How to Read a Vendor's SOC 2 Report in Twenty Minutes
Read four things before you read a single exception: the opinion, the period covered against today's date, the scope of the system described against what you are actually buying, and the complementary user entity controls, which are the controls the report assumes that you operate. Only then read the test results. Most vendor reviews run this backwards, open the exception table first, and miss the two problems that are far more common than a bad exception: a report that covers a different product than the one being sold to you, and a set of assumed customer-side controls that nobody in your organisation has been told about.
Twenty minutes is enough if you go in that order. Here is what each step is looking for.
Key takeaways
- Read four things before a single exception: the opinion, the period against today's date, the scope of the system described against what you are actually buying, and the complementary user entity controls.
- Most reviews run this backwards and miss the two commonest real problems: a report covering a different product than the one being sold to you, and assumed customer-side controls nobody in your organisation has been told about.
- An unqualified opinion does not mean there were no exceptions. Most first-year Type II reports carry at least one and still carry an unqualified opinion.
- Check the Trust Services Categories in scope. If your contract carries an uptime commitment and the report covers Security only, the report says nothing about availability controls.
- Section 5 is not covered by the opinion. Read it knowing nobody verified it.
The five sections, and what each is for
Every SOC 2 report has the same architecture, and knowing which section answers which question is most of the speed.
Section 1, the independent service auditor's report. The opinion. Who performed the examination, what they examined, which criteria, which period, and what they concluded. This is the only section written by the auditor and the only one carrying assurance.
Section 2, management's assertion. The vendor's own statement that the description is accurate and the controls were suitably designed and operating. Short, and useful mainly for confirming the scope in the vendor's own words.
Section 3, the system description. The narrative: what the service does, where its boundaries are, which components and environments are in scope, which subservice organisations it relies on, and what the vendor expects customers to do on their end. This is the longest section and the one that decides whether the report is relevant to you at all.
Section 4, the description of tests and results. Control by control: what the control is, what the auditor did to test it, and whether exceptions were noted. This is the section everyone reads first.
Section 5, other information provided by the entity. Not covered by the opinion. Management responses to exceptions live here, along with roadmap statements and anything else the vendor wanted to include without an auditor attached to it. Read it, and read it knowing nobody verified it.
Step one: the opinion, in one line
Find the concluding paragraph of Section 1 and identify which of four opinions you are holding.
Unqualified is the clean opinion, and it does not mean there were no exceptions. Most first-year Type II reports carry at least one exception and an unqualified opinion. You will also see this called an unmodified opinion, which is the term the attestation standards use; in a SOC 2 report the two mean the same thing.
Qualified means the auditor found something significant enough to say the criteria were met "except for" a named area. Everything outside that area still stands. A qualified opinion is a conversation, not an automatic rejection, and the right response is to read what it is qualified on and whether that area touches your use of the service.
Adverse means the controls taken as a whole did not meet the criteria. Rare, and a serious finding for a critical vendor.
Disclaimer means the auditor could not obtain enough evidence to conclude anything. Treat it as no report.
Also note who signed it, and confirm it is a CPA firm, because a "SOC 2" that was not issued by a licensed CPA firm is not a SOC 2. The auditee's view of what these opinions mean, and how a company should talk about its own exceptions, is covered in can you fail a SOC 2 audit; this article is the other side of that table.
Step two: the period, against today
Two dates matter: the period the report covers, and the report's issuance date. A Type II covering January to December, issued in February, read by you in November of the following year, is a document about a period that ended eleven months ago.
Ask two questions when the gap is material. What covers the time since the period ended, and when does the next report land? The vendor's usual answer to the first is a bridge letter, which is management's own unaudited representation rather than anything the auditor stands behind, and which we describe in what a bridge letter actually is. Whether you accept one should be a written policy in your vendor programme rather than a judgment call made under deal pressure.
A Type I deserves its own note. It attests to design at a single date and says nothing about whether controls operated. For a critical vendor, a Type I is a starting position, not an answer.
Step three: scope, which is where the real problems are
This is the step that gets skipped, and it is the one that finds genuine mismatches.
Which product, and which environments? Vendors with multiple products routinely have a report covering one of them. If you are buying the newer product and the report covers the flagship, the report is about something you are not using. This is common, it is rarely deliberate, and it is invisible unless you read Section 3.
Which Trust Services Categories? Security is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are optional. If your contract carries an uptime commitment and the report covers Security only, the report says nothing about availability controls. If you are relying on the vendor for processing accuracy, Processing Integrity is the category that speaks to it, and its absence is meaningful.
Which subservice organisations, and by which method? Section 3 names the providers the vendor depends on, usually its cloud host and sometimes a payment processor or a sub-processor doing real work. The critical detail is whether they are handled by the carve-out method or the inclusive method. Carve-out means those controls are excluded from the examination entirely, and the report tells you the vendor relies on them without testing them. Inclusive means they were examined as part of this report. Carve-out is normal and usually fine for a major cloud provider whose own report you can obtain, and it is not fine when the carved-out party is a small subcontractor doing something material that nobody has ever examined. Read the list and ask about anyone you have not heard of.
Step four: the controls the report assumes you operate
Section 3 ends with something most readers skim: complementary user entity controls, sometimes complementary user entity considerations. These are the controls the vendor assumes their customers operate, and the examination's conclusions depend on them.
Typical entries: you configure single sign-on and enforce multi-factor authentication for your users, you review your own users' access within the vendor's application periodically, you remove your users promptly when they leave, you manage your own encryption keys, you restrict who in your organisation holds administrative rights, you monitor your own use of the API.
Two things follow. First, these are effectively your obligations, and a clean vendor report does not cover you if you have not implemented them. Second, they are a checklist you can act on immediately: pull the list, assign each item to an owner in your organisation, and confirm it is actually done. In our experience this is the highest-value ten minutes in the whole review, and almost nobody spends it.
Some reports also list complementary subservice organisation controls, which is the same idea pointed at the carved-out providers.
Step five: now read the exceptions
With the previous four steps done, Section 4 becomes readable rather than alarming.
Look for clustering rather than count. Four exceptions spread across unrelated controls is a company that runs a real environment and reports honestly. Two exceptions both in logical access is a pattern, and a pattern says the control has a hole.
Look at whether the exception touches your use of the service. An exception in a physical security control at an office you will never visit is not the same as an exception in access provisioning for the production environment holding your data.
Look for compensating controls in the test result, and for the management response in Section 5. A response that acknowledges the finding, names the control that caught it, and dates the fix tells you something good about the company. A response that argues with the auditor or asserts the risk was low without evidence tells you something else.
Finally, look for the same exception two years running. That is the strongest single negative signal available in these documents, because it says the remediation plan was written and never executed.
The twenty-minute checklist
- Opinion type, and issued by a licensed CPA firm
- Period covered, issuance date, and what covers the gap to today
- Type I or Type II
- Product and environments in scope, matched against what you buy
- Trust Services Categories included, matched against what you rely on
- Subservice organisations, carve-out or inclusive, and whether you can obtain the carved-out reports
- Complementary user entity controls, extracted and assigned to owners on your side
- Exceptions: clustering, relevance to your use, compensating controls, response quality, repetition from last year
What this article does not cover
Deliberately narrow. Deciding which vendors get this level of review, how to tier them, what to do when a vendor refuses to provide a report, and how to run reassessment on a cadence are programme questions, and they belong to our vendor risk management guide rather than here. If you are on the other side of this transaction and trying to work out which SOC report your customer is even asking for, that is SOC 1 versus SOC 2 versus SOC 3.
Where Top Floor fits
Reading one report is a skill your team can learn from this article and should not outsource. Reading two hundred of them a year, keeping the complementary user entity controls assigned and verified, and chasing vendors whose reports have gone stale is a programme, and that is where compliance as a service earns its fee. If you already have someone who owns the vendor register and enjoys the work, buy them a calendar reminder rather than a consultancy.
Frequently asked questions
What are complementary user entity controls?
They are the controls the vendor assumes you, the customer, operate, and the report's conclusions depend on them. Typical examples are enforcing multi-factor authentication for your own users, reviewing and removing your users' access in the vendor's application, restricting administrative rights on your side, and managing your own keys. They appear at the end of the system description, they are frequently skimmed, and they are effectively your obligations. Extract the list, assign each item to an owner in your organisation, and verify it is actually in place.
What does the carve-out method mean in a SOC 2 report?
It means the controls at a subservice organisation the vendor relies on, most often a cloud provider, were excluded from the examination. The report describes the reliance and tests nothing at that provider. The inclusive method means those controls were examined as part of the report. Carve-out is normal and usually acceptable for a major provider whose own report you can obtain separately. It deserves a question when the carved-out party is a small subcontractor performing something material.
Does an unqualified opinion mean there were no exceptions?
No. An unqualified opinion means the auditor concluded the description is fairly presented and the controls were suitably designed and, for a Type II, operated effectively in all material respects. A report can carry that opinion and still list exceptions in the test results, and most first-year Type II reports do. What moves an opinion to qualified is pervasiveness: repeated failures clustered in one criterion, or failures with nothing else catching them.
How old is too old for a SOC 2 report?
That is your policy to set, not a property of the report. What matters is the length of the gap between the period end and today, what the vendor offers to cover it, and how critical the vendor is. Write the maximum acceptable gap into your vendor standard, decide in advance whether you accept bridge letters and for which tiers, and apply it consistently. Deciding this under deal pressure, vendor by vendor, is how exceptions to the policy become the policy.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.