Does an agency need SOC 2? What client reviews ask for

When you work inside client accounts, your access to them is the system a report describes.

Does an agency need SOC 2? Only when a client’s security review asks for one. A SOC 2 is an examination a company commissions from a CPA firm,1 and no law requires an agency to hold one. When a client does ask, the report covers less of their world than you might fear: your own systems, and your access to theirs.

That access is the whole engagement. Who can sign in to which client account, how they got there, and how fast they lose it.

This applies to software development shops and marketing agencies alike. One works in client repositories and cloud accounts. The other works in client ad, analytics and marketplace accounts. The mechanism is identical.

When a client review asks for SOC 2

The request arrives inside a vendor review. A client’s security or procurement team sends a questionnaire, and one of the questions asks for a SOC 2 report. From then on, the report can be a condition of a renewal or a new contract.

The questionnaire may be the client’s own or a standard one. The Cloud Security Alliance publishes the Consensus Assessments Initiative Questionnaire (CAIQ) v4, a set of yes or no questions a cloud customer may put to a provider.2 An agency running client work in the cloud fits that frame closely enough to receive it.

If the review has a date, what to do when a customer asks for a SOC 2 report works backwards from it.

What the system is when you work in client accounts

A system description has to state what the system is and where its boundary sits.3 For an agency, the honest boundary runs between your environment and theirs.

Inside your boundary
Your identity provider and laptops. Your password manager, drive and chat, wherever client data or credentials land. Your project tooling. And the access your people hold to client accounts.
Outside it
The client’s AWS account, ad accounts, store and repositories. The client owns and operates them, so their controls are the client’s, not yours.

Draw it that way and the report tests what you actually run. Draw it around the client systems and you are asserting controls you do not operate. An auditor will ask you to evidence them, and you cannot.

Contractors and offshore staff

If you staff work with contractors, freelancers or a team in another country, the rule is simple. For the report, anyone who touches a client account is one of your people. They need the same onboarding record, background check where your policy requires one, device rules and offboarding as an employee.

Hiring through an employer of record raises its own scoping question. Contractors and employers of record covers whether the provider is a subservice organization and what evidence you still owe.

Client account access is the central control

Logical access is one of the common criteria every SOC 2 tests.4 For an agency it carries most of the report. Five rules make it testable.

  1. Keep an inventory. Every client account your people can reach, with the named users on each. If you cannot list them, you cannot review them.
  2. Use named access, never shared logins. Platforms support this. Google Ads, for one, grants each user one of five access levels from Email-only to Admin.5 A client adds your developer to a repository as an outside collaborator on GitHub.6
  3. Grant the lowest level that does the job. Read-only for reporting work. Admin only where the engagement needs it.
  4. Review it quarterly. Walk the inventory, confirm each user still needs each account, and record what you removed. The access review template has the columns.
  5. Remove it the same day. When someone leaves an engagement or the company, their access to every client account goes with them. The offboarding checklist lists the steps.

One structure deserves its own attention. A manager account linked to several client ad accounts concentrates access: on Google Ads, admins on a linked manager account can manage the client’s campaigns.5 Keep that admin list short, protect it with strong multi-factor authentication, and review it first.

The controls the client keeps

Some controls only the client can run. They decide who from your team gets into their account. They can remove your people at any time. They set their own multi-factor rules. Those belong in your description as complementary user entity controls, written so a client can tell what it has agreed to do.

How to word CUECs shows the difference between a sentence that transfers a duty and one that decorates.

One report, not one per client

A SOC 2 describes your system and the controls you run across every engagement. One report serves every client who asks. A client with a requirement the report does not cover, a data location rule or a named contact for incidents, handles it in the contract or the questionnaire, not in a second examination.

Scope stays narrow on purpose. Security is the one category every SOC 2 includes, and Polara G.R.C. scopes Security only.

Answer the questionnaire first

A report takes time. A review may not wait for it. Answer the questionnaire completely and honestly now, say what is in progress, and give the date your examination is planned. How to answer a security questionnaire has wording for the no SOC 2 yet case.

What it takes, and what it costs

Through Polara Labs it is audit-ready starting at about a week of focused work. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report is optional: $2,000 added later, or $4,000 in total with onboarding, with the engagement fee for the independent partner auditor inside it. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

Does a marketing agency need SOC 2?
Only if a client asks for it, usually through a vendor security review. Nothing requires an agency to hold one. When a client does ask, the report covers your own systems and your access to theirs: the ad, analytics and marketplace accounts you manage, and where you keep their data.
Does a software development agency need SOC 2?
The same rule applies: it is a client requirement, not a legal one. For a development shop the central control is access to client repositories and cloud accounts, and the people who hold it, including contractors.
Is the client's AWS account in the agency's SOC 2 scope?
Usually not. The client owns and operates that account, so its controls are the client's. What is in your scope is how your people get access to it, how that access is limited and reviewed, and how quickly it is removed when someone leaves the engagement.
Do we need a separate SOC 2 report for each client?
No. One report describes your system and the controls you run across every client. A client with a requirement the report does not cover handles it in the contract or in its questionnaire.
What can an agency send before it has a SOC 2 report?
A complete, honest answer to the client's questionnaire, a short written security overview, and the date your examination is planned. Say plainly what is in progress. A partial answer that is accurate does more for a review than a confident one that is not.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. STAR Level 1: Security Questionnaire (CAIQ v4) Cloud Security Alliance. Yes or no questions a cloud customer may ask a cloud provider. Checked 2 October 2026.
  3. 2018 SOC 2® Description Criteria (With Revised Implementation Guidance, 2022) AICPA. The benchmarks for preparing and evaluating the system description, DC 200. Checked 2 October 2026.
  4. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  5. About access levels in your Google Ads account Google. The five access levels and what a linked manager account can do. Checked 2 October 2026.
  6. Adding outside collaborators to repositories in your organization GitHub. How a client grants a person outside its organization access to a repository. Checked 2 October 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.