Skipping Pull Requests Isn't Un-SOC 2 Compliant

"That's not SoC 2 compliant"

Skipping Pull Requests Isn't Un-SOC 2 Compliant

Amp, a 20-person engineering team, ships continuously by pushing directly to main, skipping pull requests entirely. When pursuing SOC 2, they discovered the framework doesn't mandate PRs—it requires managing risks. They worked with auditors to design controls like restricted push access, signed commits, automated CI, and a detailed audit trail. This approach scales not by size but by risk assessment, challenging the assumption that PRs are essential for compliance.

SOC 2 doesn't require pull requests. It requires that you think about your risks.

More from this day

2026-08-15