com/news/articles/cly39pgmvrzo
1•onemoresoop•7m ago•1 comments

Shortages Cause Sky-Rocketing RAM Prices – In 1985

https://www.goto10retro.com/p/shortages-cause-sky-rocketing-ram
1•rbanffy•7m ago•0 comments

Show HN: AbleMouse AI. Nose-point cursor. Screen-size independent

https://github.com/aradzhabov/AbleMouse
1•aradzhabov•9m ago•0 comments

Policy-Based Design versus Combinatorial Hell

https://becheler.github.io/policy-based-design/
2•todsacerdoti•9m ago•0 comments

Bikemap.nyc – visualization of the history of Citi Bike bike-sharing system

https://bikemap.nyc/
2•ChrisArchitect•9m ago•0 comments

Gleam Web Development Tutorial: JSON Rest API and Type-Safe SQL [video]

https://www.youtube.com/watch?v=kmbH7WdwKkc
1•andfadeev•10m ago•0 comments

macOS Background Security Improvement Update (BSI) Database

https://mrmacintosh.com/macos-background-security-improvement-update-bsi-database/
1•speckx•12m ago•0 comments

We Rewrote Our Startup from PHP to Gleam

https://www.radical-elements.com/minor-epiphanies/we-rewrote-our-startup-from-php-to-gleam-in-3-w...
1•lexx•14m ago•0 comments

Refuctoring [pdf]

https://www.waterfall2006.com/Refuctoring.pdf
2•bguthrie•15m ago•0 comments

British businesses warned of 'cashflow contagion' as more firms set to collapse

https://www.gbnews.com/money/businesses-warned-of-cashflow-contagion
1•petethomas•16m ago•1 comments

Monitoring a Docker Homelab with Open Source

https://coroot.com/blog/monitoring-a-docker-homelab-with-coroot/
2•DebianDude•17m ago•0 comments

Boycott Edge Esmeralda 2026

https://blog.hermesloom.org/p/boycott-edge-esmeralda-2026
1•sigalor•17m ago•0 comments

S3 processes over 100M reqs/sec with strong consistency

https://twitter.com/MarcJBrooker/status/2008670722613539292
1•aloukissas•17m ago•0 comments

Larry Page officially moves business out of CA ahead of a proposed wealth tax

https://www.businessinsider.com/larry-page-leave-california-wealth-billionaire-tax-koop-google-20...
2•elsewhen•17m ago•0 comments

Jensen Huang of Nvidia Named IEEE Medal of Honor Recipient

https://corporate-awards.ieee.org/ieee-medal-of-honor/
1•chrisaycock•17m ago•0 comments

Nvidia at CES, Vera Rubin and AI-Native Storage Infrastructure, Alpamayo

https://stratechery.com/2026/nvidia-at-ces-vera-rubin-and-ai-native-storage-infrastructure-alpamayo/
1•feross•18m ago•0 comments

Predator iOS Spyware: Build a Surveillance Framework

https://blog.reversesociety.co/blog/2025/predator-ios-malware-surveillance-framework-part-1
2•tonygo•19m ago•0 comments

ARM `IT` predication is architecturally unsafe for crypto implementations (POC)

https://github.com/jnk0le/random/blob/master/pipeline%20cycle%20test/CM85_predicate_timmingleak_P...
2•jnk0le•20m ago•1 comments

Facial Age Checks Now Required to Chat on Roblox

https://corp.roblox.com/newsroom/2026/01/roblox-age-checks-required-to-chat
1•haunter•20m ago•1 comments

Train Surgery [video]

https://www.youtube.com/watch?v=RAQBaDWxRQ0
1•iamflimflam1•21m ago•0 comments

Interesting Articles I've Read in 2025

https://bcmullins.github.io/interesting-articles-2025/
2•wannabebarista•21m ago•1 comments

Devaluation of Work

https://assertfail.gewalli.se/2026/01/06/Devaluation-of-work.html
1•wallymathieu•22m ago•0 comments