Skip to main content

SOC 2

How to read a SOC 2 report in 20 minutes

Type I versus Type II, the period, the opinion, carve-outs, complementary user entity controls and exceptions: what a buyer actually needs from the report.

Last updated 17 Sep 2026

A SOC 2 report is long because it is written for auditors. A buyer needs five things from it, and they are in predictable places.

1. The opinion

Section 1 is the auditor’s opinion. Read the first two pages: is it unqualified, qualified or adverse? A qualified opinion names the criteria where controls did not operate effectively. Note the CPA firm; CertReports links firms to their auditor pages.

2. Type and period

Type I covers design at a point in time. Type II covers design and operating effectiveness over a period, usually six to twelve months. Check the period end date. If it is more than three months old, ask for a bridge letter, which is a management representation rather than an auditor opinion.

3. Trust services criteria in scope

Security is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are optional. A report without Availability says nothing about uptime commitments; a report without Confidentiality says nothing about how your data is segregated.

4. System description and carve-outs

Section 3 describes the system and lists subservice organisations (for example the cloud provider) and whether their controls are carved out or included. Carve-outs mean the vendor relies on someone else’s report; ask for it or check that provider’s CertReports page.

5. Exceptions and complementary user entity controls

Section 4 lists every control tested and any exceptions. Read the exceptions, not the passes. The complementary user entity controls are the things you must do (for example manage your own users) for the vendor’s controls to work.

CertReports never hosts the report. It records the public facts (type, period, auditor, scope) with a date and a source, and deep-links to the vendor’s request flow.