Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 27th August 2026 at 8:22 am #3437
A vendor may present a SOC 2 report as complete security approval. What should a buyer verify?
27th August 2026 at 9:09 am #3438Accepted answerTreat the report as scoped evidence, not a universal certification. Check the report type and period, the systems and services included, the trust service criteria, the auditor’s opinion, exceptions, complementary user controls, subservice organizations, and whether the buyer’s planned use is covered. Ask for current bridge evidence when the period is old. NIST SP 800-161 Rev. 1 supports risk-based assessment of supplier and service evidence.
27th August 2026 at 11:30 am #3517Community replyWould you accept a report that excludes one major subservice organization from the scope of the audit?
- AuthorPosts
- You must be logged in to reply to this topic.