SOC 2 Tools and Platforms
Can I switch compliance platforms during a SOC 2 observation period?
Can you switch compliance platforms during a SOC 2 observation period?
Yes. A SOC 2 Type II report covers how your controls operated across the observation period, and the platform that stored the evidence is not part of that test. Switching mid-window does not restart the period. A clean switch needs three things: your auditor agrees the cutover date in advance, you export everything that exists only inside the old platform before access ends, and evidence stays continuous across the cutover.
The auditor samples dates from the whole period. For each sample they need evidence that the control operated, and they need to know where that evidence came from. Before the cutover, that is your export from the old platform. After it, that is the new platform's record.
When is the best time to switch?
Two dates set the timing: your contract's renewal date, with the notice deadline before it, and your audit cycle. Most compliance platform contracts are annual, so teams usually switch at renewal. For what a Vanta renewal tends to cost, see Vanta pricing in 2026.
Avoid switching while fieldwork for the previous period is still open, because the auditor's requests will point at records in the old platform. The next observation window usually starts the day after the last one ends, so almost every switch lands inside a window. That is the normal case.
A workable order:
- Read your order form for the renewal date and the notice deadline. Many contracts renew automatically unless you give notice by a set date.
- Tell your auditor the planned cutover date and ask what they need from each platform.
- Set up the new platform while the old one is still live. Connect your integrations, bring your policies, and set scope from the control list your auditor accepted.
- Export from the old platform using the list below, and keep the files unchanged.
- Switch on the agreed date. Evidence before it comes from the export, and evidence after it comes from the new platform.
- Give notice before the deadline, and keep the exports at least until the report for that period is issued.
What should you export before your contract ends?
Most of your evidence lives in your own systems, such as GitHub, your identity provider, your cloud accounts and your HR tool, and it survives the switch. What exists only inside the compliance platform is the record of people doing things: approvals, acknowledgments, reviews and uploads. Export that first.
| What to export | Why the auditor asks for it |
|---|---|
| Policies, with version history and approval dates | Shows which policy was in force on each date in the window |
| Employee policy acknowledgments and security training completions | Auditors sample employees and check both |
| Access reviews, with the reviewer, date and decision for each account | Shows the periodic reviews happened |
| Uploaded evidence, with its original file dates | Covers the controls no integration reaches |
| Test and monitoring history, with results by date | Shows monitoring ran through the window |
| Vendor list and vendor reviews, including the SOC 2 reports you collected | Vendor management controls |
| Risk register and your latest risk assessment | Risk assessment controls |
| Incident records and tabletop exercise notes | Incident response controls |
| Onboarding and offboarding records, including background checks | Auditors sample new hires and leavers |
| The control list and scope your auditor accepted | The starting point for scoping the new platform |
| Your last SOC 2 report, bridge letter and trust center documents | Keeps customer requests covered during the switch |
Keep the original files. A screenshot saved again months later loses the date the auditor relies on.
Can you keep your auditor when you switch?
Yes, if the new platform leaves the audit to a firm you choose. Vanta, Drata, Secureframe, Sprinto, Scrut Automation, Oneleet, Scytale and Screenata work that way. Thoropass audits through its own CPA firm, and Comp AI bundles an audit by default. If keeping your firm matters, confirm it with the vendor before you sign.
Two questions are worth asking any vendor. Can your current firm work from its platform? And does the vendor that prepares your evidence also provide or recommend your auditor?
Screenata sells no audit and takes no referral fee. The firm you already use, or any registered CPA firm, gets a read-only Auditor Center for each audit cycle with the controls, tests, evidence and signed manifests.
What moves over to Screenata, and what gets recaptured?
Migration to Screenata is export-based. Screenata does not pull from Vanta's or Drata's API.
Your policies come in as PDF or DOCX, and Screenata maps them to claims and tests. You bring the control list your auditor accepted, and we set scope from it with you during onboarding. You reconnect your integrations, and the native checks run overnight. Evidence from before the cutover stays in your export. From the cutover on, evidence that no integration reaches is recorded while your team does the task, with a capture-time timestamp and a signed manifest.
Screenata is $5,988 a year per framework for up to 50 employees and one legal entity, with the trust center, vendor risk management and security questionnaires included. At renewal you pay the list price for your headcount band, with no renewal uplift.
For how each alternative handles pricing and the audit, see Vanta alternatives compared.