SOC 2

How do I read a SOC 2 report?

A SOC 2 report has a few key parts: the independent auditor’s opinion, management’s assertion, the system description, and the tests of controls with their results. When you review a vendor’s report, check the report type and period, which Trust Services Criteria are in scope, whether the auditor’s opinion is unqualified, and any exceptions noted in the test results.

The sections of the report

Most SOC 2 reports contain the independent auditor’s opinion, a management assertion, a description of the system and its controls, and (for Type II) the auditor’s tests of those controls and the results.

What to check on a vendor’s report

Confirm the report type (Type I or II) and the period it covers, which Trust Services Criteria are in scope (Security is always there; others are added as they fit), whether the opinion is unqualified, any exceptions in the test results, and the complementary user-entity controls you are expected to implement on your side.

Red flags

A qualified opinion, a report period that ended long ago, or a scope that omits criteria you care about are all worth a closer look and a conversation with the vendor.

FAQ

What is an unqualified opinion?

It is the auditor’s clean opinion that controls were suitably designed and, for a Type II, operated effectively over the period. A qualified opinion means the auditor found an issue worth flagging.

What are exceptions?

Exceptions are instances where a control did not operate as intended during the period. A few minor exceptions are common; read management’s response and judge the impact.

Related

What is SOC 2? → SOC 2 Type I vs Type II → What is a SOC 2 bridge letter? →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free