GetSOC2

What to offer instead of a SOC 2 report

A buyer who cannot get a report will usually take a package of smaller artifacts plus a dated commitment. What loses the deal is offering nothing, or offering something that sounds like a report and is not.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The substitute that works most often is a package rather than a single document: a completed security questionnaire, a recent penetration test summary, a written control description, and a contractual commitment to deliver a named report by a named date. That closes a buyer's vendor assessment control in roughly the same way a report does. Their obligation is to assess you, not to collect a specific PDF. What does not work is a compliance platform dashboard, a self-issued badge, or the word compliant used without a report behind it.

Seven substitutes, ranked by how often they land

Interim assurance a buyer may accept, and the cost in CAD
What you offerHow often it is acceptedCost
Completed questionnaire, penetration test summary and control description, with a dated audit commitment in the contractMost of the time, for a first contract$8,000 to $18,000
SOC 2 Type 1 report, with a committed Type 2 windowOften, and it converts a maybe into a yes$15,000 to $35,000
Current ISO 27001 certificate with the Statement of ApplicabilityOften, where the policy says "or equivalent"Already spent, or $30,000 and up
Bridge letter, where a report exists but its period has endedAlmost always, for the gap it coversUsually included by the auditor
Independent readiness assessment report from a third partySometimes, mostly with technical reviewers$6,000 to $15,000
Contractual security addendum with audit rights and breach timingSometimes, and it costs legal time rather than moneyLegal hours
Compliance platform dashboard or trust page as the primary artifactRarely. A reviewer reads it as marketingPlatform subscription
Cheapest package that closes most first contracts$8,000 to $18,000 CAD, mostly the penetration test

The first row does the work in nearly every case, and the penetration test is the expensive part. Book it anyway: the auditor will expect one when the real engagement starts, so the money is pulled forward rather than added.

The Type 1, which is a real report and not a substitute

A Type 1 is an auditor opinion, so it clears the credibility bar every other item on the list has to argue past. It says your controls were suitably designed on one date. It says nothing about whether they operated, which is what a Type 2 adds. For a buyer's first year that is often enough, and a Type 1 with a committed Type 2 window is the most reliable way to keep a deal moving.

The cost is that you pay for two engagements in one year, roughly $35,000 to $60,000 CAD combined under 25 staff. It is only worth it if the Type 1 unblocks revenue. Type 1 against Type 2 takes the decision apart, and the interactive version answers it against your own dates.

The bridge letter is not this

A bridge letter covers the gap between the end of your last report period and today. It requires a report to bridge from, so it is not available to a company that has never been audited, and buyers who ask for one are assuming you have been. What a bridge letter can and cannot do sets the boundary. Offering one you cannot produce reads worse than offering nothing.

How to put it to them

  1. Ask what their vendor risk policy requires for a vendor in your tier, and whether it has an exception path with a named approver. Most do. This question decides everything else, and why your customer is asking covers it.
  2. Send the package unprompted rather than waiting to be asked for each piece. A reviewer who has to request four documents over three weeks will rate you lower than one who received them together.
  3. Put the audit commitment in the contract, not the email. Name the report type, the Trust Services category, the window and the delivery month. A commitment with a date is what lets their approver sign an exception.
  4. Offer a review point rather than an open promise. A clause that says you will provide the report by a date, and that they may re-assess if you do not, is easier for their legal team to accept than a best-efforts sentence.
  5. If they will not move, find out whether it is policy or preference. Policy cannot be argued with by your contact. Preference frequently can.

The two that make things worse

A trust page or platform dashboard offered as the main artifact tells an experienced reviewer that you have bought software rather than built controls. Use it as a convenience alongside real documents, never in place of them. Saying "we are SOC 2 compliant" when no report exists is the most damaging answer available. There is no such status. SOC 2 produces an attestation report, which the certification page explains, and the reviewer who eventually asks for the document will remember the first answer.

If nothing is accepted

Some buyers cannot move, usually the regulated ones and the ones whose request arrived through a signed security addendum. At that point you are deciding between the audit and the account. Whether it is worth it at your size puts the break-even in CAD against the contract value, and saying no covers the case where the deal does not pay for the report. If the date is the problem rather than the money, resetting an impossible date is the conversation to have first.

Will a customer accept a readiness assessment instead of an audit?

Sometimes, with technical reviewers, and almost never with procurement. It is not an auditor opinion and it does not claim to be, so present it as evidence of work in progress rather than as assurance.

Can we share a penetration test report with a customer?

Share the executive summary, the scope, the dates, the severity counts and the remediation status. Full technical reports contain exploitation detail for live systems and most testers provide a summary version for exactly this purpose.

Is ISO 27001 accepted in place of SOC 2 in North America?

It depends entirely on how the buyer's policy is worded. "SOC 2 or equivalent independent assurance" accepts it. "A current SOC 2 Type 2 report" does not, and the person asking you usually cannot change the wording.

How long will a buyer wait for the real report?

Six to twelve months is normal when a dated commitment is in the contract. What buyers do not tolerate is a date that moves twice, which is why the date you give should be the one your window and fieldwork actually support.

Does offering a substitute make us look unprepared?

Offering a considered package makes you look like a vendor who has done this before. Offering nothing, or offering vague reassurance, is what reads as unprepared. Reviewers see mid-audit vendors constantly.

Price the real report

An interim package buys time. Tell us your scope and dates and compare Canadian firms in CAD.

Get matched