SOC 2 explained: what is in the report and how to read it

IT-audit9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

A SOC 2 report is the most requested form of assurance in the technology sector. Customers want to know whether you control their data, and pointing their procurement team at your own security page will not settle it. What actually sits inside such a report, and what it does and does not say, is less widely understood than the request for one.

What SOC 2 is

SOC stands for System and Organization Controls, a framework from the AICPA, the American professional body for accountants. A SOC 2 report is an attestation: an independent auditor assesses the controls around your service and issues an opinion on them. It is not a certificate. No body hands out a mark of approval and there is no logo for your website. What you get is a report, often fifty to a hundred pages, that you share with customers under NDA.

SOC 1 and SOC 3 sit alongside it. SOC 1 covers controls relevant to your customers financial reporting, comparable to ISAE 3402. SOC 3 is a shortened, publicly shareable summary of a SOC 2 without the test detail.

The five Trust Services Criteria

The criteria fall into five categories: security, availability, processing integrity, confidentiality and privacy. Security is always in scope. That category holds the common criteria, the base set covering governance, risk assessment, access management, change management, monitoring and incident response.

You add the other four when they match what you deliver and what your customers expect. A SaaS provider with an availability commitment in its contracts includes availability. If you process personal data on behalf of customers, the privacy category comes into view. Every extra category costs audit hours, so scoping is a trade-off rather than a contest over who covers the most criteria.

Type I and Type II

A Type I report assesses whether controls are suitably designed and in place at a point in time. A Type II also tests whether they operated across a period, at least three months and in practice more often six to twelve. In a Type II the report states the auditor test procedures and results for each control. That is why enterprise customers almost always ask for Type II: design without operation says little about the rest of the year.

What the report contains

Four parts. The auditor opinion comes first, with the scope, the period and any limitations. Then a written assertion from your own management that the system description is accurate. Then the system description itself: which service you deliver, through which people, processes and systems. And finally the longest part, the controls with the auditor test and outcome for each one.

That last part carries the information that matters. Where a control has an exception, the auditor describes what was found and how often. A report with a few documented exceptions is not automatically weak. A report with no exceptions at all from an organisation that only started last year raises more questions than it answers.

Two elements get skipped regularly. Complementary user entity controls are the controls you expect your customer to operate, for example enabling multi-factor authentication on their side. Without those, your control environment is incomplete. And for subservice organisations such as your hosting provider, your report picks between the carve-out method, referring to their own assurance report, and the inclusive method, testing their controls inside yours.

Reading the opinion

An unqualified opinion means the auditor considers the description accurate and the controls effective. A qualified opinion names where it falls short. Always check the period as well: a report covering the year to 31 March is dated somewhere in the middle of the following year. For the months in between, customers ask for a bridge letter, a statement from your management that nothing material has changed.

What SOC 2 is not

Not a certificate, and not a guarantee that you will not be breached. The report speaks to the controls that were in scope, during the period tested. A SOC 2 report on your production environment says nothing about the company you acquired last month. It also does not replace ISO 27001: that standard certifies a management system, while SOC 2 reports on how controls operated. European customers ask for ISO 27001 more often, US parties almost always for SOC 2.

The annual cycle

Because a Type II covers a period, customers expect a new report every year with no gap between periods. That makes SOC 2 less of a project and more of a rhythm: evidence built up through the year, controls demonstrably performed monthly or quarterly, and an auditor who looks in twice a year rather than digging through everything once.

Getting started

When a customer asks for a report, start with which categories they actually need. It is almost never all five.

How do you obtain a SOC 2 report?

The engagement starts with choosing the auditor. A SOC 2 report has to be issued by an independent, qualified auditor; outside the US the report is formally issued under ISAE 3000, and in the Netherlands these are typically RE-certified IT auditors. Choose a firm that understands your technology stack, otherwise a lot of time is lost on explanation.

Scoping follows: which service, which systems and which Trust Services Criteria. Then a readiness assessment, establishing per control what is in place and what is missing. The gaps you close in this phase do not end up as exceptions in your first report. Only then does the observation period start for a Type II, followed by the audit and the delivery of the report, with room for a management response to any findings. Expect six to twelve months from start to report for a first Type II engagement.

Further reading: the difference between Type I and Type II, the Trust Services Criteria in detail, preparing for your SOC 2 audit and SOC 2 next to ISAE 3402. Our approach, timelines and cost are on the SOC 2 audit page.

Frequently asked questions

Is SOC 2 a certificate?+

No. SOC 2 is an attestation: an independent auditor gives an opinion on your controls in a report of often fifty to a hundred pages, shared with clients under NDA. There is no certifying body and no seal.

Which Trust Services Criteria do you have to include in a SOC 2?+

Security is always mandatory. Availability, processing integrity, confidentiality and privacy are added only when they fit your service and what clients contractually expect. Every extra category adds audit hours, so choose based on demand, not completeness.

Who can issue a SOC 2 report?+

An independent, qualified auditor. Outside the US the report is formally issued under ISAE 3000; in the Netherlands these are typically RE-certified IT auditors. Pick an auditor with experience in your type of organization and technology.

How do you obtain a SOC 2 report and how long does it take?+

The path runs from scoping and a readiness assessment to the observation period and the audit itself. For a first Type II, expect six to twelve months from start to report; a Type I can be issued faster and often serves as an interim step.

What is the difference between SOC 2 and ISO 27001?+

ISO 27001 certifies a management system against a fixed standard; SOC 2 reports on the operation of controls, including test results per control. European clients more often ask for ISO 27001, American clients almost always for SOC 2. Many organizations end up needing both.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us