Review assurance

SOC 2 report review checklist

Sources reviewed October 2, 2026 · By Software Compliance Directory

Review a supplier’s SOC 2 report against the service you use: scope, period, auditor opinion, exceptions, customer responsibilities, and follow-up decisions.

Match the report to your service

Record the supplier’s legal entity, product, hosting arrangement, and data access in your relationship. Compare these with the report’s system description and boundary. A report for a related service or parent company may require additional investigation.

Check type, criteria, and period

Identify whether the report is Type 1 or Type 2, the date or period covered, and the selected Trust Services Criteria. Compare them with your review requirement. Record any gap between the report period and the period you need to understand.

A management bridge letter may describe later changes. It does not extend the auditor’s examination. Read it alongside the report and decide whether further evidence is needed.

Read the opinion and relevant test results

Read the auditor’s opinion before looking for a badge or summary. For a Type 2 report, review relevant tests, exceptions, management responses, and their relationship to your dependency. An exception’s significance depends on the service, control, circumstances, and compensating measures.

Send unclear findings to the responsible reviewer or supplier. Record the question and response instead of treating an unfamiliar term as an automatic pass or failure.

Assign customer and dependency responsibilities

Identify applicable complementary user entity controls and assign them to your own team. Check how subservice organizations are handled: controls included in the examination and controls carved out need different review work.

Record the decision and follow-up

Write a service-specific conclusion with the reviewer, source report, open questions, required safeguards, decision approver, and next review trigger. Keep unresolved issues visible. Restrict report access and sharing according to the report’s terms and your supplier agreement.

Use the evidence planner to record follow-up requests. This checklist supports review; it does not issue an assurance opinion.

Explore directory profiles

Examples from the directory to review against your scope. These are starting points, not a quality ranking.

Related resources