How to Read a SOC 2 Report When You Are the Customer, Not the Auditor
A SOC 2 report is an independent CPA firm's examination of a service organization's controls relevant to the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

Buyers should read the auditor's opinion and scope boundary first, not the cover page branding, because those two sections determine what the report actually covers and whether the auditor stands behind it.
The Opinion That Controls Everything
The auditor's opinion appears early in the document and states whether the examination is unqualified, qualified, adverse, or a disclaimer. An unqualified opinion means the auditor found the controls met the criteria without reservation. A qualified opinion contains exceptions the auditor considers material but not pervasive. An adverse opinion states the controls did not meet the criteria, and a disclaimer means the auditor could not form an opinion. This four-word classification—unqualified, qualified, adverse, disclaimer—determines whether the report provides assurance or signals problems. The opinion governs everything that follows. If you stop reading after the cover letter, you have missed the only sentence that tells you whether the auditor is willing to be associated with the vendor's claims.
Where the Boundary Is Drawn
The scope section identifies exactly which systems, services, and locations are covered, and which are excluded. This matters because a vendor may operate fifteen data centers but only include three in the examination. The scope statement is your map: it tells you whether the instance you are buying matches the instance that was tested. Under a carve-out approach, components of a subservice organization's system are excluded from the description of the service organization's system and from the scope of the examination. Controls at the subservice organization are excluded from testing, and you are responsible for evaluating those third parties separately. The report will describe the subservice organization's controls, the nature of the services provided, and the applicable trust services criteria intended to be met by controls at the subservice organization—but it will not test them. Many buyers misread a carve-out as coverage; it is actually exclusion with disclosure.
Why Type 2 Is the Only Report That Tests Over Time
A Type II report tests whether controls operated effectively over a period, while a Type I report describes whether controls were suitably designed at a single point in time. The AICPA description criteria distinguish Type 1 examinations, which are as of a date, from Type 2 examinations, which are for periods ending as of a date. SOC audits concern operating effectiveness of internal controls over a period of time. A Type I report cannot tell you whether controls worked in March, April, and May; it can only tell you that on January 31 the design looked reasonable. Buyers often treat a Type I as proof of ongoing reliability. It is not. Request the period covered, check that it is a range rather than a date, and confirm the end date is recent enough for your risk tolerance.
Reading the Testing Pages for Exceptions
The detailed testing section includes the trust services criteria, the controls, the auditor's tests, and the results. This is where you find whether the vendor actually did what the policy manual claimed. Exceptions are identified by reading the description, the number of instances, and management's response. An exception does not automatically invalidate the opinion, but it tells you where the control failed and how often. Read management's response to see whether they claim the exception was isolated, whether they have implemented new controls, or whether they consider the deviation immaterial. The auditor's test results and management's response sit side by side; compare them. One describes what happened, the other describes what the vendor says about it.
What the Report Assumes You Will Do
Complementary user-entity controls are things the report assumes the customer will do: managing your own user access, safeguarding credentials, and reviewing transfer confirmations. The SOC 2 report covers the vendor's controls, not yours. If you fail to perform your complementary controls, the vendor's clean opinion provides no protection. Review this section as a checklist of obligations that transfer to your organization. The report is not a warranty; it is a shared responsibility framework with the boundaries clearly marked.
Three Questions to Send Back
When you finish reading, send the vendor three questions that demand specific answers. First: "Which specific systems and locations from your production environment are excluded from the scope statement, and why?" This forces clarification of what was carved out and what you must evaluate yourself. Second: "What exceptions did the auditor note in the testing section, and what is the current status of each?" This moves beyond the opinion to the operational reality. Third: "What complementary user-entity controls does your report assume my organization performs, and what evidence do you require that we have implemented them?" This establishes whether your controls are part of their assurance story. These questions are factual. They have answers in the report or they do not.
What the Report Actually Delivers
The SOC 2 report allows you to rely on the vendor's controls only within the stated scope, period, and assumptions. Outside those boundaries, the auditor offers no assurance. The carve-out shifts evaluation of subservice organizations to you. The complementary user controls shift operational responsibility to you. The period boundary means controls tested last year may not describe current operations. The opinion tells you whether the auditor found the covered controls effective; nothing more. Read it as a limited warranty with explicit exclusions, not as a certification of comprehensive security. The work the report does not cover is yours to perform.
Sources
- AICPA, “2015 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report” — us.aicpa.org, 2024-12-29
- DAG, “How to Read a Custodian’s SOC 2 Type II Report” — dag.com, 2026-06-02
- University of Illinois, “System and Organization Control” — siaab.audits.uillinois.edu, 2025-07-22
- cpaexamsmastery.com, “Required Sections, Structure, and Core Content of SOC Reports” — cpaexamsmastery.com, 2026-04-07
- DashSDK, “[PDF] Illustrative Type 2 SOC 2 Report with the Criteria in the Cloud” — dashsdk.com, 2026-08-14
- Washington Office of Financial Management, “Understanding How to Leverage SOC Audits” — ofm.wa.gov, 2025-10-31
More from Payments, Privacy & Trust
Section indexCross-Border Payments: FX, Chargebacks, and Risk Controls
December. A mid-size marketplace in Berlin runs a promo into LATAM. Sales jump. So do problems. FX costs come in higher than forecast. The team sees a 60 bps drop in margin from spread…
Kasino betalingsmetoder: En komplet guide til iGaming-industrien
Når du leder efter et online kasino, fokuserer du typisk på tre vigtige aspekter: velkomstbonusser, spiludvalg og betalingsmetoder i online kasinoer . Et godt udbetalingssystem,…
Piattaforme di scommesse che accettano ecoPayz
Negli ultimi anni, i metodi di pagamento digitali sono diventati sempre più importanti per chi ama scommettere online. Tra questi, ecoPayz è emerso come una delle soluzioni…

