GetSOC2

How to read a SOC 2 report you received

Most companies file a vendor's SOC 2 without opening it. Half an hour with the right five checks tells you more about a supplier than any questionnaire will.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Reading a supplier's SOC 2 report properly takes about thirty minutes and comes down to five checks: the opinion, the period, the scope, the exceptions in section 4, and the complementary user entity controls. Everything else is context. A report can carry a clean opinion and still be useless to you: it covered a product you do not use, over a period that ended eighteen months ago.

What is in the document

The sections of a SOC 2 report, in order
SectionWritten byWhat to do with it
1. Independent service auditor's reportThe CPA firmRead every word. It is two or three pages and contains the opinion, the period and the scope
2. Management assertionThe vendorSkim. Confirms the vendor stands behind the description
3. System descriptionThe vendorCheck it describes what you bought. Note the subservice organizations and the CUECs, which usually live at the end
4. Tests of controls and resultsBothThe part that repays reading. Every control, the test, the result, and any exception
5. Other informationThe vendorOptional and unaudited. Roadmaps and responses live here. Treat it as marketing

If you want the same tour from the other side, as the company being audited, the report walkthrough covers what each section will say about you.

Check one: the opinion

Find the paragraph beginning "In our opinion". Unqualified means clean. Qualified means the auditor named specific matters that were not met, and the opinion says which. Adverse and disclaimer are rare and serious. A qualified opinion is not automatically disqualifying, and what each opinion means is worth knowing before you escalate one.

Check two: the period and the type

A Type 1 covers one date and tells you the controls were designed, not that they worked. If a vendor sends a Type 1 when you asked for evidence of operating effectiveness, that is your answer. For a Type 2, note the period end date. Past about twelve months, ask for the current report. Between the period end and today, ask for a bridge letter.

Check three: scope

The system description names the system that was audited. Vendors with several products often audit one. Check the product name, the environments, and the hosting regions. A Canadian buyer with data residency commitments should confirm the audited system includes the Canadian region.

Check four: section 4

This is the part almost nobody reads and the part that informs you. Look for the word exception or deviation. For each one, note the control, the population and how many items failed, and read the management response. Two failures out of forty low-risk changes is noise. One failure out of four quarterly access reviews is a control that was not operating. How those deviations come about in the first place is on what an auditor checks during fieldwork.

A report with no exceptions is not automatically better

A first Type 2 over a three month window with zero exceptions may mean the window was too short to catch anything, or that the control set was written narrowly enough that it could not fail. Read the control descriptions. A vendor whose report discloses three ordinary findings with dated remediation often deserves more confidence than one with a spotless quarter.

Check five: the CUEC list

Complementary user entity controls are the things the vendor assumes you are doing. Every one of them is now your control. Removing your own departed users, configuring single sign-on, protecting API keys, reviewing your own audit logs. Assign each one an owner. Your own auditor may ask whether you did. The CUEC page covers the list and what to do with it.

Six things that should worry you

Red flags in a supplier SOC 2 report
What you findWhy it matters
The period ended more than a year ago and there is no bridge letterYou have no current assurance at all
The audited system is not the product you useThe report says nothing about your risk
Exceptions repeat from the previous year's reportThe remediation did not happen. Ask for evidence, not a plan
The control set is unusually short for the company's sizeScope was narrowed until it could not fail
A long CUEC list covering things you cannot actually configureResponsibility was shifted onto you without a mechanism
A critical vendor of theirs is carved out and never reviewedThe chain has an unexamined link

Record what you decided

Your own auditor tests whether you review supplier reports, and the evidence is a record of the review, not the report itself. Note the report reference and period, the opinion, the exceptions you accepted and why, the CUECs you took on, and the date the next report is due. That single page satisfies the control and takes five minutes to write while the report is open in front of you. The vendor management page covers building the wider program around it. This is also what a customer does to you, and why your customer is asking explains the control they are closing. Where the report is not worth producing for the account in front of you, saying no is the page to read first.

Need help assessing a supplier?

Canadian firms do third party risk reviews as fixed-scope work. Tell us what you are assessing.

Get matched

The restricted-use paragraph near the end of the opinion decides who may receive the report. Who can you give your SOC 2 report to explains it.

Common questions

What is the first thing to check in a vendor's SOC 2?

The opinion and the period, in that order. The opinion tells you whether the auditor could give clean assurance. The period tells you whether that assurance is current. A clean opinion over a period that ended eighteen months ago is not current assurance.

How long is a SOC 2 report good for?

Buyers generally treat a report as usable for about twelve months after the period end date. There is no formal expiry, because the report describes a period that already happened. Between the period end and your review date, a bridge letter from the vendor's management covers the gap.

Should we reject a vendor with a qualified opinion?

Not automatically. Read which criterion was qualified and whether it touches the risk you care about. A qualification on change management at a tool that holds no sensitive data is different from one on logical access at a vendor holding your customer records. Ask for remediation evidence with a date.

Do we need to read the whole report?

No. Read section 1 in full, skim section 3 for scope, subservice organizations and CUECs, and read section 4 for exceptions. Section 2 is procedural and section 5 is unaudited. That is thirty minutes for a typical report.

What if the vendor will not send the report?

Sign their NDA, since SOC 2 is a restricted use report and vendors are right to require one. If they still refuse, ask for a SOC 3, which is publicly distributable, and treat continued refusal as a finding in your own vendor assessment.