What happens if you fail a SOC 2 audit

Nobody fails a SOC 2 the way you fail an exam. You get an opinion, and sometimes exceptions, and both are fixable at a modest cost.

So, what happens if you fail a SOC 2 audit? Strictly, nothing, because there is no pass mark to miss. The CPA firm examines what you claimed about your controls and writes an opinion.1 What people call failing is nearly always a clean opinion that comes with a few exceptions attached. Those are common. They are visible to your buyers. And they are fixed with a calendar, not a check.

This page walks through the report the way a buyer reads it. Then it covers the part the person paying cares about: what an exception costs to clean up, and how much of that work you can do on your own. Short answer first. Very little of it needs outside help.

Where the bad news sits in the report

A SOC 2 report has a fixed layout.3 Knowing it takes most of the fear out of the word exception, because you can see exactly which pages carry a finding and which pages you write yourself. There is one version. Nobody gets a cleaned up copy.

PartAuthorContents
Section 1CPA firmThe opinion. About a page of standard wording
Section 2Your companyThe management assertion about your system
Section 3Your companyThe system description, its boundaries, and the controls you designed
Section 4CPA firmEach control, each test, each result. Exceptions are printed here
Section 5Your companyOther information, including your response to each exception

Reviewers skim Section 1 and dig into Section 4. The opinion paragraph is boilerplate. The test results are the only place they learn something new about you.

The four opinions a firm can give

There is no score. The firm checks whether your own statements about the system hold up under testing, and then it picks one of four outcomes. The first two are closer together than they sound.

Unqualified
The target. Your description is fair, the controls were designed well, and for a Type 2 they ran effectively across the period. Exceptions can still appear in Section 4 under an unqualified opinion.
Qualified
Clean except for one named item. The opinion carries an except for clause that points to the criterion or control that fell short. Buyers still accept the report and read it.
Adverse
The description or the controls are materially wrong, across the board rather than in one spot. It is rare, and it means a reader cannot rely on what you wrote.
Disclaimer
No opinion at all, because the evidence to test was missing. This is the outcome worth real effort to avoid, and it comes from disorganized evidence far more than from weak security.

A qualification is a disclosed limit. Reviewers are trained to weigh one. Surprises hurt deals. Disclosures rarely do.

How an exception gets recorded

An exception is small by design. It belongs to one test of one control, and the auditor writes down the count and a short note next to it. It says nothing about your company as a whole, and it does not decide the opinion on its own.

On a Type 2

The auditor takes every occurrence of a control during the period, picks a sample, and checks each one against your written procedure. Say your policy promised four access reviews and the records show two. That gap goes into Section 4 as an exception. Whether it touches the opinion depends on judgment: was it isolated, did another control cover the same risk, and does the criterion still hold overall. One late review with a clear reason usually leaves the opinion alone. A control that never ran once does not.

On a Type 1

A Type 1 looks at design on a single date. With no period there is nothing to sample, so there are no operating exceptions. What can come up is a design gap, a control that would miss the criterion even if it worked perfectly. Those are normally fixed before the report is issued. The SOC 2 timeline shows how much room each report type leaves for fixing things first.

What cleaning one up costs

Here is the cost view. An exception does not come with a penalty fee. The cost is time, plus whatever you pay someone else to manage the fix. Teams that hand remediation to a consultant pay consultant rates for work that is mostly scheduling and filing. For reference, this is one published estimate of that route:

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

You can do nearly all of it yourself. Rewrite the procedure, name an owner, set a calendar reminder, and file the evidence each time the control runs. None of that needs a specialist.

The one cost you cannot skip is a new period, because that is the only way a clean result reaches a report. On our software, which is $199 a month, cancel any time, a 3-month observation window comes to $597 of software on the monthly plan. We add nothing for the exception itself and nothing for the remediation work. The audit that closes the new period is a separate item. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and the quote is agreed before anything starts.

An exception costs you a quarter of calendar. It should not cost you a consultant.

Your side of the page: Section 5

The management response is yours to write, and the auditor does not give an opinion on it.1 It is the only spot where your words sit right next to the finding. Use it well. Do not argue with the test result, and do not claim a fix the auditor never saw. Either one turns a small item into a question about how the company is run.

  1. Describe what happened. Match the auditor's flat tone. Skip adjectives.
  2. Give the real cause. A task with no named owner is a better explanation than human error, because it points at something you can change.
  3. State the fix and its date. If it landed after the period ended, say so.
  4. Explain how you will know it stays fixed. An alert, a recurring ticket, an owner. Reviewers weigh this line most.

No edits after issuance

An issued report is a finished work product of a CPA firm, covering dates that are already over. It is not reopened to delete a true finding. Nobody can sell you that.

The path back is always the same. Fix the control. Run it correctly for a new period. Get that period examined. The next report shows a clean test where the old one showed a deviation. Buyers tend to like that pair of reports more than a single spotless one, since it shows a team that notices its own misses.

Stop exceptions before the period starts

Most exceptions are schedule problems, not security problems. The auditor tests your policy against the criteria, and then tests you against your policy.2 If you wrote quarterly and did two reviews, that is an exception you created with one word. This is the lowest cost fix on the page, because it costs nothing but an honest read of your own policies.

  1. Pick a cadence you can keep in a bad quarter. Doing more than your policy says is never a finding.
  2. Check that cadence against the criterion. Loosening too far swaps an operating exception for a design gap, which is worse. Access review under CC6 is the one to watch.
  3. Give every recurring task a named person. A shared calendar owns nothing.
  4. File evidence the day it is produced. Keep each control's tickets, exports and approvals together, so the auditor's request is a lookup.

Five common control failures lists the patterns worth checking first, and Type 1 versus Type 2 helps you confirm which report your buyer wants. Price does not change the outcome either way: a low-priced examination does not hide exceptions, and an expensive one does not remove them. Whether a low cost audit is legitimate explains how to check a firm with its state board.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Your next step

The best time to find a would be exception is before any auditor is looking. Take the free readiness assessment. It takes about 15 minutes and gives you a readiness assessment, score, gap list and one AI sample policy, so the cadence problems show up while they are still free to fix. When you want to see what the software costs and how audits are priced, the full detail is on the pricing page.

Questions

Is it possible to fail a SOC 2?
Not in the sense of a grade. The CPA firm gives an opinion, and it takes one of four forms: unqualified, qualified, adverse, or a disclaimer. A clean unqualified opinion can still sit on top of test results that list exceptions, because the two answer different questions.
What counts as an exception?
An instance where a control did not run the way your description says it runs. It is written against one test of one control in Section 4, with how many instances failed and a short note from the auditor. Reports from large, mature companies carry them too.
Do buyers get to see the exceptions?
Yes. There is only one version of the report, and Section 4 prints every test and its result. Security reviewers read that part closely, and a plain, specific management response next to an exception tends to carry more weight with them than the exception does.
Can I get an exception taken out of an issued report?
No. The report describes a period that has already ended, and it is not reissued to drop a finding. The route back is to fix the control, run it properly for a new period, and have that period examined. The next report then shows the clean result.
Will a qualified opinion lose me the customer?
Not by itself. A qualified opinion calls out one named limitation and leaves the rest of the report standing. Reviewers look at what was qualified, whether it touches their data, and how quickly and concretely you responded.

Sources

  1. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  3. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.