SOC 2 · 6 min read
How to Read a SOC 2 Report
Type I vs II, the opinion, exceptions, and the CUECs everyone forgets: what to actually check.
Type I vs Type II
A SOC 2 report is an independent CPA firm's report on a service provider's controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy).
- Type I describes whether controls are *suitably designed* at a single point in time.
- Type II tests whether controls *operated effectively* over a period (usually 6–12 months).
For a vendor that handles your data, you want Type II: design alone proves nothing about whether the controls actually ran.
What to check first
- The period covered: is it current? If it's stale, ask for a bridge letter covering the gap.
- The scope: which Trust Services Categories, and which systems/services. Does it cover the service *you* actually buy?
- The auditor's opinion: *unqualified* (clean) vs *qualified* (issues). Read the opinion letter, not just the logo.
- The exceptions/deviations in the testing tables: what failed, and does it matter to you?
The CUECs everyone forgets
Complementary User Entity Controls (CUECs) are the things the report *assumes you do* on your side for the vendor's controls to be effective: like managing your own admin accounts or configuring SSO correctly. A clean SOC 2 means nothing if you don't actually perform the CUECs. Always read this section and confirm you meet each one.
