Guide

SOC 2 Reports Explained: What Compliance Teams Need to Know

A SOC 2 report is an independent auditor's assessment of a service organization's controls against the AICPA Trust Service Criteria. It is the most requested security attestation in enterprise SaaS procurement and the primary evidence artifact in most vendor risk programs. Reading a SOC 2 report effectively — understanding what the exceptions mean, how old the evidence is, and what the scope boundaries are — is a core TPRM skill.

What is in a SOC 2 report?

A SOC 2 report has five sections. Section I is management’s description of the system — the service organization’s own description of what they do and what controls they operate. Section II is the auditor’s opinion on that description. Section III contains the criteria and management’s assessment of each. Section IV (Type II only) is the auditor’s tests of controls and results. Section V contains additional information. For vendor risk purposes, Section IV is where the work lives: it lists every control tested, the test procedure, and whether any exceptions were found.

What does a SOC 2 exception mean?

An exception means the auditor observed an instance where a control did not operate as designed during the audit period. Not all exceptions are equal. A single instance of a user account not being deprovisioned within the policy timeframe is very different from recurring failures in a vendor’s patch management process. To evaluate an exception, look for: (1) how many instances were found relative to the test population; (2) whether the exception relates to a criterion relevant to your data; (3) whether management’s response explains a root cause and remediation; and (4) whether the same exception appeared in prior reports.

What is the scope of a SOC 2 report?

SOC 2 reports are scoped to specific criteria (security is always included; availability, processing integrity, confidentiality, and privacy are optional) and specific systems. A vendor with multiple products may have a SOC 2 that covers only one of them. A vendor who acquired a company may not have integrated the acquisition into scope. The system description in Section I tells you what is included. Anything outside scope requires separate assessment.

How do you evaluate a SOC 2 report’s freshness?

SOC 2 Type II reports cover a specific audit period — typically the twelve months ending on the report date. A report dated March 2024 covering April 2023 through March 2024 tells you about controls as they operated in that period, not today. TrustVendor’s assurance score weights SOC 2 evidence by its age: a report dated within three months is fresher than one dated fourteen months ago, and the decay is shown explicitly rather than hidden behind a static rating.

Common questions

Can I share a vendor's SOC 2 report with others?
Most SOC 2 reports are shared under NDA and include a restriction on redistribution. Check the report's use restriction section — typically in the transmittal letter — before sharing it with a third party.
What is a bridge letter?
A bridge letter (also called a comfort letter) is a document a vendor provides to cover the gap between the end of their last SOC 2 audit period and today. It is management's assertion that no material changes to their control environment occurred during the gap. It is not audited and carries less assurance than the report itself.
Does a SOC 2 Type I satisfy vendor due diligence requirements?
For most compliance frameworks, a Type I is a starting point, not a final answer. It demonstrates controls are designed appropriately but not that they operate effectively. Enterprise procurement and legal teams increasingly require a Type II with a recent audit period.

Related guides

What Is Third-Party Risk Management (TPRM)?Evidence Decay: Why Freshness Is a First-Class Risk ConceptHash-Verifiable Evidence: Making Vendor Claims Auditable

Put evidence behind every vendor claim.

TrustVendor automates the evidence collection this guide describes.

Book a demo