Why your customer is asking for SOC 2
Nobody at your customer wants to read your report. Somebody there has a control that says third parties are assessed before onboarding, and your report is the cheapest way for them to close it.
Your customer is asking for a SOC 2 report because they have a vendor risk obligation of their own, usually a control in their own SOC 2 or ISO 27001 program that says significant third parties are assessed before onboarding and reviewed annually. They did not choose SOC 2 out of preference. A report from a CPA firm is the one artifact that closes their control with no work on their side. What they need is evidence they performed an assessment, and more than one artifact provides it.
CC9 The criteria that puts your customer in this position
Annual How often they must repeat the assessment on you
Who inside the customer actually raised it
The request arrives through sales, so it looks like a sales requirement. It is almost never one. Work out which of these it is, because each has different room to move.
| Origin | What they are closing | Room to negotiate |
|---|---|---|
| Their own SOC 2 or ISO 27001 vendor management control | Evidence that a third party was assessed and rated before onboarding | Real. A questionnaire plus a penetration test plus a dated audit plan often satisfies the control |
| A procurement checklist inherited from a template | A tick in a field | Considerable, but nobody in the room has authority to change the field |
| Their security team, who will read it | Whether you can be trusted with their data | Some, and they are the easiest to satisfy with substance rather than paper |
| Legal, through a security addendum in the contract | Contractual allocation of risk | Least. This becomes an obligation with a date, not a request |
| A regulator behind the customer, in finance or health | Statutory outsourcing requirements | Almost none, and the report is the smaller part of what they will want |
The first two rows cover most requests to a Canadian SaaS company selling into a US enterprise, and both are more flexible than they appear. The last two are not. Recognising them early stops you spending a month negotiating with somebody who cannot say yes.
What their obligation actually says
If your customer holds a SOC 2 of their own, their auditor tests them under the CC9 risk mitigation criteria and, for the vendors that matter most, under the subservice organization treatment in their system description. The wording in their policy will be close to this.
- Assessed before onboarding
- Some documented review of the vendor happened before data flowed. A SOC 2 report is the easiest evidence. A completed questionnaire with a risk rating is also evidence, and it is what most of their smaller vendors provide.
- Risk rated
- Vendors are tiered so effort is proportionate. If you do not touch customer data, you may be a tier below the one that requires a report, and nobody has checked which tier you are in.
- Reviewed annually
- The assessment repeats. This is why buyers ask for a current report every year and why a lapsed report creates a problem at their renewal, not yours.
- Exception approved
- Almost every vendor risk policy has a documented exception path with a named approver and an expiry date. This is the mechanism that gets a mid-audit vendor onboarded, and asking about it directly is legitimate.
The mirror image, from the side where you are the customer, is on vendor management for SOC 2. It shows what the person on the other side has to produce for their own auditor.
What they do with the report when it arrives
Less than you think, and not the parts you worked hardest on. A reviewer opens the opinion, the scope, the period covered and the exceptions, in that order, and most reviews are decided inside ten minutes. What your customer's reviewer checks walks the same document in the order they open it, and how to read a SOC 2 report is the same skill applied to your own suppliers.
The question worth asking out loud
Ask your contact: "What does your vendor risk policy require for a vendor in our tier, and is there an exception process while our audit completes?" It signals you have done this before, and the answer tells you whether you are negotiating a substitute or a deadline. Most founders never ask because it feels like an admission.
The Canadian wrinkle
A US enterprise buying from a Canadian vendor is also working out where their data will sit and under whose law. That is a separate question and the report does not answer it, which is why the security addendum shows up beside the report request. Expect questions about data residency, cross-border transfer and breach notification timing, and expect your own PIPEDA obligations to be treated as your problem. Your report says nothing about PIPEDA. SOC 2 and PIPEDA sets out which obligations the audit does not discharge, and data residency covers where the questions land for a company hosting in Canada.
If you decide not to comply
Sometimes the right answer is that the deal does not justify the spend, and your customer's control has an exception path anyway. That path has an expiry date and it usually costs you something at renewal rather than at signature. What happens if you say no works through which accounts survive it and which do not, and whether it is worth it at your size puts a number against the decision.
Can we ask our customer why they need it?
Yes, and you should. Ask what their vendor risk policy requires for a vendor in your tier. It is a normal question between vendor and buyer, and the answer frequently reveals that a questionnaire and a penetration test close the same control.
Does our customer read the whole report?
Rarely. They read the auditor's opinion, the scope and period, the exceptions and the complementary user entity controls. The control matrix is skimmed. A clean opinion on the wrong scope is worth less to them than a qualified opinion on the right one.
Why do they want a Type 2 rather than a Type 1?
Because a Type 1 says the controls were designed on one date and a Type 2 says they operated over a period. Their own auditor is more likely to accept the second as evidence of ongoing assurance. Many will take a Type 1 for a first year with a committed Type 2 date.
They asked for SOC 2 but we hold ISO 27001. Is that enough?
Sometimes, and it is worth offering. A North American buyer whose policy says "SOC 2 report or equivalent independent assurance" can usually accept a current ISO 27001 certificate with the Statement of Applicability. A policy that names SOC 2 specifically usually cannot.
Will they accept a report from any auditor?
It has to be a CPA firm licensed to perform the examination, and a name they can verify. Beyond that, buyers rarely care which firm. They care about the scope, the period and the exceptions.
Compare Canadian auditors
Once you know what your customer will accept, the next decision is who signs the report.
Get matched