How to review a supplier SOC 2 report
Blog

SOC 2 Report Review: How to Vet a Supplier Properly

To review a supplier’s SOC 2 report, read four things in order: the auditor’s opinion, the dates the report covers, the system description to confirm the product you buy was actually in scope, and the test results section where exceptions are recorded. Then read the complementary user entity controls, because those are the security obligations the report places on you rather than on your supplier.

Most Australian businesses receive a SOC 2 report, file it, and treat the supplier as assessed. That is a wasted opportunity and a genuine risk, because a report can be clean, current and completely irrelevant to the service you actually purchased. This guide covers how to read one properly in about twenty minutes.

What is a SOC 2 report and who issues it?

A SOC 2 report is an attestation report issued by an independent accounting firm about the controls a service organisation has in place. The framework is maintained by the American Institute of Certified Public Accountants, and only a licensed CPA firm can issue one.

SOC 2 is an attestation, not a certification. Nobody issues a SOC 2 certificate, and a supplier claiming to be SOC 2 certified is either using loose language or does not understand what they bought. What exists is a report, covering either a point in time, which is a Type 1, or a period of operation, which is a Type 2. A Type 2 is substantially more useful because it tests whether the controls actually worked over months rather than whether they existed on one day.

SOC 2 reports are also restricted use documents. Suppliers will normally require a non disclosure agreement before releasing one, which is normal and not a red flag. Refusing to release one at all, while claiming to hold it, is.

What are the sections of a SOC 2 report?

A SOC 2 report has five sections, and knowing which is which saves an hour of reading. The independent service auditor’s report contains the opinion. Management’s assertion is the supplier’s own claim. The description of the system defines what was audited. The controls, tests and results section is where the detail sits. Other information is optional and unaudited.

The five sections of a SOC 2 report and the single thing to check in each one
Read the opinion and the dates first, then check the scope before you read anything else.
SectionWhat it containsWhat to check
1. Independent service auditor’s reportThe audit firm’s formal opinion on the description, control design and, for a Type 2, operating effectivenessWhether the opinion is unqualified or qualified, and which firm signed it
2. Management’s assertionThe supplier’s own statement that its description is accurate and controls suitably designedThat the legal entity named is the one you contract with
3. Description of the systemInfrastructure, software, people, procedures and data covered by the auditThat the specific product, environment and region you use is named
4. Controls, tests and resultsEach control, the Trust Services Criteria it maps to, how it was tested and the outcomeEvery recorded deviation, and what the supplier says about it
5. Other informationOptional management commentary and framework mappings, outside the auditor’s opinionRead it as marketing, because it was not audited
The five sections of a SOC 2 report, and what to look for in each.

Section four is where most of the value sits and where most readers stop paying attention. It lists every control the supplier claimed, the procedure the auditor used to test it, and the result. Deviations recorded here are the closest thing you will get to an honest account of where the supplier struggles.

How do you check whether a SOC 2 report is still current?

A SOC 2 Type 2 report covers a defined period, commonly three, six or twelve months, and it says nothing at all about the time after that period ended. Find the period on the first page and work out how long ago it closed. A report covering a period that ended more than about twelve months ago should be treated as historical.

Suppliers cover the gap between the end of a reporting period and the issue of the next report with a bridge letter, sometimes called a gap letter. It is a short statement from the supplier’s management confirming that no material changes to controls occurred since the report period closed. It is written by the supplier, not the auditor, so it carries less weight than the report itself, but its absence is worth asking about. If you are unclear which report type you have been sent, our comparison of SOC 2 Type 1 and Type 2 explains what each one covers.

A practical rule for annual vendor reviews: ask for the current report each year, not the one you already have on file. Suppliers do not volunteer that their latest audit produced exceptions.

What are complementary user entity controls, and why do they matter to you?

Complementary user entity controls, usually abbreviated to CUECs, are the security controls a supplier assumes you will operate at your end for their controls to be effective. They are listed in the report, and they are the section most Australian businesses skip entirely.

A typical example: a supplier’s report may state that access to the platform is controlled by the customer, and that the customer is responsible for reviewing user access, configuring multi factor authentication and removing departed staff. If you do not do those things, the supplier’s clean SOC 2 report provides you with no protection at all against the risk you were worried about.

Treat the CUEC list as a task list. Every item on it is something you have just agreed to be responsible for, whether or not you read it. This is also the part of a supplier review that connects directly to your own obligations under Australian Privacy Principle 11, which requires you to take reasonable steps to protect personal information you hold, including information held on your behalf by a supplier.

What makes a SOC 2 report weaker than it looks?

Four issues account for most of the cases where a clean looking SOC 2 report does not mean what the recipient assumed. Each one is easy to check and none requires an accounting background.

Four red flags that make a SOC 2 report weaker than it looks, covering stale reporting periods, narrow scope, carved out subservice providers and ignored exceptions
Four checks that take twenty minutes and change what the report is worth to you.

The reporting period has closed too long ago

A Type 2 report describes a window that has already ended. If that window closed a long time ago, the report tells you about a control environment that may have changed substantially since. Ask for the current report or a bridge letter covering the gap.

The system description does not cover what you bought

The description of the system defines the audit boundary. Suppliers with multiple products commonly audit one of them. Regions, subsidiaries and recently acquired platforms are frequently excluded. If the product you use is not named, the report does not cover it, no matter how clean the opinion is.

Critical subservice providers have been carved out

A supplier that relies on other providers can either include them in the audit, known as the inclusive method, or exclude them and describe the controls it expects them to perform, known as the carve out method. Carve out is common and legitimate, but it means those providers’ controls were not tested in this report. If a carved out provider is central to the service you buy, you may need their report too.

Exceptions were recorded and nobody read them

Deviations appear against individual controls in section four even when the overall opinion is unqualified. A qualified opinion signals something more serious, meaning the auditor could not conclude that all controls were suitably designed or operating effectively. Either way, the right response is to ask the supplier what has been remediated since, and to get the answer in writing.

How does a SOC 2 report fit into an Australian vendor review?

A SOC 2 report is evidence, not an outcome. In an Australian vendor review it should sit alongside your own risk assessment of what the supplier does for you, what data they hold, and what happens to your business if they fail. A report from a supplier holding your customers’ personal information deserves a much closer read than one from a supplier who processes nothing sensitive.

Where a supplier has no SOC 2 report, that is not automatically disqualifying. Many capable Australian suppliers hold ISO 27001 instead, which is a different but comparable form of independent assurance. Our comparison of SOC 2 and ISO 27001 in Australia explains what each one actually demonstrates.

If you are on the other side of this process and your own customers are asking for evidence, our guides to what enterprise buyers ask before they buy and SOC 2 for Australian SaaS companies cover what those buyers are looking for.

Common questions

Do SOC 2 reports expire?

SOC 2 reports do not carry a formal expiry date, but they cover a fixed period and lose relevance quickly once it ends. Most organisations treat a report as current for about twelve months from the end of the reporting period, then expect a new one. Between reports, a bridge letter from the supplier’s management covers the gap.

Are SOC 2 reports public?

No. SOC 2 reports are restricted use documents intended for the service organisation, its customers and their auditors. Suppliers normally release them under a non disclosure agreement on request. A publicly downloadable document is more likely a SOC 3 report, which is a general use summary containing far less detail and no test results.

Is a SOC 2 report confidential?

Yes, in practice. SOC 2 reports contain detailed information about a supplier’s controls, systems and any deviations found, which is why they are distributed under a non disclosure agreement and marked restricted use. Do not circulate a supplier’s report beyond the people who need it for your assessment, and check your NDA before sharing it with your own auditors.

Who can issue a SOC 2 report?

Only a licensed CPA firm can issue a SOC 2 report, because it is an attestation engagement performed under standards set by the American Institute of Certified Public Accountants. Compliance automation platforms can help a supplier prepare for the audit and collect evidence, but they cannot issue the report. Check which firm signed the opinion in section one.

What is the equivalent of SOC 2 in Australia?

There is no direct Australian equivalent of SOC 2. The closest widely used alternative is ISO 27001 certification, which is an international standard covering an information security management system rather than an attestation on controls. Australian buyers commonly accept either. Sector specific schemes such as IRAP for government also exist, but they answer different questions.

How often should we review a supplier’s SOC 2 report?

Annually for suppliers that matter, and whenever something changes materially, such as a supplier acquisition, a breach notification, or you starting to send them a new category of data. Diarise it rather than relying on the supplier to send you the new report, because most will not unless asked.


Get help reviewing the suppliers that matter

Siege Cyber helps Australian businesses assess the suppliers holding their data, including reading the reports properly and working out what the findings actually mean for your risk. See our cyber security advisory services, or our SOC 2 services if your own customers are the ones asking.

Get in touch and we will take a look with you.