SOC 2 management assertion: two letters you can copy
Section 2 is a one page letter, and a person at your company signs it. Here are both versions, free to copy.
The SOC 2 management assertion is your company’s own statement, printed as Section 2 of the report.1 It says the system description is accurate and the controls were designed well. An officer signs it, not the auditor, and it fits on one page.
Both versions are below. They are free to copy and need only your names, dates and scope.
What the letter says in plain words
Three claims, in order. We wrote the description of our system. We are responsible for the controls in it and for picking the criteria. Those controls were suitably designed, and in a Type 2, they also worked across the whole period. The CPA firm then gives its own view on whether your statement holds up. That split matters: the firm reports on your claim, it does not make the claim for you.
Because it is your claim, overreaching costs you. Every extra category or system named in the letter is more evidence to produce and more for the firm to test.
Copy this: the Type 1 letter
A Type 1 speaks about a single day. It says nothing about how controls behaved in the weeks before or after. Swap in your company, product and dates.
We have prepared the accompanying description of the Northwind scheduling platform as of August 31, 2026 (the description).
Northwind management is responsible for designing, implementing and operating controls within the system, for providing a complete and accurate description of it, and for selecting the trust services criteria against which it is presented.
Management asserts that the controls in the description were suitably designed and implemented as of August 31, 2026 to meet the applicable trust services criteria for the Security category.
Ravi Menon, Chief Technology Officer, Northwind Labs, Inc. Signed September 21, 2026.
Notice the two dates. August 31 is the day the letter describes. September 21 is when it was signed, which is also the day the report came out.
Copy this: the Type 2 letter
The wording barely moves, but the promise gets much bigger. “Throughout the period” covers every day in the window, and the firm tests samples from across it.
We have prepared the accompanying description of the Northwind scheduling platform for the period March 1, 2026 to August 31, 2026 (the description).
Northwind management is responsible for designing, implementing and operating effective controls within the system, for the completeness and accuracy of the description, and for selecting the applicable trust services criteria.
Management asserts that the controls in the description were suitably designed, implemented and operated effectively throughout the period March 1, 2026 to August 31, 2026 to meet the applicable trust services criteria for the Security category.
Ravi Menon, Chief Technology Officer, Northwind Labs, Inc. Signed September 21, 2026.
Name only the categories you scoped. For most first reports that is Security, the common criteria.4
Sentences to add when they apply
The two letters above assume a clean result and no outside vendors worth mentioning. Real companies run on cloud providers and sometimes miss a control. Each case gets one extra sentence, added to whichever version you use. Leave both out if they do not apply, since an unneeded qualifier only raises questions.
You rely on vendors you cannot test
Pick one method and state it. With a carve out, you write: “Northwind uses Google Cloud as a subservice organization. The description covers Northwind’s controls, excludes those of the subservice organization, and lists the complementary subservice organization controls our design assumes.” The inclusive method brings the vendor’s controls into scope, which means the vendor must sign its own assertion and be tested next to you. A small company rarely gets a hyperscaler to agree, so carve out is the normal choice. The system description template carries the same choice into Section 3.
A control did not operate as described
Keep the letter and add a qualifier that points to where the detail lives. Section 4 holds the tests and results.3 The Type 2 clause reads: “...to meet the applicable trust services criteria for the Security category, except for the matters described in Section 4 of this report.” Say it once. Explanations belong in Sections 4 and 5, not here. Whether the gap changes the opinion is the firm’s call, covered in what an exception does to a report.
Two letters people mix up with this one
Searches treat these as the same document. They are not. Each has a different reader and a different date on it.
- The management representation letter
- Addressed to the CPA firm by name. It confirms you handed over everything relevant, including incidents and known failures, as the attestation standards require.2 It stays in the firm’s file and is dated the day the report is issued.
- The bridge letter
- Something you write yourself after the report, to cover the months since the period ended. Nobody examined it, and it adds no assurance. The bridge letter guide has the wording.
Who signs, and what happens if they leave
The signer needs two things: authority to speak for the company, and real knowledge of how the system runs. A CEO, CTO or CISO fits. A consultant can help with the words but cannot sign. The auditor never signs, because a firm that wrote your assertion would be judging its own work. Who can perform a SOC 2 audit covers that line.
The letter is dated on the issue date, which can land weeks after the period closes. If the officer leaves in between, their successor signs for the company. Prepare for that: have the departing officer write a dated handover memo listing systems, open issues and where the evidence lives. Tell the firm early who will sign. Never backdate, and never use a signature from someone already gone.
What this letter costs you
The letter itself costs nothing. It is a page of standard wording plus your details, and you can write it from this template. The spending is in everything it points to: the description, the evidence and the examination.
That is where cybersoftware keeps the bill small. The software drafts Section 2 with your signer, title and dates, and tracks the evidence behind it, at $199 a month, cancel any time. The examination comes with access to our preferred pricing program, with an independent partner auditor. Start with the free readiness assessment or compare options on pricing.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
What is a SOC 2 management assertion?
How is it different from the management representation letter?
Who should sign the assertion?
What changes between the Type 1 and Type 2 wording?
Our signer left before the report was issued. What now?
Sources
- SOC 2 Report
- Statements on Standards for Attestation Engagements
- SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.