Certification
You have an exception in your SOC 2. Now write the response
The first Type 2 often produces an exception and the room treats it as a failure. Customers who read these reports regularly do not — but they do read the paragraph you write underneath it, and that paragraph is entirely yours.
Facts checked — 2026-09-11
How should you respond to a SOC 2 exception?
An exception means the auditor tested a control and found an instance where it did not operate as described — a review done late, a ticket approved by the person who raised it. It is recorded alongside your response, and the report can still carry an unqualified opinion.
Write the response as a corrective action rather than a defence: what happened, why the process allowed it, what changed as a result, and when. "One of twelve monthly reviews was completed nine days late owing to a single owner being absent; the review now has a named deputy and an automated reminder, effective March" tells a reader the system works. "Management notes this was an isolated administrative oversight" tells them nothing and invites the follow-up question.
Resist the urge to minimise. A reader who is assessing you has seen many of these, and a response that names a real cause reads as an organisation that understands its own processes — which is, in the end, what they are trying to find out.
The bottom line
Cause, change, date. A response in that shape converts an exception from a blemish into evidence that your corrective action process actually runs.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.