HomeBlog › How to Read a SOC 2 Report: Sections, Opinions and Exceptions Explained

How to read a SOC 2 report: sections, opinions and exceptions explained

Published 2026-08-19 · 7 min read · BALTUM

Whether you are evaluating a vendor's SOC 2 report or preparing your own, the document is easier to judge once you know its five sections and the handful of places where problems hide. This guide explains the structure, the kinds of opinion, and what an "exception" really means.

The five sections of a SOC 2 report

  1. Independent service auditor's report (the opinion): 2–4 pages signed by the CPA firm. This is the only part that carries the auditor's assurance.
  2. Management's assertion: your company states that the system description is accurate and the controls were suitably designed (Type 1) and operated effectively (Type 2).
  3. System description (Section III): services, infrastructure, people, data, processes, subservice organisations, and complementary user entity controls. Written by you, reviewed by the auditor.
  4. Trust Services Criteria, controls and tests (Section IV): a table of each criterion, your control, the auditor's test and the result.
  5. Other information (Section V, optional): management's responses to exceptions, future plans; not covered by the opinion.

Types of opinion

  • Unqualified (clean): controls were suitably designed and, for Type 2, operated effectively. Exceptions may still be listed, but none was serious enough to change the conclusion.
  • Qualified: one or more criteria were not met; the opinion says "except for". Customers will ask what was excluded and why.
  • Adverse: pervasive failures. Rare, because most companies withdraw before reaching this point.
  • Disclaimer: the auditor could not obtain enough evidence to form an opinion.

Exceptions are normal; patterns are not

An exception is a test result where the control did not operate as described: an access review was two weeks late, one leaver kept access for five days. A clean report can contain several. What a careful reader looks for is patterns: the same control failing repeatedly, exceptions around privileged access, or management responses that deny rather than fix. Section V is where a good company turns an exception into a credibility point by showing the root cause and the fix.

Where weak reports give themselves away

  • A very short observation period (three months) with no follow-on report the next year.
  • A system description that could be any SaaS company, with no named products or architecture.
  • Only the Security criterion for a service that promises uptime or handles confidential data, with no explanation.
  • Extensive carve-outs: if every important function is outsourced and excluded, little is actually assured.
  • A CPA firm nobody can find in a state licence register or with no public peer review.
  • An opinion date far in the past with no bridge letter.

Complementary user entity controls (CUECs)

Every report lists things the customer must do for the controls to work: manage their own users, configure MFA, review their own logs. When you read a vendor's report, check the CUECs against what your team actually does. When you write your own, keep the list realistic; auditors and customers both dislike CUEC lists that shift every responsibility to the customer.

Reading a report in fifteen minutes

  1. Opinion: clean or qualified? Type 1 or Type 2? Period covered? CPA firm name.
  2. Scope: which criteria, which services, which locations.
  3. Subservice organisations: carve-out or inclusive, and are the big ones (cloud, payroll) named.
  4. Section IV: count exceptions, look for patterns, read management responses.
  5. CUECs: can you live with them.
  6. Date: is a bridge letter needed.

How BALTUM helps

We help you write a system description that describes your company rather than a template, scope the criteria your customers actually need, and prepare the evidence so that Section IV reads cleanly. The report itself is issued by an independent, licensed US CPA firm engaged directly by you. If you would like a second pair of eyes on a vendor's report or on your own draft, get in touch.