What Is in a SOC 2 Report

TL;DR

A SOC 2 report is a CPA firm’s opinion on your controls, written in five sections. Four of them carry the opinion. The fifth does not, and that is the section most buyers read first.

  • Section I holds the auditor’s report and the opinion. Section II holds management’s assertion. Section III describes the system. Section IV lists every control, the test the auditor ran, and the result.
  • Section IV is the report. It is the only place you see an exception, and the only place you see how a control got tested.
  • Section V carries management’s response to the exceptions. The auditor disclaims an opinion on it, and says so in writing.
  • A Type 2 report covers a period. A Type 1 covers a single date. The date on the cover is the report date, not the coverage.
  • The system description has to meet nine description criteria, DC1 through DC9. Missing ones show up as a qualified opinion.
  • No trust services criterion asks where your data sits. A clean SOC 2 report tells a Canadian buyer nothing about residency.

5Sections in a SOC 2 report
9Description criteria the system description must meet
61Criteria across all five trust services categories
0Criteria that ask where your data sits

Sources: AICPA Trust Services Criteria · Linford & Co, criteria count · AICPA DC section 200

What a SOC 2 report is, and what it is not #

A SOC 2 report is an attestation report. A licensed CPA firm examines the controls you claim to run, tests them, and states an opinion on what it found. The AICPA owns the framework. The work happens under the attestation standards, which SSAE No. 21 revised for reports dated on or after 15 June 2022.

Three things follow from that, and all three surprise people.

  1. There is no certificate. Nobody issues you a SOC 2 badge. You get a report, and the report is the deliverable. See what SOC 2 is for the wider framing.
  2. There is no score. No pass mark, no percentage, no grade. An auditor forms an opinion in prose, and you read it.
  3. Restricted use. The report names its intended users and tells everyone else to stop reading. The restriction sits inside the report itself. That is why vendors hand a SOC 2 report over under an NDA rather than posting it on a trust page.

Most of the page count sits in Section IV, which lists every control one row at a time.

The five sections of a SOC 2 report #

Auditors number the sections in a conventional order. Firms vary the labels. The contents do not vary, because the description criteria and the attestation standards set them.

Section What it contains Covered by the opinion
I Independent service auditor’s report Scope, the responsibilities of each party, the inherent limitations of controls, and the opinion itself It is the opinion
II Management’s assertion Your own signed statement that the description is fair and the controls operated as described Yes. The auditor tests your assertion
III Description of the system Services, boundaries, infrastructure, software, people, procedures, data, incidents, and the controls you rely on Yes, against the nine description criteria
IV Trust services criteria, controls, tests and results Every criterion, every control mapped to it, the test the auditor performed, and the result Yes. This is where the work shows
V Other information provided by management Management’s response to exceptions, roadmap items, subsequent events No. The auditor disclaims an opinion on it

Section III has a checklist behind it #

The system description looks like marketing prose. It is not. The AICPA description criteria set nine requirements it has to satisfy, DC1 through DC9. The types of services. The service commitments and system requirements. The system components. The incidents that happened. The applicable criteria and the related controls. The complementary user entity controls. The subservice organizations and the method used for them. Any criteria you left out, with reasons. And, for a Type 2, the significant changes during the period.

DC4 is the one to look for as a buyer. If the vendor had an incident during the period, the description has to disclose it.

Section V is not audited, and says so #

What trips people up

Section V is where a vendor explains why an exception does not matter. The explanation may be true. It carries no assurance. The auditor states that the section falls outside the scope of the examination and disclaims an opinion on it. Read Section IV first, form your own view of the exception, then read the response.

How to read the test results #

Section IV runs as a table. Each row holds a control, the test the auditor performed, and the result. Two columns decide what the report is worth.

The result column #

Most rows read “No exceptions noted”. A row that does not is a deviation, and the auditor describes it. Count them, then read them. One failed access review in a quarter is not the same as a change management process that nobody followed.

Exceptions do not void a report. A report with zero exceptions and a narrow scope tells you less than a report with three exceptions and a wide one.

The test column #

Auditors use four kinds of procedure. Inquiry means they asked. Observation means they watched. Inspection means they examined a document or a configuration. Reperformance means they ran the control themselves.

What good looks like

A control tested by inspection of a sample across the period, with the sample size stated. A control tested by inquiry alone tells you the auditor asked somebody and wrote down the answer. Scan Section IV for how often “Inquired of management” stands on its own. That count says more about the rigour of the examination than the firm’s logo on the cover.

The opinion, and the dates #

Section I ends in one paragraph that carries the whole report. Four outcomes exist.

  1. Unqualified. The description is fair, the controls were suitably designed, and for a Type 2 they operated as described. This is the clean result.
  2. Qualified. Everything holds except a named matter, described in a basis paragraph above the opinion. Read that paragraph. A qualification over one control in one criterion is a different animal from a qualification over the description itself.
  3. Adverse. The auditor concludes the description is not fair or the controls did not operate. Rare, and decisive.
  4. Disclaimer. The auditor cannot form an opinion. Treat it as no report at all.

Period, not date #

A Type 1 report covers controls as of a single date. A Type 2 covers a period, and the period is the point of the exercise. Our guide to Type 1 against Type 2 covers the choice. When you read someone else’s report, find the period on the first page of Section I and ignore the date on the cover. The cover date is when the auditor signed.

What a bridge letter does #

Reports go stale. A period that ended in March reaches a buyer in November with eight months uncovered. A bridge letter fills the gap. Management writes it, management signs it, and the auditor does not. It states that nothing material changed since the period ended. Most cover no more than three months. It is a representation, not assurance, and a buyer who treats it as a second report has misread it.

What a SOC 2 report will not tell you #

Four gaps matter more than the rest.

Where the data sits #

No trust services criterion asks about data location. Security, availability, processing integrity, confidentiality and privacy carry 61 criteria between them, and none of them is residency. A vendor can hold every record in another country and still produce a clean report. If Canadian residency is a requirement, get it in the contract and check the subservice organizations named in Section III. The report will not answer it for you.

What the privacy category covers #

The privacy criteria are the AICPA’s own. They do not test PIPEDA, Quebec Law 25 or PHIPA. A vendor with the privacy category in scope met American criteria for notice, choice and retention. That is useful. It is not a Canadian privacy opinion, and nobody should present it as one.

The controls you have to run #

Complementary user entity controls sit in Section III. They are the controls the vendor assumes you operate, and the report’s conclusions depend on them. A vendor’s clean opinion assumes you configure single sign-on, review your own users and manage your own keys. Read that list. It is a to-do list addressed to you.

What the subservice organizations do #

A vendor built on a cloud platform picks one of two methods. The carve-out method excludes the subservice organization’s controls from the examination and names them instead. The inclusive method brings them inside. Carve-out is the common choice, and it means nobody tested those controls in this report. Go get the subservice organization’s own report.

Reading a Canadian SOC 2 report #

SOC terminology comes from the AICPA, and Canadian assurance standards carry no direct equivalent. CPABC says as much.

“Canadian standards currently do not specifically include reports similar to SOC 2, but an engagement under CSAE 3000 could accomplish the same.”

Chartered Professional Accountants of British ColumbiaReports on Controls at Service Organizations FAQs

So a Canadian CPA firm runs the engagement under CSAE 3000 and applies the AICPA trust services criteria to it. CPA Canada publishes a SOC 2 guide for that work, adapted from the AICPA version to meet Canadian standards. It carries illustrative service auditor’s reports and the 2018 description criteria.

Two practical consequences for a Toronto or Vancouver team.

  1. Check which standard Section I names. A report referencing CSAE 3000 alone reads as unfamiliar to a US procurement team. Ask your firm to report against both Canadian and US standards. CPA Canada’s guide covers that case, and a dual reference removes an argument you do not need during a deal.
  2. A Canadian report carries the same weight. The criteria are identical and the auditor is a licensed CPA firm. Buyers who push back are reacting to the wording in Section I, not to a real difference in rigour.

What is changing in the standards #

The trust services criteria have not changed since 2017. The AICPA revised the points of focus in 2022 and left the criteria alone. Behind them, the Auditing Standards Board proposed revisions to the attestation standards in February 2026, covering evidence and risk assessment. Comments closed on 30 June 2026. The board expects to adopt the changes in 2027. The proposed effective date covers engagements that begin on or after 15 June 2029. Nothing in your next two audits depends on it. Anyone selling you an urgent 2026 remediation project because of it is selling you something.

Frequently asked questions #

How many sections does a SOC 2 report have?

Five. The independent service auditor’s report, management’s assertion, and the description of the system. Then the trust services criteria with the controls and test results, and other information provided by management. The fifth section falls outside the auditor’s opinion, and some reports leave it out.

Which section of a SOC 2 report should I read first?

Section I for the opinion and the period, then Section IV for the exceptions. Section III tells you what was in scope, which is what decides whether the opinion means anything for the service you are buying. Leave Section V until you have formed your own view.

Does a SOC 2 report show failed controls?

Yes. Deviations appear in the results column of Section IV, and the auditor describes each one. Exceptions do not invalidate a report and they do not force a qualified opinion. A report with no exceptions at all is worth checking for scope, because a narrow scope makes a clean result cheap.

Is a SOC 2 report public?

No. A SOC 2 report goes to specified parties who understand the system, and the report states that limit in its own text. That is why vendors release it under an NDA. A SOC 3 report is the general use version and carries the opinion without the detail.

What is a complementary user entity control?

A control the service organization expects its customers to operate, listed in Section III. The vendor’s conclusions assume you run them. Say the report makes you responsible for provisioning your own users. Skip that job and the vendor’s clean opinion does not cover the gap.

Does a SOC 2 report prove our data stays in Canada?

No. The trust services criteria contain no data residency requirement, so nothing in the examination tests where records sit. Put residency in the contract, and check the subservice organizations named in the system description. Canadian buyers in health and public sector ask for both.

Key takeaways #

  • Five sections. Four carry the opinion, and Section V does not.
  • Section IV is the report. Read the results column and the test column together.
  • A control tested by inquiry alone is weak assurance, whoever signed the cover.
  • Four opinions exist. A qualified opinion is not a failure, so read the basis paragraph.
  • Find the period on Section I. The cover date is the signing date.
  • A bridge letter comes from management, not the auditor, and covers about three months.
  • The system description has to meet nine description criteria, including disclosure of incidents.
  • Carve-out means the cloud provider’s controls went untested here.
  • Complementary user entity controls are your homework, not theirs.
  • Nothing in a SOC 2 report addresses Canadian data residency.

HZ

Hunter Zhu Founder of Nank.ai, a Toronto firm that takes Canadian companies to SOC 2, ISO 27001, and ISO 42001. Connect on LinkedIn

Get a report your buyers can read #

Nank.ai runs SOC 2 programmes for Canadian companies from Toronto, with a dedicated compliance manager who owns the result and your data held in Canada. We scope the examination against the deals you are trying to close, and we review the draft report before your auditor signs it.

What are your feelings
Updated on September 3, 2026
Scroll to Top