What a SOC 2 report looks like
A SOC 2 Type 2 report is five sections and forty to a hundred pages. Two of those sections are written by you, one is written by the auditor, and only about six pages get read by anybody.
A SOC 2 Type 2 report runs forty to a hundred pages in five sections: the independent service auditor's report, your management assertion, your system description, the controls and the auditor's test results, and an optional section for information the auditor did not test. The opinion is on page one or two. The test results are the longest section and the only one a knowledgeable reviewer reads closely.
You cannot download a real one. Reports are issued under a non-disclosure agreement and are shared company to company on request. Most first-time buyers commission one without ever having seen the artefact they are buying. This is what is in it.
| Section | Written by | Typical length | Who reads it |
|---|---|---|---|
| 1. Independent service auditor's report | The CPA firm | 2 to 4 pages | Everybody, and often nothing else |
| 2. Management assertion | You | 1 to 2 pages | Procurement, briefly |
| 3. System description | You | 10 to 30 pages | Security reviewers checking scope |
| 4. Controls, tests and results | You and the firm | 25 to 60 pages | Anyone who knows what they are doing |
| 5. Other information | You | 0 to 5 pages | Rarely anyone |
| Whole report | Both | 40 to 100 pages | Six pages of it, in practice |
Section 1: the opinion
Two to four pages on the audit firm's letterhead, addressed to your management. It names the period examined, the criteria covered, and states whether the controls were suitably designed and, for a Type 2, whether they operated effectively throughout the period. The sentence that matters begins "in our opinion".
- Unqualified opinion
- The controls met the criteria. This is the normal outcome and the one you are paying for.
- Qualified opinion
- One or more criteria were not met. The report says which. It is survivable, and it generates questions in every vendor review afterwards.
- Adverse or disclaimer
- Rare enough that most practitioners never see one. A firm that expects to issue either normally stops the engagement first.
Read the scope paragraph as carefully as the opinion. It names the criteria, so a report covering Security only says so here, and it names any subservice organisations carved out. A reviewer comparing your report to their requirement is comparing these two paragraphs.
Section 2: your assertion
A page or two, signed by an officer, in which you assert that the system description is accurate and the controls were suitably designed and operating. It is your statement, not the auditor's, and it is the document a bridge letter later extends. If your bridge letter and your assertion contradict each other, a reviewer will notice.
Section 3: the system description
Ten to thirty pages written by you, usually with heavy help from a readiness consultant, describing the service. What it does, the infrastructure and software behind it, the people and processes, the data it handles, the commitments you make to customers, and the boundaries of the system.
This is where scope lives, and scope is where money lives. A description naming one product on one cloud account produces a cheaper audit than one naming three products and an acquired legacy environment. It is also the section a Canadian company should read with privacy in mind: it lists the personal information you hold and where it lives. That inventory is the same one PIPEDA and Law 25 expect you to maintain, so write it once and use it twice.
Subservice organisations appear here too, either carved out or included. Carving out AWS or Google Cloud is normal and expected, and it means the report does not cover their controls. A reviewer who cares will ask for the provider's own report separately.
Section 4: controls and test results
The longest section and the only one worth studying. It is a table. Each row carries the criterion, the control you claim meets it, the test the auditor performed, and the result.
| Column | What it holds |
|---|---|
| Criterion | The Trust Services Criteria reference, for example CC6.1 |
| Control | Your description of the control, in your words |
| Test performed | Inspected, observed, inquired or reperformed, and over what sample |
| Result | No exceptions noted, or a description of the exception |
Three things to look for when you read somebody else's report, and to expect in your own. The word "inquiry" on its own is the weakest test there is, and a report where many controls were tested only by asking somebody is a weak report. Sample sizes tell you how much work was done. And to anybody who has read a few, an exception with a sensible management response beside it reads better than a report with no exceptions and thin testing.
Exceptions are not failures
An exception is one instance where a control did not operate as described, for example one of twenty-five terminations where access was removed on day four instead of day one. The opinion can still be unqualified. What matters to a reviewer is the pattern and your response, not the count.
Section 5: other information
Optional, and often absent. It is where management can add context the auditor did not test: a roadmap, a response to an exception, a note about a system that entered scope after the period ended. It carries no assurance and says so. Use it sparingly, because a long section 5 reads as an argument with the four sections above it.
What a reviewer actually does with it
- Checks the period covers the window they care about, and how long ago it ended.
- Reads the opinion paragraph and the criteria listed with it.
- Checks the system description names the product they are buying.
- Scans section 4 for exceptions, and for controls tested by inquiry alone.
- Files it, and asks for a bridge letter if the period ended more than a quarter ago.
That whole pass takes a competent reviewer twenty minutes. Everything else in the report exists so that those twenty minutes can be trusted.
Getting hold of a sample
Audit firms will show a redacted sample report on a call. Ask during selection: the quality of a firm's report writing varies more than its testing does. Compliance platforms sometimes publish sample structures. Anything offered as a free downloadable "SOC 2 report example" with no non-disclosure agreement attached is a marketing document rather than a report.
Ask firms to show you their report format
Tell us your scope and we will put it in front of Canadian CPA firms. Ask each of them for a redacted sample before you choose.
Get matchedCommon questions
Can I download an example SOC 2 report?
Not a real one. Reports are confidential and are shared under a non-disclosure agreement between the company that holds the report and the customer asking for it. Audit firms will show redacted samples during selection, and asking to see one is a reasonable part of choosing a firm.
How long is a SOC 2 report?
Forty to a hundred pages for a Type 2, with the controls and test results section making up more than half of it. A Type 1 is shorter, usually thirty to sixty pages, because there are no operating effectiveness test results to record.
What does an exception in a SOC 2 report mean?
That a control did not operate as described in at least one sampled instance. The report states the exception and normally carries your management response beside it. The opinion can still be unqualified, and reviewers are more interested in the pattern and your response than in the number of exceptions.
Which section do customers actually read?
The opinion, the scope paragraph beside it, and a scan of the test results for exceptions. That is about six pages. The system description gets read when a reviewer is checking that the product they are buying is inside the scope of the report.