GetSOC2

Who can you give your SOC 2 report to?

Every SOC 2 report contains a paragraph saying who it is for. Most companies never read it, then find out from a customer's legal team or their own auditor that it matters.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

A SOC 2 report is a restricted-use report. The auditor's opinion states it is intended for the service organization, its user entities (your customers) and others with sufficient knowledge to understand it, such as prospective customers and the auditors of those customers. In practice that means customers and serious prospects, under an NDA, and not the public. If you want something you can publish openly, that is what a SOC 3 report is for.

What does the restricted-use paragraph say?

Near the end of the auditor's opinion there is a paragraph headed something like "Restricted use". It names who the report is intended for and says it is not intended to be used by anyone else. The exact wording varies by audit firm and by report, so read yours rather than relying on a summary. The people it typically covers are your management, your user entities, the auditors of those user entities, prospective user entities, and regulators.

The reason is practical. A SOC 2 report describes your system, your controls, the auditor's tests and any exceptions in enough detail to be useful to a customer's reviewer, and also useful to someone attacking you. A reader without the context to understand an exception can also misread it as a failure.

Who usually qualifies to receive it?

Who typically may receive a SOC 2 report
RequesterUsually acceptable?Condition worth applying
Current customerYesConfidentiality terms in the contract or an NDA covering security documents
Prospect in an active dealYesA signed NDA, and an opportunity your sales team can name
A customer's external auditorYesReleased through the customer, under the same confidentiality terms
A regulator overseeing a customerGenerally yesThrough the customer, on request
Investor or acquirer in due diligenceCheck with your audit firmUnder the deal's NDA; some firms want this named
Anyone who fills in a web formNoOffer the SOC 3 or a trust centre summary instead
A competitor posing as a prospectNoThe approval step exists for this case

When should you use a SOC 3 report instead?

A SOC 3 report is a short, general-use summary of the same examination, without the detailed description of tests and results. It can go on your website or in a sales deck without an NDA. Your auditor can issue one alongside the SOC 2 for an added fee. Most enterprise reviewers still ask for the SOC 2, so the SOC 3 does not save the NDA step for serious buyers. It does stop you sending the full report to people who only need to know a report exists. See SOC 1 vs SOC 2 vs SOC 3 for how the three differ.

What should you check in your audit firm's terms?

Your engagement letter with the audit firm may say how the report can be distributed, whether it can be reproduced in part, and whether the firm's name can be used in marketing. Check three things before you set a sharing process:

  1. Whether the whole report must go out intact. Sending selected pages usually is not allowed. Share the full report or none of it.
  2. How you may describe it in marketing. "SOC 2 certified" is wrong in any case. "We hold a SOC 2 Type 2 report covering security and availability for the period ending..." is accurate.
  3. Who may receive it beyond the standard list. Investors and acquirers are the common grey area. Ask the firm rather than guess.

How do you actually control who gets it?

The mechanics, a single release channel with an NDA, an approval step, a log of every release and watermarked copies, are the same whether you use a trust centre platform or a request form. TrustCenter has the step-by-step: how to share a SOC 2 report safely, and NDA-gated security documents for the gate itself.

Send the current period, with a bridge letter

A report whose period ended many months ago needs a bridge letter covering the gap. Send them together, and retire superseded reports from wherever you keep them.

Common questions

Can we post our SOC 2 report on our website?

No. A SOC 2 report is restricted use. Publish a SOC 3 report or a trust centre summary openly, and keep the SOC 2 behind an NDA for customers and prospects.

Can a customer give our SOC 2 report to their auditor?

Generally yes. Auditors of user entities are among the intended users in typical restricted-use wording. Make sure your NDA allows sharing with the recipient's auditors and advisers under the same confidentiality terms.

Do we need an NDA before sending a SOC 2 report?

It is the normal practice. The NDA, or confidentiality terms in an existing contract, records that the recipient accepts the report's restriction and will not pass it on beyond the people it is intended for.

Can we send only the pages a buyer asked about?

Usually not. Audit firms expect the report to be shared intact, because a page out of context can misrepresent the opinion. Send the whole report and point the reviewer to the section they need.

Find an auditor for your next report

Compare Canadian SOC 2 firms, or describe your scope once and get quotes.

Get matched