Screenata

SOC 2 Tools and Platforms

Can I switch compliance platforms during a SOC 2 observation period?

September 29, 20265 min read

Can you switch compliance platforms during a SOC 2 observation period?

Yes. A SOC 2 Type II report covers how your controls operated across the observation period, and the platform that stored the evidence is not part of that test. Switching mid-window does not restart the period. A clean switch needs three things: your auditor agrees the cutover date in advance, you export everything that exists only inside the old platform before access ends, and evidence stays continuous across the cutover.

The auditor samples dates from the whole period. For each sample they need evidence that the control operated, and they need to know where that evidence came from. Before the cutover, that is your export from the old platform. After it, that is the new platform's record.

When is the best time to switch?

Two dates set the timing: your contract's renewal date, with the notice deadline before it, and your audit cycle. Most compliance platform contracts are annual, so teams usually switch at renewal. For what a Vanta renewal tends to cost, see Vanta pricing in 2026.

Avoid switching while fieldwork for the previous period is still open, because the auditor's requests will point at records in the old platform. The next observation window usually starts the day after the last one ends, so almost every switch lands inside a window. That is the normal case.

A workable order:

  1. Read your order form for the renewal date and the notice deadline. Many contracts renew automatically unless you give notice by a set date.
  2. Tell your auditor the planned cutover date and ask what they need from each platform.
  3. Set up the new platform while the old one is still live. Connect your integrations, bring your policies, and set scope from the control list your auditor accepted.
  4. Export from the old platform using the list below, and keep the files unchanged.
  5. Switch on the agreed date. Evidence before it comes from the export, and evidence after it comes from the new platform.
  6. Give notice before the deadline, and keep the exports at least until the report for that period is issued.

What should you export before your contract ends?

Most of your evidence lives in your own systems, such as GitHub, your identity provider, your cloud accounts and your HR tool, and it survives the switch. What exists only inside the compliance platform is the record of people doing things: approvals, acknowledgments, reviews and uploads. Export that first.

What to exportWhy the auditor asks for it
Policies, with version history and approval datesShows which policy was in force on each date in the window
Employee policy acknowledgments and security training completionsAuditors sample employees and check both
Access reviews, with the reviewer, date and decision for each accountShows the periodic reviews happened
Uploaded evidence, with its original file datesCovers the controls no integration reaches
Test and monitoring history, with results by dateShows monitoring ran through the window
Vendor list and vendor reviews, including the SOC 2 reports you collectedVendor management controls
Risk register and your latest risk assessmentRisk assessment controls
Incident records and tabletop exercise notesIncident response controls
Onboarding and offboarding records, including background checksAuditors sample new hires and leavers
The control list and scope your auditor acceptedThe starting point for scoping the new platform
Your last SOC 2 report, bridge letter and trust center documentsKeeps customer requests covered during the switch

Keep the original files. A screenshot saved again months later loses the date the auditor relies on.

Can you keep your auditor when you switch?

Yes, if the new platform leaves the audit to a firm you choose. Vanta, Drata, Secureframe, Sprinto, Scrut Automation, Oneleet, Scytale and Screenata work that way. Thoropass audits through its own CPA firm, and Comp AI bundles an audit by default. If keeping your firm matters, confirm it with the vendor before you sign.

Two questions are worth asking any vendor. Can your current firm work from its platform? And does the vendor that prepares your evidence also provide or recommend your auditor?

Screenata sells no audit and takes no referral fee. The firm you already use, or any registered CPA firm, gets a read-only Auditor Center for each audit cycle with the controls, tests, evidence and signed manifests.

What moves over to Screenata, and what gets recaptured?

Migration to Screenata is export-based. Screenata does not pull from Vanta's or Drata's API.

Your policies come in as PDF or DOCX, and Screenata maps them to claims and tests. You bring the control list your auditor accepted, and we set scope from it with you during onboarding. You reconnect your integrations, and the native checks run overnight. Evidence from before the cutover stays in your export. From the cutover on, evidence that no integration reaches is recorded while your team does the task, with a capture-time timestamp and a signed manifest.

Screenata is $5,988 a year per framework for up to 50 employees and one legal entity, with the trust center, vendor risk management and security questionnaires included. At renewal you pay the list price for your headcount band, with no renewal uplift.

For how each alternative handles pricing and the audit, see Vanta alternatives compared.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.