How to verify a SOC 2 report you were sent
The document arrives as a PDF and somebody has to decide whether it counts. Here is the read order, and the six checks a template cannot survive.
How to tell if a SOC 2 report is real: open Section 1 and Section 4, in that order. Section 1 should be a letter on a CPA firm’s letterhead naming the firm, the city it signed from, and a date, with a signature under it. Section 4 should read like the vendor’s own company: their ticket numbers, their cloud accounts, their job titles.
Then look the firm up in its state board license register, match the dates against what sales told you, and read the exceptions rather than counting them. Four checks get you to an answer in ten minutes, and none of them require an accountant. Two more below close the gap.
Deciding whether a vendor’s report counts is rarely an auditor’s job. It falls to whoever in security or procurement has the approval sitting in their queue and a vendor waiting on it, which is who this page is written for.
What the five sections are for
A SOC 2 report has a fixed shape. Five sections, in the same order every time. Knowing who wrote which part is most of the skill, because two of the five carry the CPA firm’s name and three of them are the vendor describing itself.
| Section | Who wrote it | What it tells you |
|---|---|---|
| Section 1 | The CPA firm | The opinion. Which firm, what they examined, what period or date it covers, and whether the opinion is clean |
| Section 2 | The vendor | Management’s assertion. The vendor stating, in writing and under its own name, that the description is accurate |
| Section 3 | The vendor | The system description: what is in scope, what is out, which subservice providers they rely on, and the controls as designed |
| Section 4 | The CPA firm | Every control, the test the auditor ran against it, and the result. The evidence, and the part worth your time |
| Section 5 | The vendor | Other information, including management’s response to anything that deviated. Not covered by the opinion |
Section 3 is where a vendor sounds most impressive and where they are quoting themselves. Section 4 is where an independent party wrote something down.
The checks a template cannot survive
- The opinion letter is on firm letterhead and signed. A named CPA firm, a city, a date, and a signature block. A report whose first section is unsigned, or signed by the vendor, is not an examination report.
- The firm exists in a state board register. Every U.S. CPA firm is licensed by a state board of accountancy, and those registers are public and searchable by firm name.1 Two minutes.
- Section 4 names things only this vendor would know. Their ticketing tool, their cloud provider, their access review owner, their alerting. Generic procedure text with no proper nouns in it is the strongest single signal that nobody tested anything.
- The date or period matches what you were told. A Type 1 covers one date. A Type 2 covers a period with a start and an end. Compare both against the claim that got the vendor into your queue.
- The scope covers the system you are buying. Section 3 names the system. If it names a different product, a different environment, or a parent company, the report is real and still does not answer your question.
- The exceptions read as findings, not as absences. Zero exceptions across forty controls is possible. It is also what a document with no testing behind it looks like.
Those six take about twenty minutes together, and five of them are reading. Only the license lookup needs a browser tab.
The opinion letter, and who signed it
Section 1 is a letter, not a certificate. It says which firm performed the examination, what they examined, against which criteria, and what they concluded. The conclusion is an attestation opinion, and only a licensed CPA firm can issue one.2
So the letterhead is doing real work. Look for the firm name, the city, the date, and a signature. Then search the state board of accountancy in that state for the firm license. If the register has no such firm, you are holding something other than a SOC 2 report, and it does not matter how good the design is. Who is allowed to perform a SOC 2 audit covers the licensing rule and what a consultant may and may not put their name to.
Read the opinion paragraph itself rather than the summary the vendor emailed you. An unqualified opinion is the clean one. A qualified opinion says everything held except one named thing, which is disclosed and is often survivable. An adverse opinion or a disclaimer is a different conversation.
The opinion answers whether the description and the controls hold overall. Section 4 records each instance that did not. A report can carry an unqualified opinion and several exceptions at the same time, and that combination is normal rather than contradictory.
Section 4 is where a fake gives itself away
Sections 1 through 3 are the easiest parts of a report to imitate. Boilerplate exists for all of them. Section 4 is different, because it has to describe work that either happened or did not.
A real test results section is specific and slightly boring. It names populations and sample sizes. It says what the auditor inspected. It refers to systems by their actual names, and the names change from vendor to vendor because the systems do.
- What real testing reads like
- Inspected the access review completed for the quarter ending March 31 and agreed the reviewer, the date, and the accounts removed. Selected 25 of 213 changes deployed during the period and inspected the approval recorded in the vendor’s pull request.
- What a template reads like
- The organization maintains appropriate access controls. Changes are reviewed and approved prior to deployment. No proper nouns, no counts, no dates, and nothing that would read differently if the company sold something else entirely.
One more tell. In a Type 2, tests are performed over a period, so the language should be about instances across that period rather than about a single moment. Wording that only ever describes a state, never a sample, usually means you are reading a Type 1 that has been described to you as a Type 2.
Dates and scope have to match what you were told
This is the check that catches honest reports being used dishonestly. The document is real. The pitch around it is not.
A Type 1 opinion covers design as of a single date. A Type 2 covers operation across a period, and that period has a start and an end printed in Section 1. If a salesperson told you they hold a Type 2 and the letter says as of, you were told something inaccurate. Type 1 versus Type 2 sets out the difference in one page, and the observation period explains why a short first window is legitimate rather than a shortcut.
Then check how old the period is. A report ages, and a period that closed a long time ago tells you about a company that no longer exists in the same shape. Ask for a bridge letter covering the gap between the period end and today. How long a SOC 2 report stays valid covers what a bridge letter can and cannot do.
Scope last. Section 3 names the system that was examined, and a large company can hold a genuine report for a product you are not buying. Confirm the product name, the environment, and which Trust Services Criteria were in scope. Security is the required one, and the others are chosen.3
Read the exceptions, do not count them
An exception is one instance where a control did not operate the way the description says it operates. It attaches to a specific test, not to the company. Reports from serious engineering organizations carry them.
So the number is close to meaningless on its own. What matters is which control deviated, whether that control touches your data, how many instances out of how many tested, and what management wrote in Section 5. Two exceptions with a concrete fix and a date beside them tell you more about a vendor than a spotless report with no sample sizes in it. What happens when an audit finds exceptions goes through the four opinion types and how a finding gets cleared.
A separate worry usually surfaces here: the vendor paid very little for this report, so is it worth anything. Price is the wrong end of that question. Check the firm license, then read Section 4, and let the testing answer it. Whether a cheap SOC 2 audit is legitimate takes the objection apart, including how to run the state board lookup.
When the vendor will not send you the report
This happens constantly and it is rarely the problem it feels like. A SOC 2 report is a restricted use document.4 Section 1 typically closes with a paragraph naming who the report is intended for, and the engagement letter behind it restricts distribution further.
A vendor who will not attach the PDF to an email may be following that restriction rather than hiding anything. Ask under NDA. Most of the time the document appears.
- Ask for it under a mutual NDA. This is the normal path and it usually resolves the whole thing in a day.
- Accept a controlled viewer if that is what they offer. A watermarked portal copy you can read is worth more than a PDF you never receive.
- If the answer is still no, ask for the facts instead. The CPA firm name, the opinion type, the report type, the period covered, and the criteria in scope. A vendor holding a real report can answer all five in one email.
- Treat a refusal to name the firm as the actual signal. Distribution can be restricted. The identity of the firm that signed the opinion is not a secret, and hesitation there is worth more attention than the refusal to send the file.
What you should not accept is a badge on a website, a screenshot of a dashboard, or a compliance page with a logo on it. None of those are the report. The report is the document with the letter at the front.
Everything above is what your buyer is doing to your report. It is also what your report has to withstand. Polara G.R.C. scopes Security only, and a Type 1 is $4,000 one time, including the first examination and the engagement fee for the independent partner auditor. What you send your buyer is the full report, opinion letter through tests of controls, not a badge.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How do you check that a SOC 2 report is genuine?
Which section of a SOC 2 report should I read first?
Can a SOC 2 report be faked?
What if the vendor will not send me the report?
Do exceptions in a SOC 2 report mean the vendor failed?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.