Skip to content
SecuriFii

Choosing

How to read a supplier’s SOC 2 report in ten minutes

A supplier sends a SOC 2, it goes in the vendor file, and the review is recorded as satisfied. The report is usually eighty pages and the part that would have changed your answer is about a page and a half of it. Here is where to look, in the order that finds problems fastest.

Facts checked2026-09-11

Five checks, in order

CheckWhat you are looking forThe failure it catches
TypeType 1 or Type 2. Type 1 covers design at a date only.A Type 1 filed as though it evidenced controls operating.
ScopeWhich systems and services the report covers.A valid report for a different product. The most common false comfort in vendor review.
PeriodThe observation window, and how long ago it closed.A report whose period ended fourteen months ago, covering a year you no longer care about.
ExceptionsThe testing section — what the auditor found, and management’s response.Real findings sitting behind an unqualified opinion.
CUECsComplementary user entity controls: things YOU must do.Obligations transferred to you that nobody in your organisation has accepted.

A SOC 2 report is confidential and normally shared under NDA, so expect to sign one. If a supplier will not share the report at all, a summary or the auditor’s opinion page alone is a considerably weaker basis for a review.

Check the type before anything else

A Type 1 reports on whether controls were suitably designed and implemented as at a single date. A Type 2 also reports on whether they operated effectively across a period. Only the second is evidence that anything actually ran.

This is a thirty-second check that occasionally ends the review, and it is missed regularly because both documents are titled SOC 2 and look identical from the cover. If you asked for a SOC 2 meaning a Type 2 — which is what most vendor questionnaires intend — and received a Type 1, you have a report about intentions.

It is not nothing: a Type 1 from a real CPA firm tells you controls were designed and in place. But it cannot support a conclusion about operation, and filing it as though it could is the quiet version of not doing the review.

Scope: the check that catches most problems

The scope of a SOC 2 is set by the service organisation, through the system description and which Trust Services Criteria categories it selected. That latitude is legitimate and it is why scope deserves your attention more than the opinion does.

Read the system description and answer one question: does this cover the specific product, platform or service we are buying? Large suppliers frequently have reports covering one platform and not another, or covering a core service while the module you are adopting sits outside it. The report is entirely valid and tells you almost nothing about your purchase.

Then check which criteria categories are included. Security, through the common criteria, is in every SOC 2. Availability, Processing Integrity, Confidentiality and Privacy are optional. If uptime is the thing you are relying on and Availability was not in scope, the report does not speak to it — and a supplier selecting only Security is making a reasonable choice that your review has to account for.

The two sections everyone skips

First, the testing section — controls, tests performed, results. This is where the report says what actually happened, and it is where exceptions live. Two things surprise reviewers: exceptions can appear under an unqualified opinion, and a qualified opinion is usually confined to one area rather than being a general failure. So neither the opinion paragraph alone nor the word "qualified" alone tells you enough. Read the exceptions and read management’s response to each one, which is where you find out whether the issue is fixed, being fixed, or accepted.

Second, the complementary user entity controls — the CUECs. This is a list of controls the report assumes YOU operate, without which the supplier’s controls cannot achieve what they claim. Configuring access in their console, managing your own users and offboarding, enabling the features that make their assurances true, reviewing the logs they expose.

The CUEC list is the most consequential page in the document for a customer, because it is the part that transfers work to you, and it is almost never read by whoever files the report. Extract it, assign each item an owner in your organisation, and treat any you cannot honestly claim as a gap in your controls rather than theirs. An auditor reviewing your third-party management will ask about exactly this.

Where the supplier’s own suppliers went

Most services run on other services, and the report handles that in one of two ways worth telling apart.

Under the inclusive method, the subservice organisation’s controls are in scope and are tested alongside the supplier’s own. Under the carve-out method — much more common — they are excluded from testing, and the report instead discloses complementary subservice organisation controls: the controls the supplier expects its provider to operate.

The distinction matters because a carve-out disclosure is a representation, not a tested assertion. Your supplier is saying it has a basis to expect those controls exist; the auditor did not examine them. So if your supplier carved out its cloud provider, the report tells you nothing tested about that provider, and the assurance chain continues one link further than the document covers.

That is usually fine and usually resolvable — major providers publish their own reports. But it means "they have a SOC 2" is a statement about one layer, and knowing which layers were carved out is part of knowing what you actually verified.

Age, and the letter that covers the gap

A Type 2 covers a period that has closed, and reports are issued some months after that. A report you receive today might cover a window that ended a year ago, which means your assurance is about a version of the supplier that may no longer exist.

The usual bridge is a bridge letter, sometimes called a gap letter, covering the interval between the period end and your own date. Know what it is worth: it is issued and signed by the supplier’s management, not their auditor, because the CPA firm’s attestation is limited to the period examined. It asserts the controls are still operating and discloses material changes, and it typically covers up to about three months.

So a bridge letter is the supplier’s own assertion stretched over the gap. Accept it for a short interval, and treat a long gap with only a bridge letter as what it is: an unaudited claim about the most recent period, which happens to be the period you care about most.

Common questions

What should I check first in a supplier’s SOC 2?

Whether it is a Type 1 or Type 2, then the scope. A Type 1 covers design at a single date and cannot evidence that controls operated. Scope catches the most common problem in vendor review — a valid report that covers a different product from the one you are buying.

What are complementary user entity controls?

Controls the report assumes you operate, without which the supplier’s controls cannot achieve what they claim — managing your own users, configuring access, enabling features, reviewing logs they expose. Extract the list, assign owners, and treat anything you cannot claim as a gap in your controls.

Does an unqualified opinion mean there were no findings?

No. Exceptions can appear beneath an unqualified opinion, and a qualified opinion is usually confined to one area rather than being a general failure. Read the testing section and management’s responses rather than stopping at the opinion paragraph.

What is the carve-out method, and why does it matter to me?

It means the supplier’s own providers were excluded from testing, with their expected controls disclosed instead. That disclosure is a representation, not something the auditor examined — so if your supplier carved out its cloud provider, the report tells you nothing tested about that provider.

How old is too old for a SOC 2 report?

Reports cover a closed period and are issued months later, so some age is normal. A bridge letter conventionally covers up to about three months. Beyond that you are relying on the supplier’s unaudited assertion about the most recent period, which is usually the period you care about most.

Is a bridge letter signed by the auditor?

No — by the supplier’s own management. The CPA firm’s attestation is limited to the period it examined, so it neither issues nor signs the letter. That makes a bridge letter the supplier’s assertion rather than independent assurance.

The bottom line

Type, scope, period, exceptions, CUECs — in that order, and it takes ten minutes. The scope check catches more bad reviews than everything else combined, and the CUEC list is the page that quietly makes some of the supplier’s assurance your job.

Related insights