Platform Intelligence~8 min readLast reviewed July 2026

Migrating off Delve: what to verify and re-certify

If you're re-evaluating your compliance platform after the March 2026 reporting on Delve, this is a practical guide to what re-certification actually involves. It does not argue that you should leave. Several companies have publicly done so - Lovable, LiteLLM, and Context AI, per TechCrunch (March–April 2026), with Context AI re-certifying on Vanta with Insight Assurance - and Delve disputes the underlying allegations. If you are in that re-evaluation, here is what carries over, what doesn't, and how to verify any platform's output, including whichever one you move to next. GRC Migrate is independent and takes no vendor commissions.

What transfers - and what doesn't

Your existing report stays valid; a new one is a fresh engagement. A SOC 2 report is a document your auditor issued for a defined period. Changing the platform that collects your evidence does not invalidate a report already issued, and it does not automatically produce a new one - a platform never issues your SOC 2; an auditor does. So your next report comes from an auditor engagement, and if leaving Delve also means leaving the audit arrangement it provided, that engagement is with a new firm. A prior attestation from one auditor does not transfer to another.

Type I vs Type II changes the clock. A Type I opinion covers the design of your controls at a point in time and can be issued relatively quickly. A Type II covers operating effectiveness over a period - commonly three to twelve months - so a fresh Type II restarts that observation window. A new auditor may accept a shorter bridge period depending on your control history, but that is their judgment to make, not a setting you choose. Plan your re-certification around the report type your customers actually require.

The verification checklist - for any platform's output

Whatever prompted the re-evaluation, these checks protect you on the platform you leave and the one you adopt. None of them require trusting a vendor's marketing:

  • Spot-check 5–10 controls against reality. Pick specific controls and confirm the evidence matches what's actually configured in your systems - not what a dashboard asserts.
  • Confirm the auditor designed their own test procedures. The audit firm should define how controls are tested, not receive pre-drafted conclusions from the platform.
  • Verify the audit firm's AICPA accreditation and independence. Look up the CPA license yourself, and confirm the firm has no economic tie to your platform. The AI-native platforms guide lays out the auditor-independence spectrum in full - a disclosed bundle is a different thing from an undisclosed routing.
  • Compare your trust page to what's implemented. Whatever your public trust page claims is live should actually be live. This is worth doing regardless of platform.

Evidence portability: export before you switch

Before your access to any platform ends, export what you own: policies (as PDFs), uploaded evidence files, vendor and personnel records, and your audit trail and change logs. Delve has stated that customers own their codebases and security operations, so the underlying controls and systems are yours regardless of platform - but the record of them inside a platform is only exportable while you still have access. The mechanics are the same as any platform switch; the guide to what happens to your compliance data and the step-by-step migration guide cover the export-before-decommission discipline in detail.

What a new auditor accepts is a question, not a given. Documents you own generally travel and can support the new engagement; automated test history and continuous-monitoring records typically do not carry, because the new platform starts accumulating from your connection date. Auditors vary in what prior-platform evidence they'll rely on - the safe assumption is that a new auditor evaluates your controls independently rather than inheriting another platform's conclusions, which is exactly the independence you want.

Timeline and cost, realistically

Re-certification has three cost components: a new audit engagement, your new platform subscription, and the migration labor. Audit fees vary widely by firm size and scope, so model your own numbers rather than trusting a single figure - the SOC 2 cost guide covers the ranges and what drives them. On timeline, the audit is the long pole, not the platform move: a Type I is faster; a Type II is gated by its observation window. The platform migration itself is usually measured in weeks, not months - the migration assessment gives a complexity score for your specific situation.

Finding an independent auditor

Re-certification requires an independent auditor, and the cleanest way to satisfy the independence checks above is to select the audit firm yourself. GRC Migrate's directory lists audit and readiness firms by framework, from public sources, with no firm paying to be listed - so you can find an AICPA-accredited firm with no economic tie to your platform. That is the one place this page points you; everything else here is verification you do yourself.

Re-evaluating and want an independent read on the re-certification path?

A free 30-minute consultation maps your exact situation - what data moves, what doesn't, whether your timeline is viable, and what the switch will actually cost in time and disruption.

Independent advice. Not affiliated with any platform vendor.

Book Free Call