How to Read a SOC 2 Report

A guide to understanding the different sections and their content

Written By Micah

What is a SOC 2 report?

The SOC 2 report, prepared by a third-party auditor, is based on the AICPA (American Institute of Certified Public Accountants) Trust Services Principles, which assess five criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory and is also referred to as the Common Criteria. You can add any relevant TSCs to your SOC 2 based on customer inquiries or risks identified in your organization’s annual risk assessment. For more information, check out our blog post here.

Why review a SOC 2 report?

It’s important to review a SOC 2 report to gain a full understanding of an organization's system and cybersecurity program. A company's SOC 2 report is often reviewed during the initial due diligence process when evaluating a new a vendor, as the report will inform you of both controls the firm has implemented as well as controls that end users should implement to make the product or service they are purchasing or using work securely.

While conducting your review, there are a few items to look for. You can use this checklist to help you familiarize yourself with the review process. The sections are explained in more detail below.

  • Confirm the report is still valid - Is the report over a year old? If so, get a new one, generally companies get a fresh SOC 2 audit performed every year

  • Look for the auditor’s opinion - you want it to be “unqualified”, if not, read more below. A keyword search can be useful here

  • Skim/read the System Description - understand the overall control environment

  • Look for test exceptions - ideally there are none, but if there are exceptions noted it's useful to dig a bit into the context of the finding

    • For example: what was the finding? What is management’s response (documented in Section 5 of the report)? Does this exception impact your system?

  • Are there any Complementary User Entity Controls you should be implementing as the end user?

The sections of a SOC 2 report

The cover page

The SOC 2 report wastes no time in giving you helpful information. Starting on the cover page, you’ll find everything from the type of SOC 2 report (Type 1 or Type 2), the monitoring period, the relevant TSCs, and sometimes, the auditing firm that conducted the audit.

A Type 1 report examines the suitability of the design of controls at a single point in time, and Type 2 examines the suitability of both the design and the operating effectiveness of controls over a specified period — usually between six and twelve months. Both reports are considered valid for one year.

Section 1*: Management’s Assertion

*Sometimes Section 1 and 2 are flipped in order

This statement from management explains that the described controls were accurately represented and effective at mitigating risk during the assessment period. It is presented in a standard, templated format that all companies follow, but may have some unique language. This section is generally boilerplate, and does not contain very much unique information.

Section 2*: Opinion Letter or Auditor’s Report

*Sometimes Section 1 and 2 are flipped in order

This is the independent auditor's opinion on the fairness and effectiveness of the organization’s controls in meeting objectives or criteria. Through the auditor’s evaluation of an organization’s compliance program, they will determine if the organization is compliant and functioning as expected.

They will express their opinion using one of the four terms below:

  • Unqualified - this is what you want to see! Think of this as an “A” as it’s the highest rating for a SOC 2 report as it indicates there were no major concerns or issues during the audit. It is possible to achieve an unqualified opinion with minor test exceptions or findings noted, so it is important to still review Section 4 of the report to see if there were exceptions noted that might be relevant to your organization.

  • Qualified - this means there were major issues or findings identified over the course of the audit. A qualified opinion does not always mean that you should not do business with that firm, but it will mean you need to review the testing results to see if any findings impact your organization’s compliance program.

  • Adverse - You will likely never see this opinion as it is in no one's best interest to publish a report with this opinion. If you do see this, then seriously consider the risks of working with this service provider.

  • Disclaimer - this will appear when the auditor can't test or can't conclude on a portion of the compliance program. It is not necessarily a bad thing, but you should determine whether their disclaimer will impact your compliance program.

Section 3: System Description

The System Description is the bulk of the SOC 2 report and is key to understanding an organization’s security practices. This section is basically the organization's security program and policies explained in plain language. The System Description has sections that explain all aspects of the system, including people, processes, data, access controls, monitoring, infrastructure, incident response. If you are only going to read one section of the report, generally the Section 3 is the most useful.

You’ll typically find Complementary User Entity Controls (CUECs) at the end of the System Description. CUECs are controls that the end customer is responsible for implementing in order for the utilized product/service/system to function as intended.

Section 4: Controls, Control Objectives, and Test Results

If your goal is to evaluate specific activities an organization is doing to ensure data security, then you’ll want to spend some time in Section 4 of the report. This section lists out the specific security controls tested by the auditor to evaluate how well those controls were performed. Type 2 reports will be more detailed regarding auditor testing than Type 1 reports, because the Type 2 audit is focused on testing the effectiveness of controls over a period of time. A Type 1 report is not required to show the testing approach used by the auditor, but you can safely assume that they inspected documents and made inquiries of control performers and other company staff.

Skim this section looking for any testing exceptions. If you find any, look for the nature of the exception and determine whether it impacts your control environment. For example, if a finding relates to an aspect of their system or product that you don't use or rely upon in your control environment, it may not apply to you. If a finding is relevant to your controls, then consider whether they have compensating controls that can be relied upon or whether you need to put controls in place to protect your control environment. Section 5 (more on that below) may include the company’s response to findings, so be sure to look there too.

Section 5: Other Information Provided by the Organization

Sometimes, the audited organization may include additional information not covered by the auditor’s report, such as plans for control improvements or the management’s response to exceptions. It is important to review the contents of this section if it is present, as it may hold useful information that can be used in your due diligence, vendor review, and vendor management programs.

For information on how to share your organization’s SOC 2 report, click here. You can also reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.