SOC 2 Reports: What They Tell an Automation Buyer
A SOC 2 report says what one CPA firm found when it examined a vendor's controls, in a scope the vendor chose, over a window that has already closed. Read the opinion letter, the period, the categories in scope and the exceptions, or the badge on the website has told you nothing at all.
A SOC 2 report tells you what an independent CPA firm found when it examined one vendor's controls, against a defined set of criteria, over a defined scope, during a defined window. That is all it tells you. It is not a certification, it is not a guarantee, and the badge on a vendor's website is not the report.
If you are buying automation software that will hold your customer records, your invoices, or your credentials to other systems, a SOC 2 report is one of the few documents that gives you something better than a sales promise. But it is only useful if you read it, and most buyers never ask for the PDF.
What a SOC 2 report actually is
SOC stands for System and Organization Controls. It is a family of reporting services created by the American Institute of Certified Public Accountants (AICPA) for service organizations — companies that run systems on behalf of other companies. That describes almost every automation platform you would consider.
A SOC 2 examination is performed by a licensed CPA firm under AICPA attestation standards. The vendor writes a description of its system and asserts that its controls meet the applicable criteria. The CPA firm examines that description and those controls and issues an opinion. The output is a document containing the auditor's opinion, the vendor's system description, the criteria in scope, the specific controls the vendor claims, the tests the auditor performed, and — this is the part buyers skip — any exceptions the auditor found.
The AICPA's own guide for these engagements is titled "SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy." Those five categories named at the end are the trust services categories, and they are the whole vocabulary of SOC 2.
Type I and Type II are not tiers
People talk about Type II as though it were a better grade than Type I. It is closer to say they answer different questions.
| Type I | Type II | |
|---|---|---|
| Question answered | Were the controls suitably designed? | Were the controls suitably designed and did they operate effectively? |
| Time covered | A single date | A stated period, commonly three to twelve months |
| Testing | Design only | Design plus tests of operating effectiveness over the period |
| What it is good for | A new product or a first-year program | Evidence the controls held up in practice |
A Type I is a photograph. A Type II is a video. A vendor that has only ever produced Type I reports, three years running, is telling you something — usually that it has not yet been willing to be measured over time. The AICPA publishes an illustrative Type 2 report if you want to see the shape of one before a vendor sends you theirs.
Check the period dates on the cover. A Type II covering January through March of two years ago is a stale document, and vendors do send those.
The five trust services criteria
The AICPA's Trust Services Criteria define five categories an examination can address:
- Security — protection of systems and information against unauthorized access and disclosure.
- Availability — whether the system is available for operation and use as committed.
- Processing integrity — whether processing is complete, valid, accurate, timely and authorized.
- Confidentiality — protection of information designated as confidential.
- Privacy — how personal information is collected, used, retained, disclosed and disposed of.
Which of these a report covers is a scoping decision the vendor made, not a fixed list. Many SOC 2 reports address security alone. That is a legitimate report, but if you are buying an automation platform because you need jobs to run on schedule and post the right numbers, a security-only report says nothing about availability or processing integrity — the two categories that map most directly to what you are worried about.
Ask which categories are in scope before you ask anything else. The answer is printed on the face of the report.
What the report does not cover
This is the part worth internalizing.
It does not cover the whole company. The system description defines a boundary: named products, named environments, named locations. A vendor with six products may have a SOC 2 covering two of them. If the product you are buying is not inside the described system, the report is about something else.
It does not cover the future. A Type II report covers a closed period that ended before the report was issued. Nothing in it speaks to what happened last month.
It does not mean zero findings. Reports contain exceptions, and an opinion can be qualified. Go to the auditor's opinion letter first and read whether it is unqualified. Then go to the test results section and read the exceptions and management's responses. A vendor with three minor exceptions and honest remediation notes is often a better bet than one with a spotless report and a narrow scope.
It does not cover your configuration. Every SOC 2 report includes complementary user entity controls — things the report assumes you will do, such as managing your own user accounts, enforcing your own authentication, and reviewing your own access lists. Those are your obligations, spelled out in the vendor's report, and no auditor checked whether you met them.
It is not a legal compliance opinion. SOC 2 is an attestation against the AICPA's criteria. It is not a finding under any privacy statute, and it does not make anyone compliant with anything.
Why the badge is not the report
A logo on a marketing page is a graphic file. It carries no opinion, no scope, no period, no exceptions, and no auditor's name. The information that would let you evaluate the vendor is precisely the information a badge omits.
SOC 2 reports are ordinarily distributed under a non-disclosure agreement rather than posted publicly, which is why you have to ask. The AICPA's general-use companion product is SOC 3, described in its own title as a report for general use — that is the one a vendor can legitimately publish. If a vendor offers you a SOC 3 summary and calls it a SOC 2, you have not received the document you asked for.
Sign the NDA, get the PDF, and read four things: the opinion letter, the report period, the categories in scope, and the exceptions table.
What to ask a vendor
- Is it a Type I or a Type II, and what period does it cover?
- Which trust services categories are in scope?
- Which products and environments are inside the described system boundary?
- Is the opinion unqualified? If not, what was qualified and why?
- What exceptions did the auditor identify, and what did management say about them?
- What are the complementary user entity controls I am expected to operate?
- Which CPA firm performed the examination?
- When does the next report period close, and will you send it to me?
Put the last one in your contract. A SOC 2 report is an annual artifact; a vendor that will not commit to giving you the next one is offering a one-time reassurance.
Where this sits in a real buying decision
The U.S. Department of Labor, in its guidance for retirement plan fiduciaries choosing service providers, tells hiring organizations to "look for service providers that follow a recognized standard for information security and use an outside (third-party) auditor to review and validate cybersecurity," and to look for contract provisions that give you the right to review the audit results. That is a useful framing even outside the retirement plan context: the report is a starting point for a contract conversation, not the end of the diligence.
For a ten-person company automating invoice routing, a current Type II covering security and availability, with a clean opinion and a scope that includes the product you are buying, is a reasonable bar. Below that, you are relying on the vendor's own description of itself, which is where most buyers already are.
One more caution, because it comes up constantly: a report is about an organization's controls, not about a piece of software. There is no such thing as a "SOC 2 compliant tool." There is a service organization that underwent an examination and received an opinion, and there is you, deciding whether the scope of that examination covers the risk you actually carry.
The Bot Desk publishes information, not legal advice. We are not a law firm and nothing here creates an attorney-client relationship. Contracts, audit rights, and regulatory obligations turn on facts specific to your business, and you should consult a qualified attorney licensed in your state before relying on any of this for a decision.
Read next
Sources
- AICPA & CIMA - SOC 2: Trust Services Criteria
- AICPA & CIMA - 2017 Trust Services Criteria (revised points of focus, 2022)
- AICPA & CIMA - 2018 SOC 2 Description Criteria
- AICPA & CIMA - Illustrative Service Auditor's SOC 2 Type 2 Report
- U.S. Department of Labor, EBSA - Tips for Hiring a Service Provider With Strong Cybersecurity Practices