What a vendor's SOC 2 report does and does not tell you
A SOC 2 Type II report is genuinely useful evidence. It is also routinely over-read. Most of the value is lost because nobody checks three specific things on the cover page.
The three things to check first
- 1. The period, not the date
- A Type II report covers a window that has already closed. "Current" usually means the most recent report exists, not that it covers now. The gap between the period end and today is the part nobody is attesting to, and it is frequently over a year.
- 2. The scope
- Which trust services criteria are in scope? Security is mandatory. Availability, confidentiality, processing integrity and privacy are optional and often absent. A report covering Security only says nothing about whether your data stays confidential.
- 3. The opinion and the exceptions
- Read the auditor's opinion and the exceptions table, not the summary. A qualified opinion, or a list of exceptions in controls you depend on, is the most valuable page in the document and the least read.
Type I versus Type II
A Type I report says the controls were suitably designed at a point in time. A Type II says they operated effectively over a period. A vendor offering a Type I for a critical service is offering a design review, and it should be treated as an interim answer.
What SOC 2 asks of you about your own vendors
If you are pursuing SOC 2 yourself, vendor management is not optional.
- CC9.2
- Assess and manage risks associated with vendors and business partners. Your auditor will ask how, and how often.
- CC3.2
- Identify and analyse risks to objectives, which includes risks introduced through third parties.
- CC4.1
- Ongoing and separate evaluations to determine whether controls are functioning. The word ongoing is doing real work in that sentence.
The usual audit finding is not that vendor management is absent. It is that the evidence is a folder of documents with no record of anyone having assessed them, and no cadence.
The bridge letter question. When a report's period has ended, a vendor may offer a bridge letter covering the gap. That is management's assertion, not an auditor's opinion. It is better than nothing and it is not the same thing. Record which one you hold.
Where continuous assurance fits
SOC 2 is annual by design, and there is nothing wrong with that. The gap is the eleven months in between, and what happens in them.
- Track the period end date of every report you hold and raise it as a finding when coverage lapses, rather than discovering it at renewal.
- Record which criteria each report covers, so a confidentiality question is not answered with a security-only report.
- Watch the public signals continuously. A vendor's SOC 2 says nothing about the DMARC policy they relaxed last month.
- Keep the exceptions table with the vendor record, so a known weakness stays visible rather than being filed and forgotten.
The sample finding is exactly this case: an attestation that said "current" and covered a period that ended nineteen months earlier.
How many of your vendor attestations have lapsed?
It is usually more than expected. We will tell you the number before you commit to anything.
Book a call