A free SOC 2 system description template, part by part

You write Section 3, not the auditor. Here is every part, a worked boundary, and the wording that comes back.

This SOC 2 system description template is free, and it matters more than its length suggests. Section 3 of the report is written by you, not the auditor.1 Your controls are then tested against your exact words, so each sentence you add is something someone will check.

Narrow wording costs less

Each system, tool or team you name in Section 3 becomes part of what the auditor examines. Name an internal admin tool by accident and you owe evidence for it. Describe a second product loosely and it may get pulled in. That is extra hours for you and for the firm, on work no buyer asked for. Write only what the examination should cover.

The document is yours because independence demands it. A firm that drafted it would be examining its own writing.2 The auditor can tell you what must be covered and send back what it cannot test. It cannot write the words.

The eleven parts to fill in

These appear in roughly this order in most reports. The last column shows the kind of wording that gets returned, which is useful to read before you start writing each part.

PartWrite hereGets sent back
Services and commitmentsWhat the product does, for whom, and what you promise themMarketing lines about a secure platform
BoundaryThe products and environments in scope, and what is excluded“Production and supporting systems” with nothing named
InfrastructureCloud accounts, regions, networks, databases and storage by name“A major cloud provider”
SoftwareThe app, repositories, build and deploy, identity, logging, ticketing“Industry standard tools”
PeopleRoles that run the system, reporting lines, who has production accessA least privilege slogan instead of a structure
ProceduresHow change, access, incidents and vendor review really work“Policies are documented”, which is not a procedure
DataCustomer data held, how it arrives, where it rests, how long you keep itRetention “as required by law” with no period
Subservice organizationsEach vendor you depend on, named, with the method usedA vendor list with no method
Customer controlsWhat customers must do for your controls to work“Customers own their security”
Controls and criteriaYour controls as they run today, mapped to criteria in scopeControls written in the future tense
Changes in the periodBig changes during a Type 2 window, with dates“No significant changes” in a year with a migration

A sample boundary paragraph

The boundary is where loose writing hurts most, and the damage is quiet. Nothing is rejected up front. Instead the auditor starts fieldwork by working out what is in scope, and every test after that carries the doubt. Here is one for an eight person company on Azure.

Example: Harbor Metrics, Inc.

The system is the Harbor Metrics analytics application and its supporting infrastructure, hosted in one Microsoft Azure subscription in the East US region. In scope are the production App Service plan, the Azure SQL database holding customer records, the storage account for uploaded files, and the GitLab repositories and CI pipelines that build and release the application. Staff sign in through Microsoft Entra ID, which also controls access to the Azure subscription. The company website and employee laptops are out of scope. Harbor Metrics runs no data center of its own, so physical security rests with Microsoft and is carved out.

Every sentence names something: the subscription, the region, the components, the sign in system, and what is excluded. A reader could draw the line from this paragraph alone.

The vendors underneath you

Your system rests on vendors whose controls you cannot test yourself. The cloud runs the data center. The identity provider handles sign in. Name each one and state your method. With a carve out, you list the controls you assume the vendor operates, and the auditor tests your vendor oversight instead: the report you read, the review you did before onboarding. With the inclusive method the vendor’s controls sit inside your examination, which needs the vendor’s own assertion and cooperation. A small company will not get that from a hyperscaler. A list of vendors with no method leaves the reader guessing. Complementary user entity controls covers both methods, and how to tell if a report is real shows how a buyer reads your answer.

What your customers have to do

A carve out points down to your vendors. The complementary user entity controls point up to your customers. These are tasks the customer must perform so your controls deliver what Section 3 claims, and they are listed near its end. Write them as tasks with a pace and a trigger. “The customer reviews its admin users each quarter and removes access when an employee leaves” can be checked. “Customers are responsible for their own security” cannot.

How Section 3 ties to your signature

Section 2 is management’s assertion. It states that the description presents the system as designed and implemented and that the controls were suitably designed for the criteria in scope.3 An officer signs it, and the management assertion template has the wording. The auditor treats Section 3 as the terms of that statement. Claiming too much costs more than claiming too little, because you widened what is tested and then signed for it. The PBC list asks for this document before fieldwork. A Security only scope keeps it to the common criteria; the scoping tool shows when more is needed.4

Write it yourself, or have it drafted

With this template, a founder can draft Section 3 in a day. Hiring it out is priced differently:

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

The cybersoftware software drafts Section 3 from your questionnaire answers and keeps it in step with your evidence, at $199 a month, cancel any time. Audits come with access to our preferred pricing program. Take the free readiness assessment or see pricing.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What is the system description in a SOC 2 report?
Section 3 of the report. It explains the service being examined: what it does, where its boundary is, the infrastructure and software inside it, the people and procedures that run it, the vendors it depends on and the controls in place. Your company writes it and asserts it is accurate, and the auditor tests against it.
Does the company or the auditor write it?
The company. If the CPA firm wrote it, the firm would be examining its own work, which breaks independence. The firm tells you what it must cover and returns sentences it cannot test, but the words are yours.
What should a boundary statement include?
Specific names: the products and environments in scope, the cloud accounts and regions, the databases, repositories and pipelines, the identity systems, and a list of what is out. Someone should be able to sketch the boundary from your paragraph alone.
Carve out or inclusive for vendors?
Carve out, for nearly every small company. The inclusive method puts the vendor inside your examination and needs the vendor to sign its own assertion and be tested alongside you. With a carve out, you name the vendor, list the controls you assume it runs, and your own vendor oversight is tested instead.
What goes wrong with a vague description?
The auditor cannot tell what is in scope, so fieldwork starts with scoping talks and every test inherits the doubt. Loose wording can also pull in systems nobody asked about, which means more evidence and more cost.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. AICPA Code of Professional Conduct AICPA. Independence, integrity, commissions and referral fees. Checked 1 August 2026.
  3. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  4. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.