Glossary

SOC Report

If you have ever evaluated a cloud provider, SaaS company or other technology vendor, you may have been asked whether the company has a SOC report.

A SOC report is an independent auditor’s report on the controls a service provider has in place. It gives customers a way to look beyond a vendor’s own claims and see whether important processes around security, availability, financial reporting or data protection have been independently examined.

The most familiar example in technology is the SOC 2 report. Companies often request one when deciding whether to trust a vendor with business-critical systems or sensitive data.

But SOC 2 is only one type of SOC report, and simply saying that a company is “SOC compliant” does not tell you very much.

What does SOC mean?

SOC stands for System and Organization Controls.

The reports are part of a framework created by the American Institute of Certified Public Accountants, or AICPA. Independent CPA firms perform the examinations.

The basic idea is straightforward: when one company relies on another company for an important service, it also takes on some of that provider’s risk.

A business using a payroll company depends on that company to process financial information correctly. A company using a SaaS platform may depend on the provider to protect customer data. An organization using hosted infrastructure may depend on the provider to control administrator access and keep systems available.

Customers cannot realistically audit every vendor themselves. A SOC report gives them a standardized way to see what an independent auditor found.

What does a SOC report actually tell you?

A SOC report describes:

  • the service or environment being examined
  • the controls the provider has in place
  • the criteria the auditor used
  • how those controls were tested
  • what the auditor found

For a technology provider, those controls might include how employees receive administrative access, how access is removed when someone leaves, how software changes are approved, how incidents are handled or how systems are monitored.

A SOC report does not simply say: “This company is secure.”

It is closer to saying: “These are the controls we examined, this is how we tested them, and this is what we found.”

That is why the actual report matters more than a SOC logo on a vendor’s website.

SOC 1 vs. SOC 2 vs. SOC 3

There are three SOC reports you are most likely to encounter. They sound like different levels of the same certification. They are not.

Report Main focus Most relevant to
SOC 1 Financial reporting controls Finance teams and financial auditors
SOC 2 Security and operational controls IT, security, procurement and compliance teams
SOC 3 Public summary of SOC 2 assurance Customers and the general public

For most IT and cybersecurity teams, SOC 2 is the most relevant report.

SOC 1

SOC 1 looks at controls that could affect a customer’s financial reporting.

Imagine a company outsources payroll processing. If the payroll provider calculates transactions incorrectly or lacks proper controls around financial data, that could affect the customer’s financial statements.

A SOC 1 report gives the customer and its financial auditors information about those controls. It is commonly relevant to services such as payroll processing, transaction processing, claims administration and certain financial platforms.

SOC 1 is not primarily a cybersecurity report.

SOC 2

SOC 2 is the report most commonly requested when evaluating technology companies.

It examines controls related to five areas known as the Trust Services Criteria:

  • Security
  • Availability
  • Processing integrity
  • Confidentiality
  • Privacy

Security is the foundation of a SOC 2 examination. The other areas may be included depending on the service and what the organization wants covered.

For example, a cloud service could have controls covering who can access production systems, how privileged accounts are managed, how incidents are handled and how changes to the environment are approved. The auditor examines those controls and reports on the results.

This is why procurement, security and compliance teams frequently request a SOC 2 report during vendor due diligence.

SOC 3

SOC 3 covers the same general Trust Services Criteria used for SOC 2 but provides much less detail. The main difference is who can read it.

A full SOC 2 report contains information about internal systems, controls and audit testing, so companies usually restrict access to customers and qualified prospects. SOC 3 reports are designed for public distribution.

A vendor may therefore publish its SOC 3 report on its website while requiring an NDA or customer relationship before providing the full SOC 2 report.

If you are performing a serious vendor assessment, the SOC 2 report is usually the more useful document.

SOC 2 Type I vs. Type II

You will also see SOC 2 reports described as Type I or Type II. This is one of the most important distinctions to understand.

  Type I Type II
What it evaluates Design of controls Design and operating effectiveness
Time period A point in time A defined period
Main question Are the controls in place? Did the controls actually work over time?

Suppose a company has a policy requiring administrator access to be reviewed regularly.

A Type I examination can determine whether that control exists and is appropriately designed. A Type II examination can test whether those access reviews actually happened during the audit period.

That is why customers often place more weight on Type II. Type I shows that the control exists. Type II provides evidence that it operated.

Is SOC 2 a certification?

Not exactly.

SOC 2 is commonly called a certification, but technically an independent CPA firm performs an examination and issues an attestation report. A company does not simply pass a test and become permanently “SOC 2 certified.”

The report covers a specific:

  • system or service
  • scope
  • set of controls
  • examination period

That distinction matters because two companies can both say they have completed SOC 2 examinations while having very different scopes. One report might cover nearly the company’s entire cloud platform. Another might cover only a specific service or business unit.

So the more useful question is not: does the vendor have SOC 2? It is: what exactly did the SOC 2 examination cover?

What should you look for in a SOC 2 report?

You do not need to be an auditor to get useful information from a SOC 2 report. Start with four things.

1. Check the scope

Find out which product, service or environment the report covers. If you are purchasing Product A but the report only covers Product B, the report may not provide the assurance you think it does.

2. Check the dates

A SOC 2 Type II report covers a defined period. An older report may not reflect major changes the company has made since then.

3. Review exceptions

SOC reports may identify situations where a control did not operate exactly as expected. An exception does not automatically mean the vendor has poor security. What matters is:

  • what failed
  • how often it happened
  • how serious the issue was
  • whether it was corrected

4. Look at outside dependencies

Many service providers rely on other companies. A SaaS provider may run on AWS, Microsoft Azure or another infrastructure provider, for example.

The report should explain how those outside organizations fit into the environment being examined.

Does SOC 2 mean a company is secure?

No. This is one of the most important things to understand about SOC 2.

A SOC 2 report provides evidence about specific controls within a defined scope and period. It does not prove that:

  • the company can never be breached
  • every product is secure
  • every system was included
  • every security control is perfect
  • the vendor meets every regulatory requirement

SOC 2 is useful because it provides independent evidence about the company’s control environment. But it does not replace technical due diligence.

If you are evaluating a storage platform, for example, you may still need to determine whether it supports encryption, immutability, role-based access controls, data sovereignty requirements, ransomware recovery or the performance your applications require.

A SOC report helps you evaluate the organization and its controls. It does not answer every question about the product itself.

Why SOC reports matter for infrastructure and data storage

SOC reports become particularly important when a vendor has access to sensitive data or critical infrastructure.

Consider a managed service provider that administers part of your environment. You may want to know:

  • How are administrator accounts protected?
  • Who can access customer systems?
  • How is access approved?
  • How quickly is access removed when employees leave?
  • How are incidents handled?
  • How are system changes controlled?

The same questions apply to cloud services, hosted platforms and other services handling enterprise data. Organizations may be trusting these providers with backups, customer information, financial records, intellectual property or data used by AI applications.

A SOC 2 report provides one source of evidence for evaluating that relationship. But it should still be combined with questions about the technology itself.

For data storage, that can include how data is encrypted, whether immutable copies can be created, where data resides, how deletion is controlled and how the system behaves during a cyberattack or infrastructure failure.

SOC 2 vs. ISO 27001

SOC 2 and ISO 27001 frequently appear together on vendor security pages, but they are different forms of assurance.

  SOC 2 ISO 27001
What it is Independent attestation report Information security standard and certification
Primary focus Specific controls and their operation Information security management system
Output Detailed auditor report Certification
Common audience Customers, auditors and risk teams Customers and organizations worldwide

Neither automatically replaces the other. Many technology providers maintain both because different customers and markets may ask for different forms of assurance.

Frequently asked questions

What is a SOC report in simple terms?

A SOC report is an independent auditor’s report on the controls used by a company that provides services to other businesses. It helps customers understand whether important processes around security, financial reporting, system availability or data protection have been independently examined.

What does SOC stand for?

SOC stands for System and Organization Controls. This is different from a security operations center, which is also commonly abbreviated SOC in cybersecurity.

Which SOC report is most relevant for technology vendors?

Usually SOC 2. It is commonly used to evaluate SaaS, cloud, infrastructure and other technology service providers.

Is SOC 2 Type II better than Type I?

Type II generally provides stronger evidence because it examines whether controls operated effectively over a period of time. Type I evaluates controls at a specific point in time.

Is SOC 2 required by law?

There is no universal law requiring every technology company to complete a SOC 2 examination. However, customers may require one before approving a vendor, particularly when the vendor will handle sensitive data or provide an important business service. For many vendors, SOC 2 therefore becomes a practical requirement for selling into larger enterprises.

The key takeaway

A SOC report is ultimately about trust between one organization and another. When a company hands an important function to an outside provider, it needs some way to evaluate the controls behind that service. SOC reports provide independent evidence that helps customers do that.

SOC 1 focuses on financial reporting controls. SOC 2 focuses on security and related operational controls. SOC 3 provides a less detailed version of SOC 2 assurance that can be shared publicly.

And Type I versus Type II answers another important question: were the controls simply in place, or did the auditor also test whether they worked over time?

That is the real value of a SOC report. It gives customers something more useful than a vendor saying, “Trust us.”