I think companies like Deel showed that SOC2 is more show than anything else.
For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
Hasn't Deel been run out of business though?
IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.
A SOC2's quality entirely depends on how much you trust the auditing firm.
Delve used an audit mill they paid to rubber-stamp the cookie-cutter and AI slop reports it authored. I hope it ends up in fraud charges.
But I wouldn't assume that's the case for all SOC2 reports. Any decent auditing firm should be far more rigorous.
Delve. Not Deel. Very different startups.