NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
SOC 2 Audit: What to Expect From Start to Report
Learn

SOC 2 Audit: What to Expect From Start to Report

·Alexander Sverdlov

A SOC 2 audit is, formally, an examination: an attestation engagement in which a licensed CPA, in the United States working to AICPA standards AT-C 105 and AT-C 205, expresses an opinion in a written report. Expect to write two things yourself before the auditor tests anything: a description of your system against the AICPA's description criteria, and a written assertion by management. For a Type 2, expect the auditor to test whether your controls operated effectively throughout a period you chose, by sampling evidence from across it. Expect an outcome that is not pass or fail but one of four opinions: unmodified, qualified, adverse or a disclaimer. And expect to sign a representation letter dated the day the report is issued.

Most guides to this query describe a SOC 2 as a test you pass. The standards describe something else: a report about statements you make, in which the auditor's job is to say whether those statements hold. That changes how you prepare. This guide follows the examination in order, quotes the AICPA wherever it says something specific, and ends with a checklist. The difference between the two report types is in our guide to SOC 2 Type 1 vs Type 2; what drives the fee is in SOC 2 cost outside the US.

MomentWhat happensWhere it comes from
Scope and periodManagement picks the categories, the system and, for a Type 2, the periodAICPA SOC 2 FAQ
System descriptionYou describe the system against the description criteriaDC section 200
Management assertionManagement asserts the description is fairly presented and the controls are suitably designed and, for a Type 2, operated effectivelyAT-C 205.10
TestingType 2: tests of operating effectiveness across the period; inquiry alone is not enoughAICPA SOC 2 FAQ
RepresentationsA letter from management, dated as of the report dateAT-C 205.51 and .55
ReportDescription, assertion, opinion and, for a Type 2, tests and resultsAICPA guidance for service organization management
The shape of a SOC 2 Type 2 examination: agree scope and period, write the system description, operate the controls, the auditor tests samples, management representations and the report

What does a SOC 2 audit produce?

A report with four parts. The AICPA's guidance for service organization management lists them: the description of the system, management's assertion, the service auditor's opinion, and, for a Type 2 only, a "description of the service auditor's tests of controls and results thereof." A Type 1 covers the description and the suitability of design as of a point in time. A Type 2 adds whether the controls "operated effectively throughout the period".

The report is not public. The same guidance says the service auditor's report "is required to be restricted to specified parties" with the knowledge to understand it, and that handing it out for general marketing is likely inappropriate. For that, the AICPA points to a SOC 3, a general use report that covers the same categories with less detail. There is no Type 1 SOC 3.

What a SOC 2 report contains: the system description, management's assertion, the auditor's opinion and, for a Type 2 only, the tests and results, with use restricted to specified parties

What will you have to write before testing starts?

The system description, and it is yours, not the auditor's. It is measured against the AICPA's description criteria, DC section 200, which set what the description has to disclose, including the service commitments and system requirements your controls are meant to achieve. The AICPA's FAQ adds that "there is no minimum set of controls or standardized template of controls"; you design controls to meet the Trust Services Criteria for the categories in scope. The common criteria, CC1.1 to CC9.2, apply in every SOC 2 and are aligned to the 17 principles of the 2013 COSO framework.

Then the assertion. AT-C 205.10 says the practitioner "should request from the responsible party a written assertion". This is not a formality: under AT-C 205.84, if the responsible party refuses, the practitioner should withdraw where the law allows, and otherwise disclaim an opinion. Plan for the assertion to be signed by someone senior enough to stand behind it.

How does the auditor test a Type 2?

By examining evidence from across the period. The AICPA's SOC 2 FAQ says inquiry alone is "unlikely to provide sufficient appropriate evidence" of operating effectiveness, so expect requests for records: access reviews, change tickets, incident logs, training records, the output of monitoring. A control that ran in month one and month six but not in between is the kind of gap testing finds.

The period is your decision. The FAQ says the SOC 2 guide "does not prescribe a minimum period of time" and that the period "is a business decision made by service organization management after considering the informational needs of intended users". It gives one warning: for a period of less than two months, as an example in paragraph 2.46 of the guide, the auditor may conclude that sufficient appropriate evidence is unlikely to be obtainable. A longer period gives the auditor more to sample and you more to keep.

Illustrative view of a SOC 2 Type 2 period midway: system description approved, controls with evidence for the period, quarterly access reviews done and vendor SOC reports collected

What happens with your cloud provider and other vendors?

DC section 200 gives two ways to handle a subservice organization, such as the cloud platform you run on. Under the carve-out method, its system is excluded from your description and from the scope of the examination, but your description still identifies the services it performs, the types of controls expected of it, and the controls you use to monitor it. Under the inclusive method, its controls are subject to the auditor's procedures, and the auditor must be independent of both organizations. With carve-out, expect to show how you monitor the provider, for example by reviewing its own SOC report.

Two terms will appear in your description. Complementary user entity controls are controls you assumed your customers would implement, necessary in combination with yours to meet your service commitments and system requirements. Complementary subservice organization controls are the same idea for your subservice organizations. Customers should read these sections closely, because they say what the customer has to do itself.

Venvera SOC 2 Type 2 dashboard showing categories in scope, controls operating effectively, open findings and criteria coverage for availability, confidentiality, privacy, processing integrity and security

What are the possible outcomes?

AT-C 205 defines a modified opinion as "a qualified opinion, an adverse opinion, or a disclaimer of opinion". Without any of those, the opinion is unmodified. A qualified opinion follows misstatements that are material but not pervasive; an adverse opinion follows misstatements that are both material and pervasive; a disclaimer follows an inability to obtain sufficient appropriate evidence where the possible effects could be both material and pervasive. The AICPA's management guidance says the auditor "may identify deficiencies or deviations that may cause the service auditor to qualify the opinion," and in a Type 2 the tests and their results are set out in their own section, which the FAQ calls section 4.

A deviation is not automatically a qualification. Since 2018, the effect is judged against your service commitments and system requirements, and the FAQ notes that the same deficiency could lead to a qualified opinion for one service organization but not for another. That is a reason to write your commitments carefully in the description: they are the yardstick.

The four possible SOC 2 opinions under AT-C 205: unmodified, qualified when material but not pervasive, adverse when material and pervasive, and a disclaimer when evidence is insufficient

What happens at the end of the audit?

Management signs a representation letter. AT-C 205.51 says the practitioner should request "written representations in the form of a letter addressed to the practitioner," including management's assertion, and AT-C 205.55 says they should be dated "as of the date of the practitioner's report." The report is issued with that date. If you need the report for a deal on a given day, the letter and its signatory have to be ready for that day too.

Does the auditor have to be independent of you and your tools?

Yes. AT-C 105.26 says the practitioner "must be independent" when performing an attestation engagement, and AT-C 205.06 requires a disclaimer that states the lack of independence if a practitioner who is not independent is required by law to accept the engagement anyway. An April 2026 Journal of Accountancy article on compliance tool providers adds that if a tool provider is a responsible party, the auditor must be independent of it too, that the fee must be set by the service auditor using professional judgement, and that a third party controlling the fee or tying it to other services may impair independence. Ask any auditor who arrives bundled with a platform how it meets those rules.

What the other results get wrong

Page one for this query is mostly compliance automation vendors. Four claims recur that the AICPA's own material contradicts. The first is a minimum period, usually three months, stated as a rule; the FAQ says the guide prescribes no minimum. The second is the pass or fail framing; the outcome is one of four opinions, and a qualified report with clear descriptions can still serve a customer. The third is that a qualification means a whole criterion failed; the FAQ says the effect is judged against service commitments and system requirements. The fourth is the word certification; a SOC 2 is an examination report.

Prepare for your own audit

Fill this in before the auditor's first request list arrives.

QuestionYour answerWhy it matters
Which report does the customer asking for it accept: Type 1 or Type 2, which categories?Sets the scope and the testing.
What period will the Type 2 cover, and why that length?No minimum is prescribed; under two months risks the opinion.
Who drafts the system description, and who signs the assertion?Both are management's; a refused assertion ends in withdrawal or a disclaimer.
Which subservice organizations are carved out, and do you hold their SOC reports?Carve-out still requires you to monitor their controls.
Which complementary user entity controls will you list?Customers read them as their own obligations.
Can you produce evidence for every control for every month of the period?Inquiry alone is unlikely to be sufficient.
Who signs the representation letter on the report date?AT-C 205.55 dates it as of the report.
Venvera SOC 2 gap assessment page listing a completed Type 2 readiness assessment with its date, creator, status and an 83 percent score

Venvera's SOC 2 module maps your controls to the Trust Services Criteria, dates the evidence behind each one, and shows which controls are missing evidence for the period, so the request list is answered from records you already keep. Controls you run for ISO 27001 or HIPAA can serve as evidence for the same criteria. Venvera is not a CPA firm and does not issue SOC reports. Start with the SOC 2 readiness checklist, or see how to collect audit evidence. The certification audit for ISO 27001 works differently, and is covered in what to expect in an ISO 27001 audit.

The bottom line on a SOC 2 audit: the auditor tests the whole period, so the evidence has to cover the whole period

Frequently asked questions

Can you fail a SOC 2 audit?

Not in the sense of a pass mark. The auditor issues an unmodified, qualified or adverse opinion, or disclaims one. Whether a qualified report is acceptable is a question for the customer reading it.

How long must a Type 2 period be?

The AICPA prescribes no minimum. The period is management's decision; under two months, the auditor may conclude sufficient evidence is unlikely to be obtainable.

Can we publish our SOC 2 report on our website?

No. Use of a SOC 2 report is restricted to specified parties. A SOC 3 is the general use report meant for that.

Who can perform a SOC 2 audit?

In the United States, a licensed CPA under AT-C 105 and 205. Outside it, a CPA or equivalent licensed in another jurisdiction may perform one where local law permits, usually under ISAE 3000 (Revised).

Primary sources

Report contents, Type 1 and Type 2, restricted use and qualification are from the AICPA's information for service organization management in a SOC 2 engagement. Period length, inquiry, controls and the 2018 change are from the AICPA SOC 2 and SOC 3 FAQ. Assertions, representations, opinion types and independence are from SSAE No. 21, which restates AT-C 105 and 205. Carve-out, inclusive, CUEC and CSOC definitions are from DC section 200; the categories, common criteria and COSO alignment from the Trust Services Criteria; SOC 3 from the AICPA's SOC 3 page; tool provider independence from the Journal of Accountancy. Several AICPA documents require a free account.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING