SOC Report Reality Check

Answer a few plain-English questions about a vendor's SOC report and get a color-coded risk read — for SOC 1, SOC 2, or SOC 3.

Your answers stay in your browser
No signup required
No tracking or data collection

How this tool works: Your responses are processed entirely in your browser — nothing you enter is stored, transmitted, or used to identify you. No cookies, no personal data, no tracking. Results are generated on-device only. Privacy Policy

Who this tool is for

This tool is for anyone who has been handed a vendor's SOC report and is expected to conclude something from it: business owners doing due diligence on a payroll, hosting, or software provider, procurement and contracts staff processing a vendor onboarding, compliance managers who need to document third-party review for SOC 2, HIPAA, or CMMC, IT leaders evaluating a managed service provider, and in-house counsel checking what a report does and does not cover before signing. It is equally useful at a family foundation with three critical vendors and at a company reviewing fifty — the report structure is the same, and so are the traps.

What it measures — and what “in scope” means

The tool walks through the parts of a SOC report that determine whether it means anything for your decision: which type of report you received (SOC 1 for financial controls, SOC 2 for security and related criteria, SOC 3 as a general-use summary), whether it is a Type I point-in-time design review or a Type II test of operating effectiveness over a period, whether the scope covers the service and locations you actually buy, what the auditor's opinion says and whether it is qualified, what exceptions were noted and in which controls, how recent the period is, and which complementary user entity controls the vendor has quietly left to you. The result is color-coded by risk with a plain-language explanation of each flag and a list of what to fix or what to ask the vendor. "In scope" means the report's stated system boundary — if your service is not inside it, the report does not cover you.

What your result is not

The result is a structured reading aid, not an audit of the vendor and not a substitute for reading the report yourself. It cannot see the report — it depends on your answers about it — and it cannot tell you whether the vendor is safe to use, only whether the report supports that conclusion. A green result means the report is the right type, recent, in scope, and clean; it does not mean the vendor has no risk. A SOC 3 will always cap at yellow because a general-use summary cannot carry a vendor-risk decision on its own.

Frequently asked questions

QWhat is the difference between a SOC 2 Type I and Type II report?

A Type I describes the design of controls at a single point in time. A Type II tests whether those controls operated effectively over a period, usually six to twelve months. For vendor due diligence, Type II is the meaningful one.

QIs SOC 2 a certification?

No. SOC 2 is an attestation report issued by a CPA firm. There is no certificate and no pass or fail — there is an auditor's opinion, a system description, and a list of tested controls with any exceptions.

QWhat are complementary user entity controls (CUECs)?

Controls the vendor's auditor assumed you, the customer, would implement — for example, managing your own user accounts or enabling MFA. If you do not implement them, the vendor's clean opinion does not protect you.

QWhat does a qualified opinion mean?

The auditor found that one or more controls were not designed or operating effectively enough to support a clean opinion. Read the basis for qualification carefully; it usually points at the exact risk you care about.

QCan I rely on a SOC 3 report?

Only as a starting point. A SOC 3 omits the control detail and test results. Ask the vendor for the full SOC 2 Type II under NDA.

QHow do I review a SOC 2 report quickly?

Check the type, the period, the scope, the opinion, the exceptions, and the CUECs — in that order. The related article walks through each in about twenty minutes.

Related reading

How to Review a Vendor SOC 2 Report: The 20-Minute Checklist Most Owners SkipHow Much Does SOC 2 Cost in 2026? The Full Cost Stack — and Where Companies OverspendWhat CMMC 2.0 Actually Means for Small Contractors

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.

Need a Deeper Analysis?

This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.

Schedule a Scope Call