How to verify a SOC 2 report you were sent

The document arrives as a PDF and somebody has to decide whether it counts. Here is the read order, and the six checks a template cannot survive.

How to tell if a SOC 2 report is real: open Section 1 and Section 4, in that order. Section 1 should be a letter on a CPA firm’s letterhead naming the firm, the city it signed from, and a date, with a signature under it. Section 4 should read like the vendor’s own company: their ticket numbers, their cloud accounts, their job titles.

Then look the firm up in its state board license register, match the dates against what sales told you, and read the exceptions rather than counting them. Four checks get you to an answer in ten minutes, and none of them require an accountant. Two more below close the gap.

Deciding whether a vendor’s report counts is rarely an auditor’s job. It falls to whoever in security or procurement has the approval sitting in their queue and a vendor waiting on it, which is who this page is written for.

What the five sections are for

A SOC 2 report has a fixed shape. Five sections, in the same order every time. Knowing who wrote which part is most of the skill, because two of the five carry the CPA firm’s name and three of them are the vendor describing itself.

SectionWho wrote itWhat it tells you
Section 1The CPA firmThe opinion. Which firm, what they examined, what period or date it covers, and whether the opinion is clean
Section 2The vendorManagement’s assertion. The vendor stating, in writing and under its own name, that the description is accurate
Section 3The vendorThe system description: what is in scope, what is out, which subservice providers they rely on, and the controls as designed
Section 4The CPA firmEvery control, the test the auditor ran against it, and the result. The evidence, and the part worth your time
Section 5The vendorOther information, including management’s response to anything that deviated. Not covered by the opinion

Section 3 is where a vendor sounds most impressive and where they are quoting themselves. Section 4 is where an independent party wrote something down.

The checks a template cannot survive

  1. The opinion letter is on firm letterhead and signed. A named CPA firm, a city, a date, and a signature block. A report whose first section is unsigned, or signed by the vendor, is not an examination report.
  2. The firm exists in a state board register. Every U.S. CPA firm is licensed by a state board of accountancy, and those registers are public and searchable by firm name.1 Two minutes.
  3. Section 4 names things only this vendor would know. Their ticketing tool, their cloud provider, their access review owner, their alerting. Generic procedure text with no proper nouns in it is the strongest single signal that nobody tested anything.
  4. The date or period matches what you were told. A Type 1 covers one date. A Type 2 covers a period with a start and an end. Compare both against the claim that got the vendor into your queue.
  5. The scope covers the system you are buying. Section 3 names the system. If it names a different product, a different environment, or a parent company, the report is real and still does not answer your question.
  6. The exceptions read as findings, not as absences. Zero exceptions across forty controls is possible. It is also what a document with no testing behind it looks like.

Those six take about twenty minutes together, and five of them are reading. Only the license lookup needs a browser tab.

The opinion letter, and who signed it

Section 1 is a letter, not a certificate. It says which firm performed the examination, what they examined, against which criteria, and what they concluded. The conclusion is an attestation opinion, and only a licensed CPA firm can issue one.2

So the letterhead is doing real work. Look for the firm name, the city, the date, and a signature. Then search the state board of accountancy in that state for the firm license. If the register has no such firm, you are holding something other than a SOC 2 report, and it does not matter how good the design is. Who is allowed to perform a SOC 2 audit covers the licensing rule and what a consultant may and may not put their name to.

Read the opinion paragraph itself rather than the summary the vendor emailed you. An unqualified opinion is the clean one. A qualified opinion says everything held except one named thing, which is disclosed and is often survivable. An adverse opinion or a disclaimer is a different conversation.

A clean opinion and exceptions can coexist

The opinion answers whether the description and the controls hold overall. Section 4 records each instance that did not. A report can carry an unqualified opinion and several exceptions at the same time, and that combination is normal rather than contradictory.

Section 4 is where a fake gives itself away

Sections 1 through 3 are the easiest parts of a report to imitate. Boilerplate exists for all of them. Section 4 is different, because it has to describe work that either happened or did not.

A real test results section is specific and slightly boring. It names populations and sample sizes. It says what the auditor inspected. It refers to systems by their actual names, and the names change from vendor to vendor because the systems do.

What real testing reads like
Inspected the access review completed for the quarter ending March 31 and agreed the reviewer, the date, and the accounts removed. Selected 25 of 213 changes deployed during the period and inspected the approval recorded in the vendor’s pull request.
What a template reads like
The organization maintains appropriate access controls. Changes are reviewed and approved prior to deployment. No proper nouns, no counts, no dates, and nothing that would read differently if the company sold something else entirely.

One more tell. In a Type 2, tests are performed over a period, so the language should be about instances across that period rather than about a single moment. Wording that only ever describes a state, never a sample, usually means you are reading a Type 1 that has been described to you as a Type 2.

Dates and scope have to match what you were told

This is the check that catches honest reports being used dishonestly. The document is real. The pitch around it is not.

A Type 1 opinion covers design as of a single date. A Type 2 covers operation across a period, and that period has a start and an end printed in Section 1. If a salesperson told you they hold a Type 2 and the letter says as of, you were told something inaccurate. Type 1 versus Type 2 sets out the difference in one page, and the observation period explains why a short first window is legitimate rather than a shortcut.

Then check how old the period is. A report ages, and a period that closed a long time ago tells you about a company that no longer exists in the same shape. Ask for a bridge letter covering the gap between the period end and today. How long a SOC 2 report stays valid covers what a bridge letter can and cannot do.

Scope last. Section 3 names the system that was examined, and a large company can hold a genuine report for a product you are not buying. Confirm the product name, the environment, and which Trust Services Criteria were in scope. Security is the required one, and the others are chosen.3

The most common problem with a vendor SOC 2 is not that the report is fake. It is that the report is real and covers something else.

Read the exceptions, do not count them

An exception is one instance where a control did not operate the way the description says it operates. It attaches to a specific test, not to the company. Reports from serious engineering organizations carry them.

So the number is close to meaningless on its own. What matters is which control deviated, whether that control touches your data, how many instances out of how many tested, and what management wrote in Section 5. Two exceptions with a concrete fix and a date beside them tell you more about a vendor than a spotless report with no sample sizes in it. What happens when an audit finds exceptions goes through the four opinion types and how a finding gets cleared.

A separate worry usually surfaces here: the vendor paid very little for this report, so is it worth anything. Price is the wrong end of that question. Check the firm license, then read Section 4, and let the testing answer it. Whether a cheap SOC 2 audit is legitimate takes the objection apart, including how to run the state board lookup.

When the vendor will not send you the report

This happens constantly and it is rarely the problem it feels like. A SOC 2 report is a restricted use document.4 Section 1 typically closes with a paragraph naming who the report is intended for, and the engagement letter behind it restricts distribution further.

A vendor who will not attach the PDF to an email may be following that restriction rather than hiding anything. Ask under NDA. Most of the time the document appears.

  1. Ask for it under a mutual NDA. This is the normal path and it usually resolves the whole thing in a day.
  2. Accept a controlled viewer if that is what they offer. A watermarked portal copy you can read is worth more than a PDF you never receive.
  3. If the answer is still no, ask for the facts instead. The CPA firm name, the opinion type, the report type, the period covered, and the criteria in scope. A vendor holding a real report can answer all five in one email.
  4. Treat a refusal to name the firm as the actual signal. Distribution can be restricted. The identity of the firm that signed the opinion is not a secret, and hesitation there is worth more attention than the refusal to send the file.

What you should not accept is a badge on a website, a screenshot of a dashboard, or a compliance page with a logo on it. None of those are the report. The report is the document with the letter at the front.

If you are the vendor being asked

Everything above is what your buyer is doing to your report. It is also what your report has to withstand. Polara G.R.C. scopes Security only, and a Type 1 is $4,000 one time, including the first examination and the engagement fee for the independent partner auditor. What you send your buyer is the full report, opinion letter through tests of controls, not a badge.

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

How do you check that a SOC 2 report is genuine?
Start with the opinion letter at the front. It should sit on the letterhead of a named CPA firm, give the city the firm signed from, carry a date, and carry a signature. Then look up that firm in the license register published by its state board of accountancy. Then read Section 4 and see whether it names the vendor systems and tickets or only generic procedures.
Which section of a SOC 2 report should I read first?
Section 1 tells you who stood behind the work and what kind of opinion they gave. Section 4 tells you what was actually tested and what the results were. Sections 2, 3 and 5 are written by the vendor, so treat them as the vendor speaking rather than as audit evidence.
Can a SOC 2 report be faked?
A PDF can be made to look like anything. What is hard to fake is a CPA firm that appears in a state board license register, an opinion letter signed by that firm, and a test results section that names the systems the vendor actually runs. Any one of those checks will usually settle it.
What if the vendor will not send me the report?
That is common and it is usually a contract question rather than a warning sign. SOC 2 reports are restricted use documents, so the vendor may need a mutual non disclosure agreement in place first. Ask for the report under NDA. If they still refuse, ask instead for the opinion type, the period covered, the scope, and the name of the CPA firm.
Do exceptions in a SOC 2 report mean the vendor failed?
No. An exception records an instance where a control did not operate as described during the period tested. Real reports carry them. Read what the control was, whether it touches your data, and what management said about it in Section 5.

Sources

  1. State Boards of Accountancy directory NASBA. Where to confirm a CPA firm holds an active license in its state. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  3. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  4. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty