Passing a customer security review before you have SOC 2
A buyer's security team wants proof and you do not have a report yet. That is a normal position for a Canadian software company, and most reviews can be passed from it if you handle the next two weeks well.
Most buyers will accept a completed security questionnaire, a penetration test letter, your core policies and a dated SOC 2 plan in place of the report, for a while. Say when the report will exist, show the controls that already run, and never answer yes to a control you cannot evidence. Reviews fail on invented answers far more often than on a missing report.
What does the buyer's security team actually need?
A reviewer is not checking whether you own a report. They are deciding whether their company can accept the risk of sending you its data, and writing that decision down for their own auditors. A SOC 2 Type 2 report makes that easy because an independent firm has already tested your controls over a period. Without one, the reviewer needs enough material to write the same decision on their own. Your job is to give them that material, organized so they do not have to chase it.
What can you send instead of a SOC 2 report?
| Document | What it shows the reviewer | Effort if you do not have it |
|---|---|---|
| Completed questionnaire | Your controls, in their format, answered accurately | Days the first time; hours once an answer library exists |
| Penetration test letter or summary | An independent tester looked at your application recently and you fixed what they found | Two to six weeks to book and run a test |
| Information security policy set | Rules exist, have an owner and a review date | A few weeks to write properly; templates are a start, not the finish |
| Architecture and data flow summary | Where their data goes, which cloud regions, which subprocessors | A day or two for whoever knows the system |
| Subprocessor list | Who else touches their data, and where | Hours |
| Dated SOC 2 plan | When a report will exist, which type, which criteria, which firm | A readiness assessment and an auditor conversation |
| Cyber insurance certificate | Financial backing if something goes wrong | Already exists if you hold a policy |
Several of these are the same artefacts a SOC 2 readiness project produces anyway, so none of the work is wasted. If you want the pack in one place that buyers can read without emailing you, a trust centre before your first report is how companies in this position usually present it.
What should you say about when the report will exist?
Give a date you can defend and the report type. A Type 1 report can exist within weeks of controls being in place, because it tests design on one date. A Type 2 report cannot exist until an observation window of at least three months has run, and most first windows are three to six months, plus four to eight weeks for fieldwork and the report. The SOC 2 deadline calculator works backwards from the buyer's date. If their date is earlier than any honest Type 2 date, say so and offer a Type 1 or a bridge plan. The first-week guide covers the three honest replies in more detail.
Put the commitment in writing carefully
Buyers sometimes ask to write "vendor will obtain SOC 2 Type 2 by" a date into the contract. Agree only to a date that includes the full observation window and the auditor's reporting time, and that does not depend on things outside your control, such as an audit firm's availability.
Which answers sink a review?
- A yes you cannot show. "MFA enforced everywhere" when one admin console does not have it. The reviewer only needs to find one to stop trusting the rest.
- "SOC 2 compliant." There is no such status without a report. Say you are preparing for a SOC 2 examination and give the date.
- Copied answers that contradict each other. Encryption described one way in question 12 and another way in question 48. Keep one approved answer per topic.
- The wrong privacy law. Answering "GDPR" by reflex when PIPEDA, Law 25 for Quebec residents or PHIPA is what governs you.
- Silence. A review that goes quiet for three weeks is often decided against you by default. Send a dated plan for the open items even when they are not done.
When is it worth getting help?
When the deal is large, the questionnaire is a full SIG or a bank's custom set, or the person who would answer it is also the person shipping the product. Help can draft the questionnaire from your evidence and build the answer library at the same time. TrustCenter's security questionnaire help page compares the options and what each costs, and the questionnaire readiness tool shows which questions you can already answer with evidence.
Common questions
Will an enterprise buyer sign without a SOC 2 report?
Often, yes, for a first contract, if the questionnaire is accurate, a recent penetration test exists and a dated plan for the report is in writing. Some regulated buyers will not, and they usually say so in their vendor policy before the review starts.
Is a SOC 2 Type 1 report enough to pass a review?
It is enough for many first contracts because it shows controls were designed properly on a date. Buyers with mature vendor programs will usually accept a Type 1 with a commitment to a Type 2 by a stated date.
Can a penetration test replace a SOC 2 report in a review?
No, but it covers a large part of what technical reviewers worry about. It shows an independent tester examined your application. A SOC 2 report covers far more: access, change management, vendor management and monitoring, tested over time.
What if the buyer asks for a SOC 2 report we will never need again?
Ask what they actually need to see. A reviewer asking for a SOC 2 report is sometimes satisfied by ISO 27001, a completed CAIQ, or the review pack above. Buy the report when several buyers need it, not for one.
Get a SOC 2 timeline you can put in a reply
Describe the deal date once. Canadian firms reply with what is realistic and what it costs.
Get matched