A SOC 2 report is a long document with a small number of load-bearing parts. If you have twenty minutes and a vendor’s report in front of you, read the opinion paragraph, the period or date it covers, the scope statement in the system description, and every exception in the testing matrix. That gets you most of the value. Everything else in this piece is about how to read a SOC 2 report when those four things raise a question.

The rest of this post explains what each section is for, so you can do that quickly and know what you are looking at. The same map helps if the report is your own and you are reading it for the first time before sending it to a customer.

The five sections and what they are worth

Reports are conventionally organised into five sections, though firms vary slightly in ordering and labelling.

Section I — Independent service auditor’s report. The opinion. Written and signed by the CPA firm. This is the only part of the report the auditor is asserting.

Section II — Management’s assertion. The service organization’s own written statement that its description is accurate and its controls were suitably designed (and, in a Type 2, operated effectively). This is what the auditor is opining on.

Section III — Description of the system. Written by management. Covers the services provided, infrastructure, software, people, procedures and data, plus the controls in place. This is where scope lives.

Section IV — Trust services criteria, controls, tests and results. The testing matrix. Each criterion, the controls mapped to it, the procedures the auditor performed, and the result. In a Type 1 there are no test results, because no operating effectiveness testing was performed.

Section V — Other information provided by management. Optional and unaudited. Roadmaps, responses to exceptions, extra context. Useful for understanding intent, but nobody has tested it. Read it as marketing with a helpful tone.

Start with the opinion

Find the sentence beginning “In our opinion” and read what follows carefully. There are four possibilities.

  • Unqualified — the auditor found the description fairly presented and the controls suitably designed (and, for a Type 2, operating effectively). This is the normal, clean outcome.
  • Qualified — everything holds except for something specific, introduced by “except for”. The exception is named. Read it.
  • Adverse — the description or the controls are not fairly presented or effective. Rare, and a serious signal.
  • Disclaimer — the auditor could not obtain enough evidence to form an opinion.

An unqualified opinion does not mean zero exceptions were found. It means the auditor concluded that what was found did not prevent the criteria from being met overall. This surprises people, and it is the single most useful thing to understand about these reports.

While you are in Section I, check three more things: the name of the firm signing it (it should be a CPA firm), the date range or “as of” date, and whether the report is Type 1 or Type 2.

Check the period, then check the calendar

A Type 2 covers a period. If the period ended eight months ago, the report is telling you about controls that operated last year.

Most reviewers work on a rough expectation that a report should be reasonably current, and ask for a bridge letter — a signed statement from management covering the span between the period end and today, confirming no material changes to the control environment. A bridge letter is not audited. It is management’s word, and its usefulness drops the longer the gap gets.

If you are looking at your second or third annual report from the same vendor, check that the periods are contiguous. A three-month hole between last year’s period end and this year’s period start is worth asking about.

Read the scope statement like a contract

Section III tells you what the report covers, and that is not automatically what you are buying.

Look for the specific product or platform named, the environments included, the locations, and any explicit exclusions. Vendors with multiple products often have a report covering one of them. If you use their data warehouse product and the report scopes the messaging product, the report is not about your risk.

Also note which trust services criteria are in scope. Security is always there. If you have uptime commitments in your contract and the report covers Security only, Availability was not examined. That may be fine — but it is a gap between what you assumed and what was tested.

Work through Section IV, and slow down at the exceptions

The testing matrix is where the actual work is recorded. Each row typically shows a control, the auditor’s test procedure, and a result — most often phrased as “No exceptions noted” or a description of what was found.

When you find an exception, do not stop at its existence. Judge it on four things.

What control failed. An exception in logical access, change management or offboarding matters more than one in a documentation-review control. Ask what an attacker or an accident could do through this gap.

How many instances. “One of 25 terminated employees had access removed in 4 days rather than 1” reads very differently from “12 of 25”. The matrix usually gives you the numerator.

Whether it is design or operation. A control that was never designed to work is a bigger problem than one that mostly worked and slipped a few times.

What management said about it. Look for a management response, often in Section V. A specific remediation with a date is a good sign. Silence, or a response that reframes the exception without addressing it, is not.

A report with a handful of small, well-explained exceptions and an unqualified opinion is often a more credible report than one with none at all. Perfectly clean reports over long periods happen, but they invite the question of how hard the auditor looked.

The two sets of controls that are not the vendor’s

Two items in the report describe controls someone other than the service organization is responsible for, and both are regularly skipped by readers.

Complementary user entity controls (CUECs) are things you must do for the vendor’s controls to work as intended — configure SSO correctly, manage your own admin accounts, review your user list, use the encryption options provided. The auditor did not test these, because they are yours. If you have never read the CUEC list for a vendor you depend on, that list is the highest-value page in the report for you.

Complementary subservice organization controls (CSOCs) are things the vendor’s own providers must do. Under the carve-out method, the subservice organization’s controls are excluded from the opinion, so those controls were not tested here either. You should see the provider named and the assumed controls listed. If a vendor carves out its hosting provider and its managed security provider, meaningful parts of the control environment sit outside this report.

What to do next

Run these five checks on the next report that lands on your desk: opinion wording, period end date, scoped system and criteria, every exception with its numerator, and the CUEC list. Write the CUEC items down as actions for your own team, because nobody else will.

If the report is your own and you are seeing exceptions in it for the first time, the useful question for your auditor is not “can we remove this” but “what would have had to be true during the period for this not to appear” — that answer is your remediation plan. Assurion performs SOC 2 examinations and also reviews vendor reports for clients who want a second read.