A SOC 2 report is one of the more useful documents in vendor evaluation. The badge on the website is one of the least useful.
The short answer
SOC 2 is an attestation, not a certification. An accounting firm examines the controls a service organization puts in scope and reports what it found. Three facts determine whether that report tells you anything:
- Type I or Type II — a snapshot of design, or observed operation over a period
- The observation period — Type II means nothing without a date range
- The scope — which trust services criteria, and which systems, the vendor chose to include
A logo conveys none of the three. Ask for the report.
Type I vs Type II
| Type I | Type II | |
|---|---|---|
| What it says | Controls were suitably designed at a point in time | Controls operated effectively across a period |
| Time covered | One date | Typically 3–12 months |
| What it rules out | Controls that were never designed | Controls that exist on paper but not in practice |
| What to ask | "When?" | "What period, and were there exceptions?" |
Type II is the meaningful one, because the failure mode SOC 2 is best at catching is documented but not practiced. A vendor who says "SOC 2" without qualifying it is very often describing Type I, or something in progress.
The scope problem nobody mentions
Here is the part vendors rarely volunteer: the vendor participates in defining what gets examined.
SOC 2 covers five trust services criteria — security, availability, processing integrity, confidentiality, and privacy — and only security is mandatory. A report covering security alone is legitimate and complete. It also says nothing about confidentiality or privacy, which for a healthcare buyer may be the entire question.
Similarly, scope covers named systems. A vendor might hold a clean report for its core platform while the newer AI features sit outside the boundary.
Two questions cut through this:
- Which trust services criteria are in scope?
- Does the scope include the specific product we are buying?
How to actually read the report
You do not need to be an auditor. Four sections carry most of the signal:
- The independent service auditor's report — the opinion itself. Look for whether it is unqualified.
- Scope and system description — what was examined. Compare it against what you are buying.
- Tests of controls and results — the substance. This is where exceptions appear.
- Complementary user entity controls — the most-skipped section. These are the things the report assumes you will do. If it says customers are responsible for access reviews and you never do them, part of the security model is not operating.
On exceptions: a report with zero exceptions across twelve months is not automatically better than one with two well-explained exceptions. Sometimes it means narrow scope. What matters is what happened, whether it touched data like yours, and what changed afterward.
The phrases that mean nothing
Three appear constantly, and none is an attestation:
- "SOC 2 ready" — no standard meaning; no third party stands behind it
- "SOC 2 compliant" — SOC 2 is not something one complies with; it is something one is examined against
- "SOC 2 aligned" — a statement about intentions
None of these is necessarily dishonest. Companies genuinely do implement controls before an audit, and saying so is fair. But the only verifiable question is whether a report exists — from which firm, covering what period, with what scope.
We are being pointed about this because we recently found the failure on our own site. More on that below.
SOC 2 is not HIPAA
They answer different questions and neither substitutes for the other:
| SOC 2 | HIPAA | |
|---|---|---|
| What it is | Voluntary attestation (AICPA) | Federal law |
| Who examines | An accounting firm the vendor engages | HHS Office for Civil Rights, through enforcement |
| Scope | Chosen with the vendor | Set by regulation |
| Applies to | Service organizations generally | Covered entities and business associates |
| What you need for PHI | Helpful evidence | A signed BAA |
A vendor handling PHI needs a BAA whether or not it holds a SOC 2 report. We covered that in Is AI HIPAA Compliant? — and unlike SOC 2, there is no such thing as HIPAA certification at all.
What to accept from a vendor without SOC 2
Audits cost real money and take real time, so early-stage vendors often have genuine controls before they have a report. That is a normal situation, not a red flag — the red flag is claiming the report exists.
Reasonable substitutes, in rough order of value:
- A documented security risk analysis — OCR repeatedly identifies deficient risk analysis as among the most common failings it finds
- A signed BAA where PHI is involved — enforceable obligations beat voluntary attestations
- A recent penetration test summary — an outside party tried to break in
- A named subprocessor list with change notice
- A written breach notification commitment with an hour count
- Evidence the audit is genuinely underway — engaged firm, target date
That last one is worth stating honestly rather than dressing up, which brings us to us.
Where we stand, and what we got wrong
As of 7 August 2026: our SOC 2 audit is in progress. No report has been issued. ISO 27001 certification is underway. Neither is complete.
We know this precisely because writing this post made us check — and we found our own site claiming otherwise. /security described SOC 2 Type II as "Available now," several product pages said "SOC 2 Certified," and a platform page claimed five frameworks were "certified and maintained." None of that was true of the audit's actual state. We corrected all of it.
That is an uncomfortable thing to publish. We are publishing it because the alternative — writing a post telling you to demand the report while our own badge overstated ours — would have been worse, and because it is a working example of the failure mode this page describes. The claim drifted ahead of the artifact. It happens quietly, usually without anyone deciding to mislead.
What we can put behind our claims today: a BAA for customers handling PHI, PHI that stays in your tenant, no customer data used to train models, and per-agent audit logging with skill version, citation, timestamp, and operator. Our security page states each framework's real status.
When the report is issued, we will say so — and you should ask for it.
Frequently Asked Questions
What is the difference between SOC 2 Type I and Type II?
Type I says controls were suitably designed at a single point in time. Type II says an auditor observed those controls operating across a period, typically three to twelve months. Type II is substantially stronger because a control that exists on paper and a control that functions every day are different things. When a vendor says SOC 2 without specifying, ask which one and ask for the observation period.
Does SOC 2 mean a vendor is secure?
It means an independent auditor examined the controls the vendor put in scope against selected trust services criteria and reported what they found. That is meaningful evidence, but scope is chosen with the vendor's participation, so a narrow scope can produce a clean report that covers little of what you care about. Read the scope section and the exceptions before treating the report as an answer.
What does "SOC 2 ready" mean?
It is not an attestation. It generally means a company believes it has implemented the controls a SOC 2 audit would examine, but no auditor has issued a report. The phrase has no standard definition and no third party stands behind it, so treat it as a statement of intent. The verifiable question is whether a report exists, from which firm, covering what period.
Is SOC 2 required for HIPAA compliance?
No. SOC 2 is a voluntary attestation developed by the AICPA, while HIPAA is federal law enforced by the HHS Office for Civil Rights. Neither substitutes for the other. A vendor handling PHI needs a business associate agreement regardless of whether it holds a SOC 2 report, and a SOC 2 report is not a finding about HIPAA compliance.
What should I ask a vendor about their SOC 2?
Ask four things: which type, which observation period, which trust services criteria were in scope, and whether there were exceptions. Then ask for the report itself under NDA rather than accepting a summary or a logo. A vendor with a genuine Type II report will hand it over as a routine part of procurement; hesitation at this step is itself information.
Are exceptions in a SOC 2 report a dealbreaker?
Usually not, and a report with zero exceptions across a long observation period is sometimes a sign of narrow scope rather than flawless operation. What matters is what the exception was, whether it touched data like yours, and what the vendor did about it. A vendor who explains an exception clearly is often a safer bet than one whose report has nothing in it to discuss.
Can a small vendor be trusted without SOC 2?
Yes, depending on what they can show you instead. Audits are expensive and early-stage companies frequently have real controls before they have a report. The substitutes worth accepting are concrete: a documented risk analysis, a signed BAA where PHI is involved, a penetration test summary, a named subprocessor list, and a clear breach notification commitment. What should not be accepted is a badge implying an attestation that does not exist.
What to do next
Ask every vendor on your list for the report — type, period, scope, exceptions. Ask us too; our answer today is that the audit is in progress, and that is the honest one.
Then read the complementary user entity controls section, because that is the part describing work that lands on you. Our guide to verifying vendor claims applies the same discipline to the performance numbers vendors publish.



