Skip to main content
Category: SOC Reporting

Report on Controls

Also known as: Service Auditor's Report, SOC Report
Simply put

A Report on Controls is a document produced by an independent CPA firm that describes an organization's controls and the auditor's findings about them. In the SOC 2 context, it is the deliverable that results from an attestation examination, not a certificate. It tells readers what controls were examined and whether they were suitably designed, and in some cases whether they operated effectively over a defined time period.

Formal definition

A Report on Controls is the deliverable of an attestation engagement performed by a licensed CPA firm under the AICPA SSAE 18 standard, in which a service auditor reports on a service organization's system and the controls relevant to the applicable Trust Services Criteria. A SOC 2 Type I report addresses the suitability of the design of controls at a specified point in time, while a SOC 2 Type II report addresses both design suitability and operating effectiveness over a defined review period whose length is set by scoping decisions rather than fixed by the standard. The report attests only to the controls and the period or point in time covered and does not constitute a certification, nor does it guarantee the absence of security breaches; its assurance is bounded by the defined scope, the selected criteria (Security is required as the Common Criteria, with Availability, Processing Integrity, Confidentiality, and Privacy optional), and the professional judgment of the service auditor. This should be distinguished from an ISO/IEC 27001 certificate, which is issued by an accredited certification body against a management system standard rather than produced as an attestation report, and from related SOC 1 and SOC 3 report types, which serve different purposes and audiences.

Why it matters

For most service organizations, a Report on Controls is the primary evidence they can hand to customers and prospects to demonstrate the state of their control environment. Rather than asking each customer to conduct its own audit, a service organization can commission a single attestation examination by a licensed CPA firm and share the resulting report under appropriate confidentiality arrangements. This makes the report a central artifact in vendor due diligence and third-party risk management, particularly for SaaS providers and other organizations that process data on behalf of their customers.

Understanding what the report is, and what it is not, matters because its assurance is bounded. A SOC 2 report attests only to the controls described and the point in time or review period covered; it does not guarantee that no security breach will occur, nor does it function as a certification. Readers who treat the report as a blanket seal of security misread its scope. A Type I report speaks only to whether controls were suitably designed at a specified date, while a Type II report additionally addresses whether those controls operated effectively over a defined period, so the type and the period covered materially change what a reader can conclude.

Because the report reflects the selected Trust Services Criteria and the professional judgment of the service auditor, two reports are rarely directly comparable without examining their scope. A report that covers only the required Security (Common Criteria) category conveys different assurance than one that also addresses Availability, Processing Integrity, Confidentiality, or Privacy. Reading the scope, the period, and the auditor's opinion carefully is essential to using the report responsibly in a compliance or procurement decision.

Who it's relevant to

Compliance and GRC managers
They commission the engagement, coordinate the description of the system and controls, and rely on the resulting report as a repeatable way to answer customer security questions. They need to understand that the report attests only to the controls and period covered and is not a certification.
Auditors and CPA firms
Licensed service auditors perform the examination under SSAE 18 and issue the opinion. Their professional judgment, the selected Trust Services Criteria, and the defined scope shape what the report can conclude, whether it is a Type I addressing design at a point in time or a Type II addressing design and operating effectiveness over a period.
Procurement and vendor risk teams
They consume the report as part of third-party due diligence. To use it responsibly, they must read the scope, the criteria included, the report type, and the period covered, and recognize that the report does not guarantee the absence of breaches.
Security engineers and control owners
They implement and operate the controls described in the report and provide evidence to the service auditor. For a Type II examination in particular, they are responsible for the consistent operation of controls across the defined review period.

Inside Report on Controls

Independent Service Auditor's Report
The CPA firm's opinion section, which states whether, in the auditor's judgment, the controls were suitably designed (Type I) and, for a Type II, operated effectively throughout the review period. This is an attestation performed under the AICPA SSAE 18 standard, not a certification.
Management's Assertion
A written statement from the service organization's management asserting that the description of the system is presented fairly and that the controls were suitably designed and, for a Type II, operating effectively over the defined period.
Description of the System
Management's narrative describing the system, services, infrastructure, and control environment in scope. It defines the boundaries of what the report covers.
Applicable Trust Services Criteria
The criteria against which controls are evaluated. Security (the Common Criteria) is the only required category; Availability, Processing Integrity, Confidentiality, and Privacy are optional and included depending on the scope selected.
Controls, Tests, and Results
In a Type II report, this section maps the controls to the applicable criteria, describes the tests the auditor performed, and reports the results, including any exceptions noted. A Type I typically documents the controls and their design without operating-effectiveness testing over a period.
Review Period or Point in Time
A Type I addresses suitability of design at a specific point in time, while a Type II addresses design and operating effectiveness over a defined review period. The period length varies and is set by scoping decisions rather than being fixed.

Common questions

Answers to the questions practitioners most commonly ask about Report on Controls.

Is a SOC 2 the same as a certification?
No. A SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, and it results in a report rather than a certificate. This distinguishes it from ISO/IEC 27001, which is a certification issued by an accredited certification body. Referring to a SOC 2 outcome as a 'certification' is a common but inaccurate description.
Does a SOC 2 report guarantee that an organization will not experience a breach?
No. A SOC 2 report attests only to the controls and the period covered by the examination. In the case of a Type II report, it addresses the suitability of design and operating effectiveness of controls over a defined review period. It does not guarantee freedom from breaches and does not speak to controls or events outside the defined scope and period.
How do we decide between a Type I and a Type II report?
A Type I report assesses the suitability of the design of controls at a point in time, while a Type II report assesses both the design and the operating effectiveness of controls over a defined review period. Organizations often begin with a Type I to establish a baseline and then move to a Type II, though the choice depends on scope, stakeholder expectations, and readiness. The review period length varies and is set through scoping decisions rather than being fixed.
Which Trust Services Criteria should be included in the scope of a report?
Security, also known as the Common Criteria, is the only required category. Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on the nature of the services and stakeholder needs. In most engagements the scoping decision is made collaboratively with the CPA firm, and adding categories typically expands the controls tested and the evidence required.
Can a SOC 2 report be used to satisfy ISO 27001 requirements?
Not directly. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other. The two frameworks differ in structure and outcome: SOC 2 is an attestation over Trust Services Criteria, while ISO 27001 certifies a management system against its clause 4 through 10 requirements with Annex A reference controls selected via a Statement of Applicability. Some organizations pursue both and reuse overlapping evidence where appropriate.
What should recipients look for when reading a report to understand its coverage?
Recipients should identify the report type (Type I or Type II), the specific Trust Services Criteria in scope, the period or point in time covered, the services and systems described, and any noted exceptions or qualifications. Because the report attests only to the controls and period covered, understanding these boundaries is essential before relying on it for vendor risk or procurement decisions.

Common misconceptions

A SOC 2 report is a certification that proves the organization is secure.
A SOC 2 is an attestation examination performed by a licensed CPA firm under SSAE 18, resulting in a report rather than a certificate. It attests only to the controls and the period covered and does not guarantee freedom from breaches. This differs from ISO/IEC 27001, which is a certification issued by an accredited certification body.
Any SOC 2 report demonstrates that controls worked over time.
Only a Type II report assesses operating effectiveness over a defined review period. A Type I addresses only the suitability of design at a point in time and does not test operation over a period.
A clean SOC 2 report means the organization also satisfies ISO 27001 or other SOC reports.
The report attests only to the controls and period covered within its defined scope. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one does not automatically satisfy the other. SOC 2 also differs from SOC 1 and SOC 3, which serve different purposes and audiences.

Best practices

Confirm whether the report is a Type I or Type II before relying on it, since only a Type II addresses operating effectiveness over a review period.
Read the Description of the System and applicable Trust Services Criteria to understand exactly what is in scope, remembering that only Security is required and other categories are optional depending on scope.
Check the review period and note that it varies by scoping decisions; assess whether it aligns with the timeframe relevant to your risk assessment.
Review the tests, results, and any noted exceptions in the controls section rather than relying solely on the auditor's overall opinion.
Do not treat a SOC 2 report as equivalent to an ISO 27001 certificate or as a guarantee of security; treat any cross-framework mapping as partial and validate gaps independently.
Verify that the report was issued by a licensed CPA firm under SSAE 18 and includes management's assertion, and distinguish it from SOC 1 or SOC 3 reports that may serve different purposes.