SOC 2 switch guides: how to change compliance platforms without losing your audit

Short answer

Ten lessons in three tracks: deciding to switch, timing it around your audit, and moving the work. They are generic and apply to any platform; where a lesson uses a vendor fact, it is one we read on the vendor's own page.

Deciding to switch

Recognise the triggers, build a shortlist and read the plan limits.

  1. 01

    Signs you have outgrown your SOC 2 platform

    The five situations that usually start a platform search, and how to tell a real limit from a fixable setup problem.

    2 min read

  2. 02

    Building a SOC 2 switch shortlist

    How to turn your reason for leaving into weighted criteria and cut eight platforms to three.

    2 min read

  3. 03

    Reading plan limits before you move

    What SOC 2 vendors publish about plan limits, what they leave out, and the questions that fill the gaps.

    2 min read

Timing and the audit

Keep your report continuous and your auditor informed.

  1. 04

    Timing a switch around your audit window

    When to move SOC 2 platforms relative to your Type I date or Type II period so your report stays continuous.

    2 min read

  2. 05

    What your auditor needs when you change tools

    The evidence, documents and explanations a SOC 2 auditor will ask for when your compliance platform changes.

    2 min read

  3. 06

    Keeping or changing your auditor when you switch platforms

    Whether to keep your current SOC 2 auditor through a platform switch, and what to ask about auditor independence from the tool vendor.

    2 min read

Moving the work

Move evidence, controls, integrations and your trust center.

  1. 07

    Moving policies and evidence to a new SOC 2 platform

    What to export from your old platform, how to keep version history and approvals, and what to rebuild rather than copy.

    2 min read

  2. 08

    Mapping controls across frameworks after a switch

    How cross-mapping and common control frameworks reduce the work of a second framework, and what to check when your new platform maps controls differently.

    2 min read

  3. 09

    Reconnecting integrations after a SOC 2 platform switch

    How to inventory the systems your evidence depends on, check them by name against the new platform, and avoid monitoring gaps on changeover day.

    2 min read

  4. 10

    Rebuilding your trust center and questionnaire library

    How to move a customer-facing trust center and your reusable security questionnaire answers without breaking links or losing approved wording.

    2 min read

Questions people ask

Do I need to read the lessons in order?

No. If you are mid-audit, start with lesson 4 on timing. If you have not chosen a platform yet, start with lesson 2. Timing a switch around your audit window

Are the lessons specific to one vendor?

No. They describe the work any switch involves. Vendor-specific migration tools are not described on the pages we read, so ask each vendor what it will import. Moving policies and evidence to a new SOC 2 platform

Who wrote them?

The Switchyard Desk, from public standards material and general SOC 2 practice. They are not legal or audit advice; your auditor has the final say on what evidence they need. Our scoring