SOC 2 report example: a sample Type 1, section by section

A watermarked sample Type 1 report for a fictional company, read one section at a time.

A SOC 2 report example is easier to read once you know its five parts: the auditor’s opinion, management’s assertion, the description of the system, the criteria with the controls that meet them, and, in a Type 2, the tests and their results.1 The sample below has every part but the first, because nobody audited it.

It is a report for a fictional company. It is watermarked SAMPLE on every page, names no audit firm, and says on page one that no CPA firm examined anything in it.

Download the sample report as a PDF of 92 pages, about 2.5 MB. Nothing to sign up for.

Polara Labs assembled the sample to show the structure and depth of the package an auditor reviews, before anyone pays for one. It is nobody’s report. It is also not a preview of your own results: we do not produce free reports, and this file was not generated from anything you entered. Read it as an anatomy lesson, with this page open beside it.

Section 1: the auditor’s report, which this sample leaves empty

In a real report, Section 1 is the reason the document exists. It is the service auditor’s report: a licensed CPA firm states what it examined, under which standards, and what it concluded.2 Only a CPA firm may sign it.3

The sample’s Section 1 holds one paragraph saying that no independent service auditor has issued an opinion, and that every status in the document is management’s own. That is the honest version of a draft. Anything calling itself a SOC 2 report while that section is blank is not one.

For the authoritative layout, the AICPA publishes an illustrative SOC 2 Type 2 report with an illustrative system description. It is available to AICPA members. When an opinion is qualified or adverse, the paragraph that says so sits here too, and what happens when a report has exceptions explains the four kinds.

Section 2: management’s assertion

Management signs this part, not the auditor. In the sample it confirms two things as of March 31, 2026. First, that the description presents the system as designed and implemented, measured against the AICPA description criteria.4 Second, that the controls were suitably designed to meet the service commitments under the 2017 Trust Services Criteria for Security.5

Read the verbs. “Designed and implemented” and “suitably designed” are Type 1 language. A Type 2 assertion says the controls operated effectively throughout a period. Our management assertion template has both versions, worded line by line.

The sample adds something a real assertion would not. It quotes answers management gave in a readiness questionnaire, each one labeled as management’s representation and not a tested result. Then Section 2.1 lists 51 findings from that intake, with owners. In an issued report, deviations the auditor found appear in the opinion and in Section 4.

Section 3: the description of the system

This is the longest part of most reports, and the one a careful reader spends time on. It is written by the company and evaluated by the auditor against the description criteria. The sample covers what the criteria ask for: infrastructure, software, people, procedures and data, then the system boundary.

Three things in it matter most when you read somebody else’s report:

Subservice organizations
The sample carves out six vendors, from the cloud host to the payment processor, and lists the controls it expects each one to run. Carved out means their controls are not covered by this report. You read their own reports for that.
Complementary user entity controls
Things the customer must do for the vendor’s controls to work, such as managing the access it grants its own staff. If you are the customer, these are your obligations. How CUECs are worded covers the difference between a real one and filler.
The boundary
What is in scope and what is not. The sample names one product and one office and excludes personal devices. A feature outside the boundary is not covered, however close to it it sits.

If you are writing your own, the system description template follows the same order.

Section 4: the criteria and the controls

Section 4 maps each criterion to the controls that meet it. The sample lists every point of focus under the nine common criteria groups, 197 of them, with the control management describes, the basis for its status, an evidence reference, an owner and management’s status. No auditor tested any of it, and the section says so above the table.

This is where Type 1 and Type 2 differ most on paper. A Type 1 report describes controls as designed on one date, so there is nothing to sample. A Type 2 report adds what the auditor did to each control across the period, the sample size, and the result, with every exception written out. That column is what a Type 2 adds. Type 1 versus Type 2 covers when each one is enough.

Section 5 and the appendices

The sample’s Section 5 lists the design deficiencies management disclosed: 21 of 33 in-scope control points carry an exception as of the as-of date. Three appendices follow. Appendix A lists every artifact on file. Appendix B is management’s remediation roadmap, 49 open items with owners and dates. Appendix C traces each intake answer to where it is used.

Real reports vary here. One may close with a section of other information provided by management, which the opinion does not cover. Treat anything after Section 4 as management’s voice unless the auditor’s report says otherwise.

How to read a SOC 2 report a vendor sent you

Six checks, in the order they save you time.

  1. Find the opinion paragraph in Section 1. Unmodified, qualified, adverse or disclaimed. If there is no signed opinion, you are not holding a report.
  2. Read the date or the period. A Type 1 is as of a date, a Type 2 covers a period. Then check how old a report can be before you ask for a bridge letter.
  3. Check which criteria are in scope. Security is always there. Availability or Confidentiality only if the report says so.
  4. List the carve-outs. Every carved out vendor is a report you still need.
  5. Copy out the CUECs. They are work your team now owns.
  6. Verify the firm. Confirm the CPA firm holds a license. How to tell if a SOC 2 report is real walks through the lookup.
Who signs a real one

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms. Through us, onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report like this sample is optional: $2,000 added later, or $4,000 in total with onboarding, with the examination by an independent partner auditor inside that figure. The sample shows what that work is organized into. It is not a substitute for it.

Want to see where your own company stands first? The free readiness assessment takes about 15 minutes and returns your readiness score, every gap category counted with exact numbers, and your first findings written out in full. It lives in your account. It is not a report, and nothing downloads.

Questions

Is this a real SOC 2 report?
No. It describes a company that does not exist, it is watermarked SAMPLE on every page, and it states on its first page that no CPA firm examined anything in it and no opinion has been issued. It shows the structure and depth of a report, and attests to nothing.
What are the sections of a SOC 2 report?
The service auditor's report with the opinion, management's assertion, the description of the system, and the criteria with the related controls. A Type 2 report adds the auditor's tests of those controls and the results. Some reports end with other information that management provides and the opinion does not cover.
What is the difference between a Type 1 and a Type 2 report?
A Type 1 report covers whether controls were suitably designed as of one date. A Type 2 report covers whether they operated effectively across a period, so it carries the auditor's tests and the results of each one, exceptions included.
Where is the AICPA example SOC 2 report?
The AICPA publishes an illustrative SOC 2 Type 2 report with an illustrative system description. It includes the assertion, the description, the auditor's report and the tests of controls with their results, and it is available to AICPA members.
Can I get my own SOC 2 report for free?
No. A SOC 2 report is issued by a licensed CPA firm after an examination, and that is paid work on every platform. The free readiness assessment returns a score and a gap list inside your account. It does not produce a report or a downloadable file.

Sources

  1. Illustrative SOC 2® Report with Illustrative System Description AICPA. An illustrative Type 2 report with the assertion, the description, the auditor’s report and the tests of controls; AICPA members only. Checked 2 October 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  3. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  4. 2018 SOC 2® Description Criteria (With Revised Implementation Guidance, 2022) AICPA. The benchmarks for preparing and evaluating the system description, DC 200. Checked 2 October 2026.
  5. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.