How to read SOC2 report in 10 minutes

Eight Things to Look for in a SOC2 report

  1. Products and ServicesDoes the report address the products and services you’ve contracted for?
  2. CriteriaWhich of the 5 Trust Services Criteria (privacy, security, confidentiality, availability and data integrity) are included in the report?
  3. Sub-service ProvidersDoes the report cover the subcontractors (sub-service providers) of the vendor?
  4. Type I or Type IIDoes the report address the effectiveness of the controls (Type II), or only the suitability of controls (Type I)?
  5. ExceptionsIs the report “clean”?  Does it contain any material exceptions?
  6. Auditor’s Opinion Are there any qualified opinions?
  7. Management’s Assertions Are subservice organizations tested?
  8. CUEC (Complementary User Entity Controls) – Where is the CUEC description in SOC2 report? What CUEC outline to you the roles, responsibilities and obligations that you have in ensuring the stated control objectives are effective for your organization? Can the CUEC be mapped back to your own policies and procedures to ensure that you have controls in place that properly align with your vendor’s expectations.