I've worked with multiple organizations through their entire SOC2 process and interviewed security teams from a bunch of other SOC2'd companies and the impression I'm left with is that you can get 100% of SOC2 just doing obvious best practices. Part of the reason I wrote this is to encourage engineering teams to push back on SOC2 processes that demand them to do new weird things.
I have kind of a meh opinion about Vanta, for what it's worth.