Complies
SOC 2 GUIDES

How to Read a SOC 2 Report and Review a Vendor

AUGUST 2026 · 9 MIN READ · BY THE COMPLIES TEAM

Skip the reading? Connect your stack and get a readiness score today. Plans from $79 a month, prices published.

To read a SOC 2 report, work in this order: the independent service auditor's opinion, the scope, the exceptions, and the complementary user entity controls. The opinion tells you whether the report is clean. The scope tells you whether it covers the product you are buying. Section 4 lists every test the auditor ran and every exception found. The user entity controls list the things you must do yourself for the vendor's controls to work at all.

Most people skim a vendor's SOC 2 report, confirm it exists, check the logo of a firm they recognize, and file it. That is a compliance theater habit, and it is also how a critical vendor with a qualified opinion and six exceptions ends up in your stack. The report is a real audit document with real findings in it, and reading it properly takes about forty minutes the first time and fifteen after that.

This guide is written from the buyer's side of the table. If you are on the other side, preparing your own report, the companion piece is the SOC 2 audit process guide.

What is in a SOC 2 report?

A SOC 2 Type 2 report contains four things: management's assertion, the description of the system, the independent service auditor's report, and the tests of controls with their results. Reports are conventionally laid out in numbered sections, and while the AICPA's description criteria (DC 200) do not mandate a format, nearly every firm uses roughly the same order.

Section What it is Who wrote it Why you care
Section 1The independent service auditor's report, containing the opinionThe CPA firmThe single most important page. Read it first, before anything else
Section 2Management's assertionThe vendor's managementThe formal claim the auditor is opining on, including the period covered
Section 3The description of the systemThe vendor's managementDefines the boundary: which product, which infrastructure, which subservice organizations
Section 4Trust Services Criteria, the controls, the tests performed, and the resultsThe CPA firm, with the vendor's control descriptionsWhere exceptions live. This is the part almost nobody reads and the part that matters most
Section 5Other information provided by management, if presentThe vendorUnaudited. Management's response to exceptions often sits here, clearly outside the opinion

One structural point worth internalizing: management writes the description and makes the assertion, and the auditor opines on that assertion. The report is not the auditor's independent essay about the vendor. It is a licensed CPA firm testing a claim the vendor made about itself. That is why the scope section deserves as much attention as the findings.

How to read a SOC 2 report, step by step

1. Read the opinion first

Turn to Section 1 and find the opinion paragraph. An unqualified opinion means the auditor found the description fairly presented and the controls suitably designed and, for a Type 2, operating effectively throughout the period. That is the clean result and what most reports contain. A qualified opinion means the auditor found something significant enough to carve out, and the paragraph will say what. Adverse and disclaimer opinions are rare and are effectively a stop sign.

A qualified opinion is not automatically disqualifying. Read what was qualified. A qualification on the availability criterion matters enormously if you are buying infrastructure and much less if you are buying an internal analytics tool. What is disqualifying is a qualified opinion the vendor never mentioned.

2. Check the scope and the period

Three scope questions decide whether the report is even relevant to you. Which Trust Services categories are in scope? Security, the common criteria, is always included; availability, processing integrity, confidentiality and privacy are optional and many reports cover security only. Which system is in scope? Vendors with several products frequently scope the report to one of them, and it may not be the one you are buying. And what period does it cover? A Type 2 covers a window, commonly three to twelve months, and a report covering a three-month window tells you far less than one covering twelve.

If the report is a Type 1, note that it tests design at a single point in time, not operation over a period. That distinction is covered fully in SOC 2 Type 1 vs Type 2. If your vendor handed you a SOC 1 instead, that is a different report about financial reporting controls, explained in SOC 1 vs SOC 2.

3. Read Section 4 and find the exceptions

Section 4 lists each criterion, the vendor's controls, the tests the auditor performed, and the results. Most rows say "no exceptions noted." Search the document for "exception," "deviation," and "not operating effectively," then read each hit in full.

An exception is a case where a control did not operate as described during the period. Judge them on three axes: which criterion they touch, how many instances out of the sample, and whether management's response describes a real fix with a date. One missed access review out of a sample of twenty five, remediated the same quarter, is a functioning program catching itself. Repeated exceptions in logical access or change management are a different signal, especially if the same exception appears in consecutive years.

4. Read the complementary user entity controls

This is the section buyers skip and auditors care about. Complementary user entity controls, usually abbreviated CUECs, are controls the vendor assumes you operate. The vendor's controls are only effective if yours are. Typical CUECs: you provision and deprovision your own users promptly, you enforce multi-factor authentication on your accounts, you configure the permissions and retention settings correctly, you review your own audit logs, you keep your API keys secret.

Two things follow. First, if you are not doing them, the vendor's clean report does not cover the gap, and your own auditor may well ask. Second, CUECs are a ready-made list of internal controls you need to own. Copy them out of every critical vendor's report and give each one an internal owner and a review date, the same way you would any other obligation.

5. Check the subservice organizations

Section 3 will name the subservice organizations the vendor depends on, typically their cloud provider and sometimes a data center or key SaaS platform. It will also say whether they were handled with the carve-out method or the inclusive method. Carve-out, which is far more common, means those providers' controls were excluded from the scope of this report and you are expected to rely on the subservice organization's own SOC report. Inclusive means they were tested here.

Practically: if the report carves out AWS, that is normal and fine, but recognize that you are relying on two reports, not one. What you are checking is whether the vendor has a process for monitoring its own subservice organizations, which is itself a criterion the auditor tests.

6. Check the report's age and ask for a bridge letter

Reports go stale. SOC 2 examinations are typically annual, and there is always a gap between the end of the observation period and the day you read the report. If the period ended more than three months ago, ask for a bridge letter, sometimes called a gap letter: a short statement from the vendor's management covering the interval since the report period, confirming no material changes to the control environment. A bridge letter is management's word, not an audited document, but its absence when a report is nine months old is worth a question.

A SOC 2 report review checklist

Check Where to look Green Ask a question
Opinion typeSection 1UnqualifiedQualified, adverse, or disclaimer
Report typeSection 1 and 2Type 2 covering 12 monthsType 1, or a Type 2 covering under 6 months
Categories in scopeSection 1Security plus the categories your use case needsSecurity only when you depend on availability or confidentiality
System in scopeSection 3Names the product you are actually buyingScoped to a different product or a subset of the platform
ExceptionsSection 4None, or isolated with a dated remediationRepeat exceptions, or clusters in access and change management
User entity controlsSection 3 or 4You already operate all of themAny CUEC you do not currently do
Subservice organizationsSection 3Named, with a stated monitoring processCarved out with no evidence they are monitored
Report ageSection 1Period ended within the last 3 monthsOlder than 6 months with no bridge letter
Audit firmSection 1 letterheadA licensed CPA firmA consultancy that is not a licensed CPA firm

Run that list once per critical vendor per year and record the answers somewhere durable. The review itself is evidence: your own auditor will ask how you assess vendors, and "we read the SOC 2 report" is a weaker answer than a dated review with an owner and a conclusion attached to it.

How do buyers verify vendor SOC 2 compliance?

By reading the report, not the badge. A trust-center page, a logo, or a line in a sales deck saying "SOC 2 compliant" verifies nothing, and there is no public registry of SOC 2 reports to check against. SOC 2 reports are confidential and distributed under NDA, so the process is: request the current report, sign the NDA, read the opinion and Section 4, and record your conclusion. If a vendor will not share the report itself and offers only a summary, treat that as an unanswered question.

This is the same loop described in our vendor risk management process guide, and it is what SOC 2 criterion CC9.2 and ISO 27001 controls A.5.19 to A.5.22 require you to be doing. Note also that reviewing incoming reports is the mirror image of answering security questionnaires yourself: your customers are running this exact checklist against you.

What if the vendor has no SOC 2 report at all?

Plenty of legitimate vendors do not have one, particularly small tools and early-stage products, and refusing to buy from any of them is not realistic. Scale the assurance to the risk. For a vendor with no access to production or customer data, a completed security questionnaire and a signed data processing agreement are often proportionate. For anything touching customer data, ask what they do have: an ISO 27001 certificate, a recent penetration test summary, or a SOC 2 examination in progress with a named firm and a period start date.

Then write down the decision and why. An auditor is far more comfortable with a documented, risk-tiered exception than with a vendor that simply has nothing on file. Teams handling this at any volume end up needing a way to pull the structured details out of a stack of PDF reports rather than rereading each one by hand, because the review only stays current if it is cheap to repeat.

How often should you re-review a vendor's SOC 2 report?

Annually for critical vendors, on each new report, and immediately after any breach disclosure or material change such as an acquisition or a migration to new infrastructure. Set the review date when you finish the current review, assign it to a named owner, and let it chase itself. Vendor programs rarely fail because someone read a report badly. They fail because the second review never happened.

That scheduling is exactly what vendor risk management software is for: one register of every vendor, tiered by the data it touches, with the SOC 2 report, the questionnaire, the insurance certificate and the DPA tracked against an owner and a renewal date, mapped to CC9.2 and the ISO supplier controls so the program doubles as audit evidence. If you are still choosing a platform to run this in, our compliance software comparison covers what nineteen of them actually cost.

Common questions

Is a SOC 2 report public?

No. SOC 2 reports are confidential and almost always distributed under a non-disclosure agreement, which is why there is no public database to look a vendor up in. Vendors typically publish a trust-center page confirming a report exists and release the document itself on request after an NDA. A vendor that publishes the full report openly is unusual, not more trustworthy.

How long is a SOC 2 report valid?

A SOC 2 report does not expire on a fixed date, but it covers a defined period and loses value as that period recedes. The practical convention is that a report is current for twelve months from the end of its observation period, with a bridge letter covering the gap between the period end and today. Most buyers ask for a new report annually.

What does a qualified opinion mean in a SOC 2 report?

It means the auditor concluded that something was materially wrong: a control was not operating effectively, or the description was not fairly presented, in a way significant enough to carve out of the opinion. The opinion paragraph states exactly what was qualified. Read that, then read the related tests in Section 4 and management's response, and decide whether the qualified area touches what you are buying.

What is the difference between a SOC 2 exception and a qualified opinion?

An exception is a single instance where a control did not operate as described, and a report can contain several while still receiving a clean, unqualified opinion. A qualified opinion is the auditor's overall judgment that the exceptions, taken together, were significant enough to affect the conclusion. In short: exceptions are findings, a qualification is a verdict.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.