What a SOC 2 report actually tells you about a vendor
It is an auditor's opinion on controls the vendor chose, over a period the vendor chose. Useful, but not the guarantee buyers assume.

SOC 2 has become the default answer to "are you secure". It is a real assurance product, but it does not mean what most buyers think.
What it is
An independent auditor's report on whether a service organisation's controls meet defined trust services criteria — security always, and optionally availability, confidentiality, processing integrity and privacy.
**Type I** assesses whether controls are suitably designed at a single date. **Type II** assesses whether they operated effectively across a period, typically six to twelve months. Type II is substantially more meaningful.
Reading it properly
- **Period covered.** A Type II covering a period that ended fourteen months ago tells you about a company that may no longer exist in that form.
- **Criteria included.** Security only, or availability and confidentiality too?
- **Subservice organisations.** Which providers are carved out, and are their controls assumed rather than tested?
- **Exceptions.** Instances where a control did not operate as described, with management's response. This is the substance.
“A report with no exceptions across a twelve-month period is either excellent or narrowly scoped. Check which.”
What it does not tell you
It is not a penetration test, not a code review, and not a guarantee against breach. It says defined controls existed and operated. It says nothing about controls the vendor chose not to include.
Practical points
- Insist on Type II for anything holding your data.
- Read scope and exceptions before the opinion letter.
- Ask for the bridge letter covering the gap between the report period and today.
- Match the criteria to your actual risk rather than accepting security-only by default.



