What happens if you fail a SOC 2 audit
Nobody fails a SOC 2 the way you fail an exam. You get an opinion, and sometimes exceptions, and both are fixable at a modest cost.
So, what happens if you fail a SOC 2 audit? Strictly, nothing, because there is no pass mark to miss. The CPA firm examines what you claimed about your controls and writes an opinion.1 What people call failing is nearly always a clean opinion that comes with a few exceptions attached. Those are common. They are visible to your buyers. And they are fixed with a calendar, not a check.
This page walks through the report the way a buyer reads it. Then it covers the part the person paying cares about: what an exception costs to clean up, and how much of that work you can do on your own. Short answer first. Very little of it needs outside help.
Where the bad news sits in the report
A SOC 2 report has a fixed layout.3 Knowing it takes most of the fear out of the word exception, because you can see exactly which pages carry a finding and which pages you write yourself. There is one version. Nobody gets a cleaned up copy.
| Part | Author | Contents |
|---|---|---|
| Section 1 | CPA firm | The opinion. About a page of standard wording |
| Section 2 | Your company | The management assertion about your system |
| Section 3 | Your company | The system description, its boundaries, and the controls you designed |
| Section 4 | CPA firm | Each control, each test, each result. Exceptions are printed here |
| Section 5 | Your company | Other information, including your response to each exception |
Reviewers skim Section 1 and dig into Section 4. The opinion paragraph is boilerplate. The test results are the only place they learn something new about you.
The four opinions a firm can give
There is no score. The firm checks whether your own statements about the system hold up under testing, and then it picks one of four outcomes. The first two are closer together than they sound.
- Unqualified
- The target. Your description is fair, the controls were designed well, and for a Type 2 they ran effectively across the period. Exceptions can still appear in Section 4 under an unqualified opinion.
- Qualified
- Clean except for one named item. The opinion carries an except for clause that points to the criterion or control that fell short. Buyers still accept the report and read it.
- Adverse
- The description or the controls are materially wrong, across the board rather than in one spot. It is rare, and it means a reader cannot rely on what you wrote.
- Disclaimer
- No opinion at all, because the evidence to test was missing. This is the outcome worth real effort to avoid, and it comes from disorganized evidence far more than from weak security.
A qualification is a disclosed limit. Reviewers are trained to weigh one. Surprises hurt deals. Disclosures rarely do.
How an exception gets recorded
An exception is small by design. It belongs to one test of one control, and the auditor writes down the count and a short note next to it. It says nothing about your company as a whole, and it does not decide the opinion on its own.
On a Type 2
The auditor takes every occurrence of a control during the period, picks a sample, and checks each one against your written procedure. Say your policy promised four access reviews and the records show two. That gap goes into Section 4 as an exception. Whether it touches the opinion depends on judgment: was it isolated, did another control cover the same risk, and does the criterion still hold overall. One late review with a clear reason usually leaves the opinion alone. A control that never ran once does not.
On a Type 1
A Type 1 looks at design on a single date. With no period there is nothing to sample, so there are no operating exceptions. What can come up is a design gap, a control that would miss the criterion even if it worked perfectly. Those are normally fixed before the report is issued. The SOC 2 timeline shows how much room each report type leaves for fixing things first.
What cleaning one up costs
Here is the cost view. An exception does not come with a penalty fee. The cost is time, plus whatever you pay someone else to manage the fix. Teams that hand remediation to a consultant pay consultant rates for work that is mostly scheduling and filing. For reference, this is one published estimate of that route:
- Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.
You can do nearly all of it yourself. Rewrite the procedure, name an owner, set a calendar reminder, and file the evidence each time the control runs. None of that needs a specialist.
The one cost you cannot skip is a new period, because that is the only way a clean result reaches a report. On our software, which is $199 a month, cancel any time, a 3-month observation window comes to $597 of software on the monthly plan. We add nothing for the exception itself and nothing for the remediation work. The audit that closes the new period is a separate item. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and the quote is agreed before anything starts.
Your side of the page: Section 5
The management response is yours to write, and the auditor does not give an opinion on it.1 It is the only spot where your words sit right next to the finding. Use it well. Do not argue with the test result, and do not claim a fix the auditor never saw. Either one turns a small item into a question about how the company is run.
- Describe what happened. Match the auditor's flat tone. Skip adjectives.
- Give the real cause. A task with no named owner is a better explanation than human error, because it points at something you can change.
- State the fix and its date. If it landed after the period ended, say so.
- Explain how you will know it stays fixed. An alert, a recurring ticket, an owner. Reviewers weigh this line most.
No edits after issuance
An issued report is a finished work product of a CPA firm, covering dates that are already over. It is not reopened to delete a true finding. Nobody can sell you that.
The path back is always the same. Fix the control. Run it correctly for a new period. Get that period examined. The next report shows a clean test where the old one showed a deviation. Buyers tend to like that pair of reports more than a single spotless one, since it shows a team that notices its own misses.
Stop exceptions before the period starts
Most exceptions are schedule problems, not security problems. The auditor tests your policy against the criteria, and then tests you against your policy.2 If you wrote quarterly and did two reviews, that is an exception you created with one word. This is the lowest cost fix on the page, because it costs nothing but an honest read of your own policies.
- Pick a cadence you can keep in a bad quarter. Doing more than your policy says is never a finding.
- Check that cadence against the criterion. Loosening too far swaps an operating exception for a design gap, which is worse. Access review under CC6 is the one to watch.
- Give every recurring task a named person. A shared calendar owns nothing.
- File evidence the day it is produced. Keep each control's tickets, exports and approvals together, so the auditor's request is a lookup.
Five common control failures lists the patterns worth checking first, and Type 1 versus Type 2 helps you confirm which report your buyer wants. Price does not change the outcome either way: a low-priced examination does not hide exceptions, and an expensive one does not remove them. Whether a low cost audit is legitimate explains how to check a firm with its state board.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Your next step
The best time to find a would be exception is before any auditor is looking. Take the free readiness assessment. It takes about 15 minutes and gives you a readiness assessment, score, gap list and one AI sample policy, so the cadence problems show up while they are still free to fix. When you want to see what the software costs and how audits are priced, the full detail is on the pricing page.
Questions
Is it possible to fail a SOC 2?
What counts as an exception?
Do buyers get to see the exceptions?
Can I get an exception taken out of an issued report?
Will a qualified opinion lose me the customer?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.