Your SOC2 audit window opens in three months. Your DMARC policy is p=none. Your auditor is going to flag it.

Not because p=none is wrong as a starting point — it's the standard way to begin DMARC rollout. But p=none at the start of a SOC2 audit period means that for the entire months it was in place, you had zero enforcement on a logical access...