Skip to main content

What a SOC 2 report actually tells you about a vendor

It is an auditor's opinion on controls the vendor chose, over a period the vendor chose. Useful, but not the guarantee buyers assume.

Technology Editor

· 1 min read

Security in California.
Security in California.Wikideas1 · CC0 · via Wikimedia Commons

SOC 2 has become the default answer to "are you secure". It is a real assurance product, but it does not mean what most buyers think.

What it is

An independent auditor's report on whether a service organisation's controls meet defined trust services criteria — security always, and optionally availability, confidentiality, processing integrity and privacy.

**Type I** assesses whether controls are suitably designed at a single date. **Type II** assesses whether they operated effectively across a period, typically six to twelve months. Type II is substantially more meaningful.

Reading it properly

  • **Period covered.** A Type II covering a period that ended fourteen months ago tells you about a company that may no longer exist in that form.
  • **Criteria included.** Security only, or availability and confidentiality too?
  • **Subservice organisations.** Which providers are carved out, and are their controls assumed rather than tested?
  • **Exceptions.** Instances where a control did not operate as described, with management's response. This is the substance.
“A report with no exceptions across a twelve-month period is either excellent or narrowly scoped. Check which.”

What it does not tell you

It is not a penetration test, not a code review, and not a guarantee against breach. It says defined controls existed and operated. It says nothing about controls the vendor chose not to include.

Practical points

  • Insist on Type II for anything holding your data.
  • Read scope and exceptions before the opinion letter.
  • Ask for the bridge letter covering the gap between the report period and today.
  • Match the criteria to your actual risk rather than accepting security-only by default.

Related