Checking a vendor SOC 2 report before you approve it
Six checks, about twenty minutes, and no accountant needed. Start with the signature and the test results.
How to tell if a SOC 2 report is real: read two sections before anything else. Section 1 should be a signed letter on the letterhead of a named CPA firm, with a city and a date. Section 4 should sound like the vendor’s actual company, with their tools, their cloud accounts and their job titles in it.
Then confirm the firm in a public license register, match the dates to what sales told you, check the scope, and read any exceptions for what they say. The whole thing takes about twenty minutes and costs nothing.
This page is for the person with the approval in their queue: a security lead, an operations manager or a founder who has to decide whether a vendor’s report counts. You do not need an accountant. You need to know where to look.
Checking is free, so do it every time
Vendor reviews can get expensive when they turn into long questionnaires and follow up calls. This part does not. Every check below runs against the document itself or against public records, so the only cost is your time, and twenty minutes is a small price next to trusting a vendor with customer data on the strength of a PDF you never read.
Price is also the wrong test. A report is not more real because the vendor paid more for it, and it is not fake because it was affordable. The signature and the testing decide it. Whether a low cost audit is legitimate walks through that question with the same public records.
Six checks in the order that saves time
- Signed letter on firm letterhead. Section 1 names a CPA firm, a city and a date, with a signature. If it is unsigned, or signed by the vendor, it is not an examination report.
- Firm listed with a state board. Every U.S. CPA firm is licensed by a state board of accountancy, and the registers are public and searchable.1 This takes about two minutes.
- Test results with proper nouns. Section 4 should name the vendor’s ticketing tool, cloud provider and review owners. Generic procedure text with no names is the strongest sign that no testing happened.
- Dates that match the pitch. A Type 1 covers one date. A Type 2 covers a period with a start and an end. Compare both with what you were told.
- Scope that covers what you are buying. Section 3 names the system. A different product or a parent company means the report is real but not about your purchase.
- Exceptions that read like findings. Zero exceptions across forty controls can happen. It is also exactly what a report with no testing behind it looks like.
Five of the six are reading. Only the license lookup needs another browser tab. The sections below explain each one in more depth.
Who wrote which section
Every SOC 2 report has the same five sections in the same order. The key skill is knowing which ones the CPA firm wrote and which ones the vendor wrote, because only two of the five come from the independent side.
| Section | Author | What you learn from it |
|---|---|---|
| Section 1 | CPA firm | The opinion: which firm, what it examined, the date or period, and whether it is clean |
| Section 2 | Vendor | Management’s assertion that its own description is accurate |
| Section 3 | Vendor | The system description: scope, exclusions, subservice providers, controls as designed |
| Section 4 | CPA firm | Each control, the test run on it, and the result. The part worth your time |
| Section 5 | Vendor | Other information, including responses to deviations. Outside the opinion |
Section 3 is where a vendor sounds best, and it is quoting itself. Section 4 is where an independent party wrote down what it saw.
The opinion letter and the license lookup
Section 1 is a letter, not a certificate. It says which firm did the examination, what it looked at, which criteria it used and what it concluded. That conclusion is an attestation opinion, and only a licensed CPA firm can give one.2
Find the firm name, city, date and signature, then search the state board of accountancy for that state. If the firm is not in the register, what you hold is not a SOC 2 report, however polished it looks. Who can perform a SOC 2 audit covers the licensing rule in full.
Read the opinion wording yourself instead of trusting the summary in the vendor’s email. An unqualified opinion is the clean one. A qualified opinion means everything held except one named item, which is often survivable. An adverse opinion or a disclaimer is a different conversation altogether.
The opinion covers the whole. Section 4 records each instance that did not work. A report can have an unqualified opinion and several exceptions at once, and that is normal.
Where a fake gives itself away
Sections 1 through 3 are easy to imitate, since boilerplate exists for all of them. Section 4 is harder. It has to describe work that either happened or did not.
Real test results are specific and a bit dull. They give populations and sample sizes, say what was inspected, and name systems. Those names change from vendor to vendor because the systems do.
- Real testing sounds like
- Inspected the access review for the quarter ending March 31 and agreed the reviewer, date and removed accounts. Selected 25 of 213 changes deployed in the period and inspected the approval on each pull request.
- A template sounds like
- The organization maintains appropriate access controls. Changes are approved before deployment. No names, no counts, no dates, nothing that would change for a different company.
One more clue. A Type 2 tests over a period, so its language talks about samples across that period. If the wording only ever describes a state and never a sample, you may be reading a Type 1 that someone described to you as a Type 2.
Dates and scope against the sales pitch
This check catches real reports used in misleading ways. The document is genuine. The story told around it is not.
If a salesperson said Type 2 and Section 1 says “as of” a single date, you were told something wrong. Type 1 versus Type 2 explains the difference, and the observation period explains why a short first window is legitimate.
Next, check the age. A period that closed long ago describes a company that may have changed. Ask for a bridge letter for the months since. How long a SOC 2 report is valid covers what that letter can and cannot do. Last, confirm the product, the environment and the criteria in scope. Security is always included and the others are optional.3
Read exceptions for what they say
An exception is one instance where a control did not work the way the description says. It belongs to a specific test, not to the company as a whole. Careful engineering teams get them too.
The count alone tells you little. Ask which control slipped, whether it touches your data, how many instances out of how many tested, and what management wrote in Section 5. Two exceptions with a clear fix and a date tell you more than a spotless report with no sample sizes. What happens when an audit finds exceptions covers the opinion types and how findings get cleared.
When the vendor will not share it
A SOC 2 report is a restricted use document.4 Section 1 usually ends by naming who the report is meant for, and the engagement letter limits sharing further. A vendor who will not email you the PDF may simply be following those terms.
- Ask under a mutual NDA. This is the normal route and it often resolves in a day.
- Accept a secure viewer. A watermarked copy you can read beats a PDF you never receive.
- If it is still no, ask for the facts. Firm name, opinion type, report type, period and criteria in scope. A vendor with a real report can answer all five in one email.
- Watch for a refusal to name the firm. Sharing can be restricted. The signing firm’s identity is not secret, and hesitation there is the real signal.
Do not accept a website badge, a dashboard screenshot or a logo on a compliance page. None of those is the report. The report is the document with the signed letter at the front.
If you are the vendor being checked
Everything above is what your buyer will do to your report, so your report has to pass it. We prepare the evidence and scope Security only, and the independent partner auditor examines it and signs. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. What you send your buyer is the full report, from the opinion letter to the tests of controls, not a badge.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Want to know how your own controls would hold up under these six checks? The free readiness assessment takes about 15 minutes. Start it free, or see what each plan costs.
Questions
What is the fastest way to check a SOC 2 report is genuine?
Which part of the report matters most?
Is it possible to fake a SOC 2 report?
The vendor will not share its report. Is that a red flag?
Should exceptions in a report worry me?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.