GetSOC2

Passing a customer security review before you have SOC 2

A buyer's security team wants proof and you do not have a report yet. That is a normal position for a Canadian software company, and most reviews can be passed from it if you handle the next two weeks well.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

Most buyers will accept a completed security questionnaire, a penetration test letter, your core policies and a dated SOC 2 plan in place of the report, for a while. Say when the report will exist, show the controls that already run, and never answer yes to a control you cannot evidence. Reviews fail on invented answers far more often than on a missing report.

What does the buyer's security team actually need?

A reviewer is not checking whether you own a report. They are deciding whether their company can accept the risk of sending you its data, and writing that decision down for their own auditors. A SOC 2 Type 2 report makes that easy because an independent firm has already tested your controls over a period. Without one, the reviewer needs enough material to write the same decision on their own. Your job is to give them that material, organized so they do not have to chase it.

What can you send instead of a SOC 2 report?

A review pack for a company without a SOC 2 report yet
DocumentWhat it shows the reviewerEffort if you do not have it
Completed questionnaireYour controls, in their format, answered accuratelyDays the first time; hours once an answer library exists
Penetration test letter or summaryAn independent tester looked at your application recently and you fixed what they foundTwo to six weeks to book and run a test
Information security policy setRules exist, have an owner and a review dateA few weeks to write properly; templates are a start, not the finish
Architecture and data flow summaryWhere their data goes, which cloud regions, which subprocessorsA day or two for whoever knows the system
Subprocessor listWho else touches their data, and whereHours
Dated SOC 2 planWhen a report will exist, which type, which criteria, which firmA readiness assessment and an auditor conversation
Cyber insurance certificateFinancial backing if something goes wrongAlready exists if you hold a policy

Several of these are the same artefacts a SOC 2 readiness project produces anyway, so none of the work is wasted. If you want the pack in one place that buyers can read without emailing you, a trust centre before your first report is how companies in this position usually present it.

What should you say about when the report will exist?

Give a date you can defend and the report type. A Type 1 report can exist within weeks of controls being in place, because it tests design on one date. A Type 2 report cannot exist until an observation window of at least three months has run, and most first windows are three to six months, plus four to eight weeks for fieldwork and the report. The SOC 2 deadline calculator works backwards from the buyer's date. If their date is earlier than any honest Type 2 date, say so and offer a Type 1 or a bridge plan. The first-week guide covers the three honest replies in more detail.

Put the commitment in writing carefully

Buyers sometimes ask to write "vendor will obtain SOC 2 Type 2 by" a date into the contract. Agree only to a date that includes the full observation window and the auditor's reporting time, and that does not depend on things outside your control, such as an audit firm's availability.

Which answers sink a review?

  • A yes you cannot show. "MFA enforced everywhere" when one admin console does not have it. The reviewer only needs to find one to stop trusting the rest.
  • "SOC 2 compliant." There is no such status without a report. Say you are preparing for a SOC 2 examination and give the date.
  • Copied answers that contradict each other. Encryption described one way in question 12 and another way in question 48. Keep one approved answer per topic.
  • The wrong privacy law. Answering "GDPR" by reflex when PIPEDA, Law 25 for Quebec residents or PHIPA is what governs you.
  • Silence. A review that goes quiet for three weeks is often decided against you by default. Send a dated plan for the open items even when they are not done.

When is it worth getting help?

When the deal is large, the questionnaire is a full SIG or a bank's custom set, or the person who would answer it is also the person shipping the product. Help can draft the questionnaire from your evidence and build the answer library at the same time. TrustCenter's security questionnaire help page compares the options and what each costs, and the questionnaire readiness tool shows which questions you can already answer with evidence.

Common questions

Will an enterprise buyer sign without a SOC 2 report?

Often, yes, for a first contract, if the questionnaire is accurate, a recent penetration test exists and a dated plan for the report is in writing. Some regulated buyers will not, and they usually say so in their vendor policy before the review starts.

Is a SOC 2 Type 1 report enough to pass a review?

It is enough for many first contracts because it shows controls were designed properly on a date. Buyers with mature vendor programs will usually accept a Type 1 with a commitment to a Type 2 by a stated date.

Can a penetration test replace a SOC 2 report in a review?

No, but it covers a large part of what technical reviewers worry about. It shows an independent tester examined your application. A SOC 2 report covers far more: access, change management, vendor management and monitoring, tested over time.

What if the buyer asks for a SOC 2 report we will never need again?

Ask what they actually need to see. A reviewer asking for a SOC 2 report is sometimes satisfied by ISO 27001, a completed CAIQ, or the review pack above. Buy the report when several buyers need it, not for one.

Get a SOC 2 timeline you can put in a reply

Describe the deal date once. Canadian firms reply with what is realistic and what it costs.

Get matched