Security

What SOC 2 actually certifies (and what it does not)

A SOC 2 badge is meaningful, but not in the way most buyers assume. Here is how to read a report and what to ask a vendor who waves one at you.

JL
Jordan Lee
Co-founder & CTO · · 4 min read

We are SOC 2 Type II certified, and we put the badge on our security page like everyone else. It is a genuinely useful signal. It is also widely misread, including by people whose job is vendor assessment.

It is an audit of your own claims

This is the part that surprises people. SOC 2 does not measure you against a fixed external standard the way a speed limit works. You define your control objectives, and an independent auditor tests whether you actually do what you said.

A company with modest controls, honestly described and consistently followed, passes. A company with ambitious controls it does not follow, fails. That makes SOC 2 a strong test of operational discipline and a weak test of whether the controls were ambitious enough.

Type I versus Type II

Type I says the controls were designed appropriately as of a single date. It is a photograph. A company can tidy up for a week, get a Type I, and revert.

Type II says the controls operated effectively over a period — typically three to twelve months. It is a film. Always ask which one, and always ask for the observation period. A Type II covering three months is meaningfully weaker than one covering a year.

The five trust services criteria

SOC 2 covers up to five criteria, and only Security is mandatory:

  • Security — protection against unauthorised access. Always included.
  • Availability — the system is available as committed. Relevant if you depend on uptime.
  • Processing Integrity — processing is complete, valid, accurate, and timely.
  • Confidentiality — information designated confidential is protected.
  • Privacy — personal information is handled per the entity’s privacy notice.

A vendor can be "SOC 2 Type II certified" having covered Security alone. If you are storing personal data with them, check whether Confidentiality and Privacy were in scope. Frequently they were not.

Read the scope section carefully

The report defines which systems were examined. A company with a main product and three acquired side products may have scoped only the main one. If you are buying the side product, the report may not cover anything you actually use.

Check the subservice organisations too. Most SOC 2 reports carve out cloud infrastructure providers, which is reasonable — but it means the report says nothing about those providers, and you should look at their reports separately.

Exceptions are normal

A report with zero exceptions across a twelve-month period is not necessarily a better report; it sometimes indicates narrow scope or light testing. What matters is the nature of exceptions and the management response.

An exception noting that two access reviews were completed four days late is operational noise. An exception noting that terminated employees retained production access for weeks is a finding about culture. Same document, entirely different signals.

What SOC 2 does not cover at all

Worth being explicit, because buyers routinely assume otherwise. SOC 2 says nothing about whether a vendor is financially stable, whether their product works, whether their code is well written, or whether they will exist in three years.

It also is not a privacy regulation. A SOC 2 report is not evidence of GDPR compliance, and the Privacy trust criterion assesses adherence to the vendor's own privacy notice — not whether that notice satisfies any particular law. Those need separate diligence.

Bridge letters and gaps

A report covers a defined window. If the window ended four months ago, there is a period with no coverage. A bridge letter — sometimes called a gap letter — is management's assertion that nothing material changed since the observation period ended.

It is an assertion, not an audit. Useful for a few months of gap; not a substitute for a current report if the gap has stretched past a year. If a vendor cannot produce either a recent report or a bridge letter, that is worth asking about directly.

How this fits with ISO 27001

The two are often presented as alternatives. They test different things. ISO 27001 certifies that an information security management system exists and conforms to the standard — it is about the framework. SOC 2 attests that specific controls operated effectively — it is about the outcomes.

Neither subsumes the other, and having both is common at larger vendors. If you must choose which to weight, SOC 2 Type II tells you more about what actually happened day to day; ISO 27001 tells you more about whether there is a durable system behind it.

Questions worth asking

  1. 1Type I or Type II, and what observation period?
  2. 2Which trust services criteria were in scope?
  3. 3Which systems and products were in scope — specifically?
  4. 4Were there exceptions, and what was the remediation?
  5. 5Which subservice organisations were carved out?
  6. 6When does the current report expire, and is there a bridge letter?

Our own report covers Security, Availability, and Confidentiality across the full SignTheDoc platform, with a twelve-month observation period. It is available under NDA, and we would rather you read it than trust the badge.

JL
Jordan Lee
Co-founder & CTO

Jordan leads engineering at SignTheDoc. Before this he built payment infrastructure, which is where he learned to care about audit trails.

Keep reading

Ready to sign your first doc?

Get started free — your first three documents are on us.

Start signing free →