top of page

SOC 2 Report: What It Is, How to Read One, and Who Needs It

Nav
7 minutes ago
8 min read

A SOC 2 report is an independent attestation, issued by a licensed CPA firm, that describes a service provider's systems and tests whether its controls meet the AICPA's Trust Services Criteria: security, plus optionally availability, processing integrity, confidentiality, and privacy. A Type 1 report checks control design at one point in time. A Type 2 report tests how those controls actually worked over a period, usually 3 to 12 months.


soc 2 report

Before I started NSOCIT, I spent years at an MSP wearing the sales hat as often as the technical one. That's where I learned that one line in a security questionnaire can stall a deal for weeks: "Please provide your most recent SOC 2 report." Sending back a nice PDF about your firewall does not count. Buyers do not find it charming.


If you sell services to bigger companies, that question is coming for you too. And if you buy software or IT services, you should be asking it yourself.


TL;DR: A SOC 2 report is a CPA's opinion on whether a vendor's security controls are designed well (Type 1) and actually work over time (Type 2). Ask vendors for a Type 2. Read the exceptions and the "complementary user entity controls," not just the opinion page. And remember the report proves a process was followed, not that a breach can't happen.


Auditor reviewing evidence for a SOC 2 report

What a SOC 2 Report Actually Is


SOC stands for System and Organization Controls. The AICPA, the body that sets standards for CPAs, created the framework. A SOC 2 report focuses on controls at a service organization that are relevant to how it protects customer data.


Three things make it different from a sales deck:


  • It's independent. Only a licensed CPA firm can issue it.

  • It's tested. The auditor checks evidence, samples records, and notes failures.

  • It's restricted. It's meant for customers and prospects, usually shared under an NDA, not posted on a website.


The companies that most often need one are SaaS providers, data centers, payroll and HR platforms, payment processors, and managed service providers. Anyone who stores, processes, or has access to someone else's data is a candidate.


Data center representing the security and availability criteria in a SOC 2 report

The Five Trust Services Criteria


SOC 2 reports are built around five categories. Only one is required.


  • Security (required). Protection against unauthorized access. This is also called the "common criteria" and covers access control, change management, monitoring, risk assessment, and incident response.

  • Availability. Systems are up and usable as promised. Common for hosting and SaaS providers with uptime commitments.

  • Processing integrity. Systems process data completely, accurately, and on time. Common for payroll and transaction processors.

  • Confidentiality. Information marked confidential is protected through its lifecycle.

  • Privacy. Personal information is collected, used, and disposed of according to the company's privacy notice.


When you review a vendor's SOC 2 report, check which criteria are in scope. A cloud backup company whose report covers only security, and not availability, hasn't been tested on whether your backups are actually there when you need them.


Calendar representing the review period in a SOC 2 Type 2 report

SOC 2 Type 1 vs Type 2


This is the question everyone asks first.


  • Type 1 looks at whether controls are designed properly as of a specific date. It's a snapshot. Think of it as checking that the smoke detectors are installed.

  • Type 2 tests whether those controls actually operated effectively over a review period, typically 3 to 12 months. Think of it as checking that the smoke detectors went off every time there was smoke.


A SOC 2 Type 2 is what most enterprise customers want. A Type 1 is often a first step for a company that's new to the process. If a vendor has been around for years and only offers a Type 1, ask why.


Bundled documents representing the difference between SOC 1 and SOC 2 reports

SOC 1 vs SOC 2 vs SOC 3


  • SOC 1 covers controls relevant to a customer's financial reporting. Your auditors care about this one if a vendor processes your payroll or billing.

  • SOC 2 covers security and the other trust criteria. Your IT and security people care about this one.

  • SOC 3 is a short, public summary of a SOC 2. It's marketing-friendly but has none of the testing detail.


A SOC 2 does not replace a SOC 1. They answer different questions.


Pages of an audit report showing what is inside a SOC 2 report

What's Inside a SOC 2 Report


A typical report has five sections. Here's what each one is for and what to look at.


  1. The auditor's opinion. The CPA firm's conclusion. "Unqualified" means clean. "Qualified" means the auditor found problems significant enough to call out. Read this page first.

  2. Management's assertion. The vendor's own statement that the description is accurate and controls are effective.

  3. The system description. What's in scope: services, infrastructure, software, people, data, and processes. This is where you confirm the service you actually use is covered.

  4. Controls and test results. The long part. Each control, how the auditor tested it, and the result. Look for the word "exception."

  5. Other information. Sometimes includes the vendor's responses to exceptions.


Business owner reading a vendor SOC 2 report for exceptions

How to Read a Vendor's SOC 2 Report in 15 Minutes


Most business owners receive these and file them unread. Here's the short version I use.


  1. Check the dates. When did the review period end? A report that ended 14 months ago is stale. Ask for a bridge letter, which is the vendor's statement that nothing material has changed since.

  2. Check the scope. Is the product you buy in the system description? Are the data centers they use listed as "carved out" (excluded and covered by someone else's report)?

  3. Read the opinion. Unqualified is what you want.

  4. Search for "exception." One or two minor exceptions with good explanations are normal. A pattern of failed access reviews or missing background checks is not.

  5. Read the complementary user entity controls. These are the things the vendor expects you to do, like turning on MFA or removing ex-employees. If you don't do them, the vendor's controls don't fully protect you.


That last one surprises people. A SOC 2 report is partly a list of homework assigned to you.


Checklist for getting a SOC 2 report, from readiness to audit

How to Get a SOC 2 Report for Your Company


If customers are asking you for one, the path usually looks like this:


  1. Define the scope. Which services, systems, and trust criteria. Start with security only unless customers require more.

  2. Do a readiness assessment. Find your gaps before the auditor does.

  3. Fix the gaps. Usually MFA, access reviews, logging, change management, vendor management, written policies, and incident response.

  4. Pick a CPA firm. Only licensed CPA firms can issue SOC 2 reports.

  5. Get a Type 1 if you need something quickly.

  6. Run your review period for a Type 2, collecting evidence the whole time.

  7. Receive the report and share it with customers under NDA.

  8. Repeat every year.


Most of the technical controls overlap with good IT practice anyway. Our cybersecurity compliance audit is a practical readiness check, and vulnerability management covers the scanning and patching evidence auditors ask for.


Hourglass representing SOC 2 audit timelines and cost drivers

How Long a SOC 2 Takes and What Drives the Cost


There's no single price tag, and anyone who quotes one without asking questions is guessing. What actually drives time and cost:


  • Scope. Security only is smaller than security plus availability, confidentiality, and privacy.

  • Readiness. If you already have MFA, access reviews, logging, and written policies, the audit is mostly evidence collection. If you don't, the fixing takes longer than the audit.

  • Report type. A Type 1 can be done once controls are in place. A Type 2 needs a review period of 3 to 12 months on top of that.

  • Company size and complexity. More systems, locations, and vendors mean more testing.

  • Tools. Compliance automation platforms can help collect evidence. They can't replace the auditor's judgment, which is exactly what the AICPA is now warning about below.


A realistic first-year plan: a few months of readiness work, a Type 1 to unblock deals, then a Type 2 review period. After that, it becomes an annual rhythm.


Approval stamp representing fast, templated SOC 2 reports

A Fast, Cheap SOC 2 Is a Warning Sign


Here's my one strong opinion. A SOC 2 report is a compliance badge, and a compliance badge is not the same thing as being secure.


That's not just me being cynical. The AICPA itself is worried. In May 2026, the Journal of Accountancy reported that the AICPA's Peer Review Board told reviewers to look harder at SOC 2 engagements, including "high-volume providers using third-party platforms."


Carl Mayes, the AICPA's vice president of ethics and firm quality, said: "Some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards."


The article describes engagements "that have identical reports, risk assessments, sample sizes, and testing procedures" and says those aren't performed in accordance with professional standards.


Translation for business owners: when a vendor brags about getting SOC 2 "in two weeks," be skeptical. And if you're getting your own, a cheap, templated report may not survive a serious customer's review. The goal is controls that actually work. The report is just the proof.


IT technician whose managed service provider should share its SOC 2 report

Ask Your IT Provider for Theirs Too


Your managed service provider usually has admin access to everything you own. That makes them one of your highest-risk vendors.


Ask them for a SOC 2 report or equivalent security documentation. Ask how they protect their own remote management tools, how they handle MFA for their technicians, and what happens to your access if you leave. A good provider will answer without flinching. If you'd like help reviewing a vendor's report, managed cybersecurity services often include that kind of vendor review.


Small business owner who may not need a SOC 2 report yet

When You Don't Need a SOC 2 Report


  • Nobody's asking. If your customers don't require one, start with the controls, not the audit.

  • You don't handle customer data. A local retailer or a consulting firm without data access usually doesn't need one.

  • A questionnaire is enough. Many smaller customers will accept a completed security questionnaire and a policy pack.


Where a SOC 2 report pays off: you sell to enterprises, healthcare, finance, or government contractors, and your deals are stalling on security reviews.


Business owner thinking through common SOC 2 report questions

Straight Answers About SOC 2 Reports


Who needs a SOC 2 report?


Service providers that store, process, or access customer data, such as SaaS companies, data centers, payroll providers, and managed service providers, especially when customers require one.


Who can issue a SOC 2 report?


Only a licensed CPA firm can issue a SOC 2 report under AICPA standards.


Are SOC 2 reports public?


No. SOC 2 reports are restricted-use documents, usually shared with customers and prospects under an NDA. A SOC 3 report is the public summary version.


How long is a SOC 2 report valid?


There's no official expiry, but most customers expect a report covering a period that ended within the last 12 months. Vendors use bridge letters to cover the gap until the next report.


What is the difference between SOC 2 Type 1 and Type 2?


Type 1 evaluates whether controls are designed properly at a point in time. Type 2 tests whether they operated effectively over a review period, usually 3 to 12 months.


What are SOC 2 controls?


SOC 2 controls are the policies, procedures, and technical safeguards a company uses to meet the Trust Services Criteria, such as MFA, access reviews, change management, logging, vendor management, backups, and incident response.


What is a SOC 2 bridge letter?


A bridge letter is a statement from the service provider covering the gap between the end of its last SOC 2 review period and the next report, saying no material changes to its controls have occurred.


Does SOC 2 replace SOC 1?


No. SOC 1 covers controls relevant to financial reporting. SOC 2 covers security and the other trust services criteria.


Business owner calling NSOCIT about SOC 2 readiness

Still Stuck? Give Us a Call


If a customer just asked for your SOC 2 report and your first reaction was "our what," give us a call at 410-703-3857 or send us a note. We help companies across the DMV, including Tysons and the rest of Northern Virginia, get the controls in place before the auditor shows up.


We'll start with what's real. The nice PDF about your firewall can stay in the drawer.


Comments


bottom of page