SOC 2 exceptions and qualified opinions
You cannot fail a SOC 2, because it is not a test. You can collect exceptions, and enough of them in the wrong place produces a qualified opinion, which is survivable and expensive.
A SOC 2 exception is a case where the auditor tested a control and it did not operate as described. Exceptions are written into the report along with your response, and most reports contain some. They only become a problem when they are numerous enough or serious enough that the auditor cannot say a criterion was met, at which point the opinion becomes qualified. A qualified opinion does not void the report and does not stop you selling, but every security reviewer who reads it will ask about it.
The four opinions an auditor can issue
The opinion wording comes from the AICPA attestation standards, not from anything SOC 2 specific. The four outcomes are the same four an accountant can issue on any attestation engagement, and the words material and pervasive are the hinge between them.
- Unqualified
- The controls were suitably designed and, in a Type 2, operated effectively throughout the period. This is what you are paying for. A report can be unqualified and still contain exceptions, as long as the exceptions did not prevent the criteria being met.
- Qualified
- Everything holds except for specific, identified matters, which the opinion names. In the language of the attestation standards the problem is material but not pervasive. This is the outcome companies encounter when something goes wrong.
- Adverse
- The problems are both material and pervasive, so the description as a whole is not fair. Rare, and generally a sign the engagement should never have proceeded to a Type 2.
- Disclaimer of opinion
- The auditor could not obtain enough evidence to form any opinion, usually because records did not exist. You paid for an engagement and received a document that says nothing. Rarer than adverse.
Exceptions are normal, qualifications are not
A first Type 2 that comes back with three or four exceptions across access reviews, offboarding timeliness and vendor reviews is an ordinary report and buyers read past it. A qualified opinion is a different category of event. It should never be a surprise. Your auditor will have raised the issue during fieldwork.
The exceptions Canadian companies actually collect
Nearly all first-year exceptions come from the same handful of controls, and they share a shape: a control that requires somebody to do something on a schedule, in a quarter when that person was busy.
| Control | What the exception looks like | Root cause |
|---|---|---|
| Quarterly user access review | One of four quarters has no evidence, or the review was signed after quarter end | Nobody owned the calendar reminder |
| Offboarding within one business day | Two of eleven leavers kept access for a week | Departure notified to IT after the fact |
| Change management approval | Six of forty sampled pull requests merged without a second approver | Emergency changes with no documented exception path |
| Vendor security review | Vendor register exists, reviews not performed | The register was built for the audit and then abandoned |
| Security awareness training | Three staff did not complete training inside the period | New joiners in the last month of the window |
| Log review | Alerting exists, evidence that anyone looked does not | The control was written as a review when the reality is alerting |
| Backup restoration testing | Backups run, a restore was never tested | The control described an intention |
Most of these are not security failures. They are documentation failures against a control you wrote yourself. Writing a control that says quarterly when you can only sustain semi-annual is a choice you make during readiness, and the readiness guide on SOC2Prep covers writing controls you can operate.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What happens when the auditor finds one
- The auditor raises it during fieldwork, usually the same week they test it. Nothing is written yet.
- You provide context or additional evidence. Some exceptions evaporate here because the evidence existed and nobody had asked the right person.
- If it stands, the exception is written into section four of the report with the population size, the number of failures, and the test performed.
- You write a management response that goes into the report beside it. This is your only chance to frame the finding for every reader.
- The partner decides whether the exceptions, taken together, prevent a criterion from being met. That decision produces the opinion.
The management response is the part you control
A weak response repeats the finding. A strong one names what changed, when it changed, and how the change is now evidenced. "Access reviews were missed in Q2 following the departure of the IT manager. The review is now assigned to the Director of Engineering, scheduled in the ticketing system, and Q3 and Q4 were completed on time." A reviewer reading that has their answer and moves on. Write these carefully. They are permanent and they get read.
What a qualified opinion does to a deal
It depends on which criterion was qualified. A qualification on a change management control at a company selling developer tooling is a conversation. A qualification on logical access at a company holding health records is a lost deal in a regulated buyer. Reviewers are not counting exceptions, they are asking whether the failure touches the risk they care about.
| Buyer | Typical response |
|---|---|
| Mid-market SaaS buyer | Asks for the management response and a remediation date, then proceeds |
| Large enterprise, non-regulated | Escalates to their security team, often accepts with a compensating contract term |
| Financial services or insurance | Usually requires remediation evidence, sometimes a clean report, before signing |
| Health sector under PHIPA | Treats an access or confidentiality qualification as disqualifying |
| Public sector procurement | Depends on the tender language. Some tenders require an unqualified opinion in writing |
A qualified report that discloses a real problem and a real fix is more credible to an experienced reviewer than a spotless first-year report over a three month window. Some security teams read a first Type 2 with zero exceptions as evidence that the window was too short to catch anything. Do not chase a clean report by narrowing controls until they cannot fail. The reviewer reads the control list too.
Recovering from one
You do not reissue a SOC 2. The period is over and the report describes what happened. What you do instead is fix the control, run the next period cleanly, and in the meantime give buyers something to hold. That is usually a short remediation memo naming the finding, the change, the date it took effect and the evidence that now exists.
If the qualification is blocking revenue right now, a Type 1 dated after the remediation is the fastest credible artifact: a CPA firm can opine that the redesigned control is suitably designed. It says nothing about operation, so pair it with the remediation memo and a committed date for the next Type 2. The observation window page covers how to sequence that without leaving a coverage gap.
Can you discuss an exception before the report is drafted?
Yes, and that is the only time it helps. During fieldwork the auditor tells you about a potential exception as it is found. That is the moment to check whether the evidence exists and was sent under the wrong request, and to draft management's response while the facts are fresh. Once the draft report arrives, the finding is settled and only the wording of your response is still yours. Managing your SOC 2 auditor covers the conversation, including what you can and cannot ask an auditor to change.
Talk to firms about a remediation path
Tell us what was qualified and we will point you at Canadian firms that have handled that specific criterion.
Get matchedWhere to go from here
- How to read a SOC 2 report you received. Where the exceptions sit in the report and how to read around them.
- SOC 2 bridge letter. What a bridge letter covers between your report date and the buyer's question.
- SOC 2 renewal. How an exception in year one changes year two.
- Questions to ask a SOC 2 auditor. What to ask an auditor about how they handle a finding mid-fieldwork.
- What to do when a SOC 2 audit stalls. Recovering an audit that is waiting on evidence nobody has.
Common questions
Can you fail a SOC 2 audit?
Not in the way you fail an exam. The engagement always produces a report. What varies is the opinion in it. The bad outcomes are a qualified opinion, which names specific criteria that were not met, and much more rarely an adverse opinion or a disclaimer. All three are still reports you receive and pay for.
How many exceptions is too many?
There is no threshold. The auditor judges whether the exceptions, together with the population they came from, prevent a criterion from being met. Two failures out of a sample of forty low-risk changes is usually fine. Two failures out of four quarterly access reviews is half the population and usually is not.
Do we have to show the report to customers if it is qualified?
You are not obliged to distribute a report at all, but withholding one after a customer asked is itself an answer they will draw conclusions from. Companies that hand over a qualified report with a clear management response and a remediation date generally do better than those that go quiet for a quarter.
Can we ask the auditor to remove an exception?
You can provide evidence that the control did operate, and if it is persuasive the exception comes out because it was never valid. You cannot ask for a valid finding to be omitted. A firm that agrees to that has ended its independence and the report is worthless to the buyer you needed it for.
Does a qualified opinion mean we start over next year?
No. The next period is a normal engagement. Most firms will want to see the remediated control operating before the new window starts, and some will test it more heavily. Expect the same fee or slightly more, not a fresh first-year price.