Skip to main content

How-to

How to read a SOC 2 report in 20 minutes

A section-by-section reading order for buyers: the opinion, Type and period, criteria in scope, carve-outs, exceptions and the controls you must run yourself.

Solomon AmosPublished 11 Sep 2026Updated 18 Sep 202611 min read

A desk with printed reports, a pen and a laptop
Photo by Helloquence on Unsplash

A SOC 2 report is long because it is written for auditors, not for the person deciding whether to sign a contract. A typical Type II runs 60 to 120 pages and most of it is a control matrix. A buyer needs five things from it, and they sit in predictable places. This guide gives the reading order that answers the risk question fastest, the traps that cost reviewers the most time, and the questions to send back when something is missing.

70 to 85%
of enterprise B2B RFPs require a SOC 2 report
Agency, SOC 2 compliance statistics 2026
10 to 40 hours
to complete one security questionnaire by hand
HyperComply and Steerlab estimates, 2025
45
vendors with public SOC 2 evidence in the CertReports index
Captured from trust centres, 18 September 2026

What a SOC 2 report is, and what it is not

SOC 2 is an attestation engagement performed by a licensed CPA firm under the AICPA attestation standards. The vendor writes a description of its system and asserts that its controls meet the Trust Services Criteria; the auditor examines that description and those controls and issues an opinion. Nothing in the process issues a certificate or a pass mark. A report can carry an unqualified opinion, a qualified one or an adverse one, and two vendors with the same badge on their websites can differ by report type, period, criteria in scope, carve-outs and exceptions.

A SOC 2 report is a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.

The report is restricted-use, addressed to the vendor and its customers, and normally shared under NDA. CertReports never hosts it. The index records the public facts (report type, period end, auditor, criteria) with a date and a snapshot, which is enough to decide whether to request the document at all. The SOC 2 hub lists every vendor with public evidence.

The five sections and what each one is for

SectionWritten byWhat it containsMinutes to spend
1. Independent service auditor’s reportThe CPA firmThe opinion, the period, the criteria, subservice organisations and their treatment3
2. Management’s assertionThe vendorThe claim the auditor tested, with the criteria and the system name2
3. System descriptionThe vendorInfrastructure, software, people, procedures, data; carve-outs; complementary user entity controls6
4. Tests of controls and resultsThe CPA firmEvery control, the test performed, the sample, the result and any exception6
5. Other informationThe vendorManagement responses to exceptions, unaudited3

Twenty minutes is enough if you read in this order and skip the passes.

Hands signing a printed document with a fountain pen
The opinion letter is signed by the CPA firm; everything in sections 2, 3 and 5 is written by the vendor. · Photo by Scott Graham on Unsplash

Step 1: the opinion

Section 1 is the auditor’s letter and its first two pages carry the only sentence a non-specialist must read: whether the opinion is unqualified, qualified or adverse. An unqualified opinion says the description is fairly presented and the controls were suitably designed (Type I) or suitably designed and operating effectively (Type II). A qualified opinion names the criteria where that was not true; read that paragraph twice. An adverse opinion is rare and disqualifying for any sensitive use.

Note the firm. Large national firms and specialist SOC firms both produce sound reports; what matters is that the firm is a licensed CPA firm and that the same firm signs the report you receive. CertReports links firms to their auditor pages so you can see how many public engagements they carry.

Step 2: Type and period

Type I covers the design of controls at a single date. Type II covers design and operating effectiveness over a period, usually six to twelve months, with sampled evidence. For any vendor that stores or processes your data, Type II is the bar. The Type I versus Type II article covers when the weaker report is acceptable.

Check the period end date against today. If it is more than three months old, ask for a bridge letter; if it is more than twelve months old, ask when the next report is due. A bridge letter is a management representation, not an auditor opinion, and industry practice caps it at about 90 days (see what a bridge letter is).

Step 3: Trust Services Criteria in scope

Security (the common criteria) is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional and many reports include only Security. A report without Availability says nothing about uptime commitments; a report without Confidentiality says nothing about how your data is segregated from other customers; a report without Privacy says nothing about personal data handling. Match the criteria to what you are buying.

CriterionWhat it coversAsk for it when
SecurityAccess, change management, risk, monitoring, incident responseAlways; it is mandatory
AvailabilityCapacity, backup, recovery, SLA supportThe service is on your critical path
Processing IntegrityCompleteness, accuracy and timeliness of processingThe vendor computes, bills or transforms your data
ConfidentialityClassification, segregation, retention and disposalThe vendor holds anything you would not publish
PrivacyNotice, choice, collection, use, retention and disposal of personal dataThe vendor processes personal data on your behalf

Step 4: the system description and carve-outs

Section 3 names the products and infrastructure in scope. Confirm the product you are buying is named; a report that covers "the platform" may exclude a newly acquired product line. It also names subservice organisations, usually the cloud provider, and states whether their controls are carved out or included. A carve-out means the vendor relies on someone else’s report for those controls. Ask for that report or check the provider’s CertReports page.

Complementary user entity controls

The system description lists the controls you must operate for the vendor’s controls to work: managing your own users, enforcing MFA on your side, reviewing access reports, configuring retention. The auditor does not test these. Assign an owner for each one before go-live; an unowned CUEC is a gap in your own control environment, not the vendor’s.

Step 5: exceptions, not passes

Section 4 lists every control tested and the result. Read the exceptions before the passes. A report with two exceptions on quarterly access reviews and a clear management response tells you more than a spotless one you cannot tell anything from. The questions to ask about each exception: what failed, how many samples out of how many, whether the same control failed in last year’s report, and what management says in section 5.

A laptop showing an analytics dashboard with charts
Section 4 is a table of tests and results. Filter it to the exceptions and you have the risk conversation. · Photo by Luke Chesser on Unsplash

The 20-minute reading plan

  1. 1

    Minutes 0 to 3: section 1

    Which firm, which opinion, which period, which criteria, which subservice organisations and how they are treated.

  2. 2

    Minutes 3 to 5: section 2

    Confirm the assertion names the same system and criteria as the opinion.

  3. 3

    Minutes 5 to 11: section 3

    Products in scope, carve-outs, and the complementary user entity controls. Write down every CUEC.

  4. 4

    Minutes 11 to 17: section 4, exceptions only

    What failed, how often, and whether it failed last year too.

  5. 5

    Minutes 17 to 20: section 5

    Management responses. A response that names a fix and a date is credible; one that disputes the finding is a follow-up.

Red flags that take seconds to spot

  • A period end more than 12 months ago and no bridge letter.
  • Security-only scope for a product that stores your customer data.
  • A carve-out of the very component you depend on, with no reference to the subservice report.
  • Exceptions with no management response, or the same exception in two consecutive reports.
  • A report that names a different legal entity or product than the one on the order form.
  • A "readiness assessment" or "SOC 2 gap report" from a consultancy presented as a SOC 2 report; only a CPA firm issues the opinion.

What to send back

What you foundWhat to ask
Period end older than 3 monthsPlease send a bridge letter dated after the period end and the expected date of the next report.
Security-only criteriaPlease confirm whether Availability and Confidentiality will be in scope next period.
Carve-out of the data platformPlease share the subservice organisation’s report or its CertReports page.
Repeated exceptionWhat changed since last year’s exception on this control?
Product not namedPlease confirm in writing that the product on our order form is within the described system.

Never "SOC 2 certified"

There is no certificate and no pass mark. If a vendor writes "SOC 2 certified", treat it as marketing shorthand and ask for the report type, the period end date, the criteria and the firm.

People also ask

How long does it take to read a SOC 2 report?

Twenty minutes if you read sections 1, 3 and 4 in that order and skip the passing controls. A full read of a 100-page Type II with all five criteria takes two to three hours and is rarely necessary for a buyer.

What is the most important section of a SOC 2 report?

Section 1, the auditor’s opinion, because it states the type, the period, the criteria and the treatment of subservice organisations in two pages. Section 4 is second, because the exceptions are where the risk lives.

What are complementary user entity controls?

Controls the customer must operate for the vendor’s controls to be effective, such as managing its own user accounts and reviewing access. They are listed in the system description and are not tested by the auditor.

What does a qualified opinion mean in a SOC 2 report?

The auditor found that the description or the controls did not meet the criteria in one or more respects and names them. It is not automatically disqualifying, but every qualification needs a management response and a fix date.

Is a SOC 2 report public?

No. It is a restricted-use document shared under NDA. What is usually public is the report type, period and auditor on a trust centre, which is what CertReports records.

How current does a SOC 2 report need to be?

Most buyers accept a report whose period ended within the last twelve months, with a bridge letter covering the gap after three months. Older than twelve months, ask for the next report’s date.

SOC 2vendor reviewattestationAICPACUEC
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like