Solo sysadmin with 6 months experience at an SMB (~500 staff) being asked to get entire org SOC2 compliant. Zero experience with compliance. Is this reasonable?
Title more or less says it all. I have no idea what this process looks like / what is the required, and there are talks of getting the org compliant with other organizations as well. Quick Google search seems to make this out to be a big and difficult project that can takes months or years. Pretty sure I'm in over my head, but management ain't listening.