A one-person company ships like a 20-person team now. That is the whole reason this problem exists. You are selling to companies big enough to have a procurement process, at a headcount that used to mean you were never in the room. So the questionnaire arrives, there is a SOC 2 line in it, and every control you read about assumes a team you do not have.
Five years at Deloitte auditing SOC 2 for tech companies across the US and Canada. 30+ of them, for names like LinkedIn, Affirm and Ripple.
In all that fieldwork I never once saw "too few people" written down as an audit failure. What I saw was auditors who never learned to translate big-company control language down to a small company, so they either invented busywork or wrote up a finding that did not need to exist.
So here is the useful version of the question. Not "can I pass" but "what does the auditor actually open when the company is one person and an agent."
Change management: I open your branch protection settings






