What is in a SOC 2 report?
A SOC 2 report has five sections. Section I is management’s description of the system — the service organization’s own description of what they do and what controls they operate. Section II is the auditor’s opinion on that description. Section III contains the criteria and management’s assessment of each. Section IV (Type II only) is the auditor’s tests of controls and results. Section V contains additional information. For vendor risk purposes, Section IV is where the work lives: it lists every control tested, the test procedure, and whether any exceptions were found.
What does a SOC 2 exception mean?
An exception means the auditor observed an instance where a control did not operate as designed during the audit period. Not all exceptions are equal. A single instance of a user account not being deprovisioned within the policy timeframe is very different from recurring failures in a vendor’s patch management process. To evaluate an exception, look for: (1) how many instances were found relative to the test population; (2) whether the exception relates to a criterion relevant to your data; (3) whether management’s response explains a root cause and remediation; and (4) whether the same exception appeared in prior reports.
What is the scope of a SOC 2 report?
SOC 2 reports are scoped to specific criteria (security is always included; availability, processing integrity, confidentiality, and privacy are optional) and specific systems. A vendor with multiple products may have a SOC 2 that covers only one of them. A vendor who acquired a company may not have integrated the acquisition into scope. The system description in Section I tells you what is included. Anything outside scope requires separate assessment.
How do you evaluate a SOC 2 report’s freshness?
SOC 2 Type II reports cover a specific audit period — typically the twelve months ending on the report date. A report dated March 2024 covering April 2023 through March 2024 tells you about controls as they operated in that period, not today. TrustVendor’s assurance score weights SOC 2 evidence by its age: a report dated within three months is fresher than one dated fourteen months ago, and the decay is shown explicitly rather than hidden behind a static rating.