A SOC 2 report is long because it is written for auditors, not for the person deciding whether to sign a contract. A typical Type II runs 60 to 120 pages and most of it is a control matrix. A buyer needs five things from it, and they sit in predictable places. This guide gives the reading order that answers the risk question fastest, the traps that cost reviewers the most time, and the questions to send back when something is missing.
- 70 to 85%
- of enterprise B2B RFPs require a SOC 2 report
- Agency, SOC 2 compliance statistics 2026
- 10 to 40 hours
- to complete one security questionnaire by hand
- HyperComply and Steerlab estimates, 2025
- 45
- vendors with public SOC 2 evidence in the CertReports index
- Captured from trust centres, 18 September 2026
What a SOC 2 report is, and what it is not
SOC 2 is an attestation engagement performed by a licensed CPA firm under the AICPA attestation standards. The vendor writes a description of its system and asserts that its controls meet the Trust Services Criteria; the auditor examines that description and those controls and issues an opinion. Nothing in the process issues a certificate or a pass mark. A report can carry an unqualified opinion, a qualified one or an adverse one, and two vendors with the same badge on their websites can differ by report type, period, criteria in scope, carve-outs and exceptions.
A SOC 2 report is a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.
The report is restricted-use, addressed to the vendor and its customers, and normally shared under NDA. CertReports never hosts it. The index records the public facts (report type, period end, auditor, criteria) with a date and a snapshot, which is enough to decide whether to request the document at all. The SOC 2 hub lists every vendor with public evidence.
The five sections and what each one is for
| Section | Written by | What it contains | Minutes to spend |
|---|---|---|---|
| 1. Independent service auditor’s report | The CPA firm | The opinion, the period, the criteria, subservice organisations and their treatment | 3 |
| 2. Management’s assertion | The vendor | The claim the auditor tested, with the criteria and the system name | 2 |
| 3. System description | The vendor | Infrastructure, software, people, procedures, data; carve-outs; complementary user entity controls | 6 |
| 4. Tests of controls and results | The CPA firm | Every control, the test performed, the sample, the result and any exception | 6 |
| 5. Other information | The vendor | Management responses to exceptions, unaudited | 3 |
Twenty minutes is enough if you read in this order and skip the passes.
Step 1: the opinion
Section 1 is the auditor’s letter and its first two pages carry the only sentence a non-specialist must read: whether the opinion is unqualified, qualified or adverse. An unqualified opinion says the description is fairly presented and the controls were suitably designed (Type I) or suitably designed and operating effectively (Type II). A qualified opinion names the criteria where that was not true; read that paragraph twice. An adverse opinion is rare and disqualifying for any sensitive use.
Note the firm. Large national firms and specialist SOC firms both produce sound reports; what matters is that the firm is a licensed CPA firm and that the same firm signs the report you receive. CertReports links firms to their auditor pages so you can see how many public engagements they carry.
Step 2: Type and period
Type I covers the design of controls at a single date. Type II covers design and operating effectiveness over a period, usually six to twelve months, with sampled evidence. For any vendor that stores or processes your data, Type II is the bar. The Type I versus Type II article covers when the weaker report is acceptable.
Check the period end date against today. If it is more than three months old, ask for a bridge letter; if it is more than twelve months old, ask when the next report is due. A bridge letter is a management representation, not an auditor opinion, and industry practice caps it at about 90 days (see what a bridge letter is).
Step 3: Trust Services Criteria in scope
Security (the common criteria) is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional and many reports include only Security. A report without Availability says nothing about uptime commitments; a report without Confidentiality says nothing about how your data is segregated from other customers; a report without Privacy says nothing about personal data handling. Match the criteria to what you are buying.
| Criterion | What it covers | Ask for it when |
|---|---|---|
| Security | Access, change management, risk, monitoring, incident response | Always; it is mandatory |
| Availability | Capacity, backup, recovery, SLA support | The service is on your critical path |
| Processing Integrity | Completeness, accuracy and timeliness of processing | The vendor computes, bills or transforms your data |
| Confidentiality | Classification, segregation, retention and disposal | The vendor holds anything you would not publish |
| Privacy | Notice, choice, collection, use, retention and disposal of personal data | The vendor processes personal data on your behalf |
Step 4: the system description and carve-outs
Section 3 names the products and infrastructure in scope. Confirm the product you are buying is named; a report that covers "the platform" may exclude a newly acquired product line. It also names subservice organisations, usually the cloud provider, and states whether their controls are carved out or included. A carve-out means the vendor relies on someone else’s report for those controls. Ask for that report or check the provider’s CertReports page.
Complementary user entity controls
The system description lists the controls you must operate for the vendor’s controls to work: managing your own users, enforcing MFA on your side, reviewing access reports, configuring retention. The auditor does not test these. Assign an owner for each one before go-live; an unowned CUEC is a gap in your own control environment, not the vendor’s.
Step 5: exceptions, not passes
Section 4 lists every control tested and the result. Read the exceptions before the passes. A report with two exceptions on quarterly access reviews and a clear management response tells you more than a spotless one you cannot tell anything from. The questions to ask about each exception: what failed, how many samples out of how many, whether the same control failed in last year’s report, and what management says in section 5.
The 20-minute reading plan
- 1
Minutes 0 to 3: section 1
Which firm, which opinion, which period, which criteria, which subservice organisations and how they are treated.
- 2
Minutes 3 to 5: section 2
Confirm the assertion names the same system and criteria as the opinion.
- 3
Minutes 5 to 11: section 3
Products in scope, carve-outs, and the complementary user entity controls. Write down every CUEC.
- 4
Minutes 11 to 17: section 4, exceptions only
What failed, how often, and whether it failed last year too.
- 5
Minutes 17 to 20: section 5
Management responses. A response that names a fix and a date is credible; one that disputes the finding is a follow-up.
Red flags that take seconds to spot
- A period end more than 12 months ago and no bridge letter.
- Security-only scope for a product that stores your customer data.
- A carve-out of the very component you depend on, with no reference to the subservice report.
- Exceptions with no management response, or the same exception in two consecutive reports.
- A report that names a different legal entity or product than the one on the order form.
- A "readiness assessment" or "SOC 2 gap report" from a consultancy presented as a SOC 2 report; only a CPA firm issues the opinion.
What to send back
| What you found | What to ask |
|---|---|
| Period end older than 3 months | Please send a bridge letter dated after the period end and the expected date of the next report. |
| Security-only criteria | Please confirm whether Availability and Confidentiality will be in scope next period. |
| Carve-out of the data platform | Please share the subservice organisation’s report or its CertReports page. |
| Repeated exception | What changed since last year’s exception on this control? |
| Product not named | Please confirm in writing that the product on our order form is within the described system. |
Never "SOC 2 certified"
There is no certificate and no pass mark. If a vendor writes "SOC 2 certified", treat it as marketing shorthand and ask for the report type, the period end date, the criteria and the firm.
People also ask
How long does it take to read a SOC 2 report?
Twenty minutes if you read sections 1, 3 and 4 in that order and skip the passing controls. A full read of a 100-page Type II with all five criteria takes two to three hours and is rarely necessary for a buyer.
What is the most important section of a SOC 2 report?
Section 1, the auditor’s opinion, because it states the type, the period, the criteria and the treatment of subservice organisations in two pages. Section 4 is second, because the exceptions are where the risk lives.
What are complementary user entity controls?
Controls the customer must operate for the vendor’s controls to be effective, such as managing its own user accounts and reviewing access. They are listed in the system description and are not tested by the auditor.
What does a qualified opinion mean in a SOC 2 report?
The auditor found that the description or the controls did not meet the criteria in one or more respects and names them. It is not automatically disqualifying, but every qualification needs a management response and a fix date.
Is a SOC 2 report public?
No. It is a restricted-use document shared under NDA. What is usually public is the report type, period and auditor on a trust centre, which is what CertReports records.
How current does a SOC 2 report need to be?
Most buyers accept a report whose period ended within the last twelve months, with a bridge letter covering the gap after three months. Older than twelve months, ask for the next report’s date.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
SOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read
What is a bridge letter, and how much should a buyer trust one?
Solomon Amos · 12 Sep 2026 · 9 min read