How To Review a SOC 2 Report: A Section-by-Section Guide

How To Review a SOC 2 Report: A Section-by-Section Guide

A SOC 2 report is one of the most important documents you will receive when evaluating a vendor’s security posture. These reports can stretch to 85 pages or more, filled with technical language, control descriptions, and auditor assessments. Knowing how to review a SOC 2 report efficiently saves time and helps you make informed decisions about the vendors in your supply chain.

This guide breaks down each section, explains what to look for, and gives you practical tips for assessing whether a vendor meets your security requirements. Whether you are reviewing your first report or your fiftieth, the structure below will help you focus on the details that matter most. Our risk advisory services team uses the same approach when assessing third-party controls on behalf of clients.

What a SOC 2 report contains and why it matters

A SOC 2 report documents how a service organization protects customer data according to the Trust Services Criteria developed by the AICPA. The report is produced by an independent auditor and covers five potential categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Not every report includes all five, because the organization chooses which categories to include based on the services it provides and the data it handles.

The AICPA maintains the SOC suite of services and reporting framework that defines how these examinations are scoped and performed. Most reports follow a standard structure with four required sections and one optional section:

  • Section 1: Independent Service Auditor’s Report
  • Section 2: Management’s Assertion
  • Section 3: System Description
  • Section 4: Trust Services Criteria and Related Controls
  • Section 5: Other Information Provided by Management (optional)

Understanding what each section contains, and what it does not, is the key to an efficient review.

How to read the auditor’s opinion in Section 1

Section 1 is the single most important page in the entire document. It contains the independent service auditor’s opinion, which tells you whether the organization passed or failed its SOC 2 assessment.

There are two opinion types you need to understand:

Unqualified opinion: This is the outcome you want to see. An unqualified opinion means the auditor found the organization to be in SOC 2 compliance across all tested criteria. Every control was designed appropriately (in a Type 1 report) and operated effectively throughout the examination period (in a Type 2 report).

Qualified opinion: A qualified opinion means the auditor identified at least one area where the organization did not meet the SOC 2 criteria. The issue could be relatively minor, for example a few new hires who did not complete security awareness training on schedule, or it could be severe, such as a data store that lacks encryption at rest. A qualified opinion does not automatically disqualify a vendor, but it should trigger additional due diligence to assess the risk to your organization.

Section 1 also outlines the scope of the examination. Pay attention to the system being reviewed, which Trust Services Categories were included, and, for a SOC 2 Type 2 report, the examination period. A report covering only three months provides less assurance than one covering a full twelve months.

What management’s assertion tells you in Section 2

Section 2 is management’s assertion, where the company undergoing the SOC 2 audit confirms two things: first, that it prepared the system description found in Section 3, and second, that the controls described were suitably designed and operating effectively during the examination period.

This section does not contain technical details. Its purpose is to put the organization’s management on record as vouching for the accuracy and completeness of the information in the report. While brief, it establishes accountability. If the system description or control descriptions later prove inaccurate, management cannot claim the auditor acted alone.

For your review, a quick read of Section 2 is sufficient. Confirm that the assertion covers the same system, categories, and time period described in Section 1. If there are discrepancies, that is worth flagging.

How to evaluate the system description in Section 3

Section 3 is typically the longest part of the document, and it contains the operational details that matter most for vendor risk management. Several subsections deserve careful attention.

Overview of services provided

This subsection describes the services the organization delivers. Confirm that the system described here matches the service or application you actually plan to use. If your vendor offers multiple products and the audit only covers one of them, the findings may not address the risks relevant to your relationship. The language here should be objective and factual, because marketing language like “best in class” has no place in an audit document.

Principal service commitments and system requirements

This is where the organization states its commitments to customers as they relate to the Trust Services Categories in scope. For example, if Availability is included, you should see specific commitments around uptime levels or disaster recovery timelines. Compare these commitments against your own contractual requirements. If the vendor promises 99.5% uptime in the report but your SLA requires 99.9%, that gap is worth discussing.

Components of the system

This subsection covers the technical infrastructure: the cloud service provider, hosting environment, software tools, data types processed or stored, and the organization’s policies and procedures. It gives you a quick snapshot of the technology stack and data handling practices. If you have specific requirements around data residency or encryption standards, this is where you confirm whether they are met.

Complementary user entity controls (CUECs)

Complementary user entity controls are the controls that the service organization expects you, the customer, to have in place for the system to function securely. A common example is account deprovisioning: when you terminate an employee, it is your responsibility to revoke that user’s access or notify the vendor to remove the account. If you fail to do so, the vendor cannot be held responsible for unauthorized access through that account.

Review the CUECs carefully and verify that your organization has corresponding controls in place. If you do not, those gaps represent real security risks that fall outside the vendor’s SOC 2 compliance scope.

Complementary subservice organization controls (CSOCs)

CSOCs describe the shared responsibilities between the service organization and its own third-party vendors, also called subservice organizations. This section tells you where your data might be hosted beyond the primary vendor and who shares responsibility for its security. If the vendor relies heavily on subservice organizations, you may want to request similar audit reports from those third parties as well.

What to look for in Section 4: controls and test results

Section 4 is where most reviewers go first, and for good reason: it contains the list of controls, the auditor’s testing procedures, and the results of those tests. Each control is mapped to a specific Trust Services Criterion, and the auditor describes how they tested whether the control was designed appropriately and operating effectively. This is the same testing discipline our audit and assurance services practice applies across engagements.

The critical thing to look for here is exceptions. An exception (also called a deviation) occurs when the auditor performs a test and finds that a control was not operating as intended. Not every exception is equally serious. A single instance of a late access review is different from a systemic failure to encrypt sensitive data. For each exception, consider:

  • What control failed, and how does it relate to the data or services you use?
  • Was the failure a one-time event or a recurring pattern?
  • Does the exception affect any of the Trust Services Categories most relevant to your use case?

If the SOC 2 audit report includes multiple exceptions in areas critical to your operations, that should inform your risk assessment and potentially your decision about continuing the vendor relationship.

How Section 5 addresses exceptions and management responses

Section 5 is optional, but when included, it typically contains management’s response to the exceptions noted in Section 4. This can be valuable information. A vendor that acknowledges an exception and describes concrete remediation steps, such as implementing a new monitoring tool or updating a policy, demonstrates a commitment to improvement.

On the other hand, vague responses like “management is aware of the issue” without a clear action plan should raise concerns. Pay attention to whether the remediation timeline is realistic and whether the proposed fix actually addresses the root cause of the exception.

These documents are dense, but they follow a predictable structure. By focusing on the auditor’s opinion, the system description, the CUECs, and the control test results, you can conduct an effective review without reading every page. Use this guide as a checklist each time you receive a new report, and you will be able to evaluate vendor security with confidence. For broader context on how independent control attestation fits within audit standards, the AICPA also publishes guidance through its auditing standards resources.

Frequently Asked Questions

What is a SOC 2 report?

A SOC 2 report is an independent audit report that evaluates how a service organization protects customer data based on the AICPA’s Trust Services Criteria. It covers areas such as security, availability, processing integrity, confidentiality, and privacy. Organizations request SOC 2 reports from their vendors to verify that appropriate controls are in place and operating effectively.

What is the difference between a SOC 2 Type 1 and Type 2 report?

A SOC 2 Type 1 report evaluates whether controls are suitably designed at a specific point in time. A SOC 2 Type 2 report goes further by testing whether those controls operated effectively over a defined examination period, typically six to twelve months. Type 2 reports provide stronger assurance because they demonstrate sustained compliance rather than a single snapshot.

What does a qualified vs. unqualified opinion mean in a SOC 2 report?

An unqualified opinion means the auditor found the organization in full SOC 2 compliance, with all controls properly designed and operating effectively. A qualified opinion means the auditor identified at least one area of non-compliance. A qualified opinion does not necessarily mean the vendor is unsafe, but it requires further investigation to understand the severity and relevance of the finding.

What are complementary user entity controls?

Complementary user entity controls (CUECs) are security responsibilities that fall on the customer rather than the vendor. Common examples include deprovisioning terminated employees, enforcing multi-factor authentication on user accounts, and monitoring access logs. Failing to implement required CUECs can create security gaps that the vendor’s own controls cannot address.

How often should you request a new SOC 2 report from a vendor?

Most organizations issue updated SOC 2 Type 2 reports annually. You should request a current report at least once per year as part of your ongoing vendor risk management program. If a vendor undergoes significant changes, such as a major infrastructure migration or an acquisition, requesting an interim report or bridge letter is a reasonable precaution.

Which sections of a SOC 2 report should you read first?

Start with Section 1 to check the auditor’s opinion, then move to Section 4 to review control exceptions. After that, read Section 3 to verify the system description covers the services you use and to review the complementary user entity controls. This order lets you identify the highest-risk findings quickly before reviewing the full detail of the report.

Let’s talk about your business.