SOC 2 Report Example 

Table of Contents

Updated:

March 11, 2026

SOC 2 Report Example

Most teams lose 12 weeks every year to compliance tasks, often because their reports lack the “real-world” evidence auditors now require. In 2025, your SOC 2 report must be more than a checkbox; it must be a narrative of verified trust.

Using the example below, we illustrate how to document penetration testing and human-led validation to satisfy modern audit requirements and protect your firm from the rising costs of data breaches.

Download SOC 2 Report Example

What Is a SOC 2 Report?

A SOC 2 report is a formal review written by an independent CPA. It explains whether a company has the right security and operational controls in place to protect customer data and run its systems reliably. The CPA looks at how those controls are set up and, in some cases, how well they work in real day-to-day operations.

SOC 2 Report Example

There are two types of SOC 2 reports:

SOC 2 Report Structure

Although the exact layout varies slightly between auditors, most SOC 2 reports follow a standard structure with five sections. The summary below reflects common guidance:

SOC 2 Report Structure

1. Independent Auditor’s Report

This section presents the independent auditor’s opinion and explains whether the company’s controls satisfied the selected SOC 2 criteria. The opinion can confirm the controls met requirements, note exceptions, identify significant deficiencies, or state that evidence was insufficient to form a conclusion. It also describes the audit scope and general approach.

2. Management’s Assertion

This section provides a formal statement from management confirming the system description is fairly presented and that controls were designed appropriately. In a Type 2 report, management also asserts the controls operated effectively throughout the audit period. It typically summarizes the services in scope, the systems involved, and any criteria not fully satisfied.

3. System Description

This section explains what was audited and how the organization operates. It describes the services provided, key commitments such as availability or uptime, and primary system components, including infrastructure, software, people, processes, and data. It may also cover significant incidents, material changes during the audit period, relevant third-party services, and customer-operated controls.

4. Controls, Criteria, and Test Results

This section documents control performance and links each control to the applicable Trust Services Criteria. It lists the controls, explains the criteria each supports, and describes the auditor’s testing procedures. In a Type 1 report, it generally lists the controls without operating effectiveness results. In a Type 2 report, it includes test details, results, and exceptions, which makes this section central for assessing risk.

5. Information or Appendices

This optional section adds management context and supporting detail. It may describe remediation plans, future improvements, risk management or business continuity activities, and additional information about vendors and third-party dependencies.

SOC 2 Report Example

As a fintech business, ABC Company depends on protecting customer data and maintaining reliable systems. Its SOC 2 report documents how the company’s controls align to the AICPA Trust Services Criteria, which cover areas such as security, availability, processing integrity, confidentiality, and privacy.

SOC 2 reports often exceed 100 pages. Instead of walking through every exhibit, the overview below focuses on the sections readers use most and the details that tend to drive vendor and customer decisions.

Section I: Independent Auditor’s Report

This is typically the most referenced section. The auditor summarizes the engagement, identifies the period under examination, and provides a high-level description of the system in scope.

Below is an excerpt taken from an example SOC 2 system description:

Scope and Boundaries of the System

A SOC 2 system description snippet usually gives readers a clear snapshot of ABC Company’s environment, such as core infrastructure, key applications, data flows, and relevant service providers. After the system description, the auditor outlines:

The auditor’s opinion is the headline result. In this example, the report states that ABC Company’s controls operated effectively throughout the examination period. That language indicates the auditor issued a clean opinion for the in-scope criteria and period.

Even with a positive opinion, the report can still surface items worth attention elsewhere, such as minor exceptions, complementary user entity controls, or recommended improvements that do not rise to the level of a qualification.

Section II: Management’s Assertion

Section II of a SOC 2 report is Management’s Assertion, which is a signed statement where company leadership takes responsibility for the system included in the report and states that the system description and related controls meet the applicable Trust Services Criteria for the stated time period.

This section is usually short, but it serves as the company’s formal accountability statement and sets the boundaries for what the auditor reviews. Management confirms that the SOC 2 examination focuses on controls tied to one or more trust services categories, such as security, availability, processing integrity, confidentiality, and privacy.

A typical management assertion includes the following elements.

In practice, reviewers treat Management’s Assertion as the company’s signed confirmation that the scope, time period, and criteria are correct, then compare that claim to the system description and audit test results, since issues often appear as missing scope details, unclear boundaries, or controls that do not fully support the selected criteria.

Section III: System Description

Section III of a SOC 2 report is the System Description, which is a management written explanation of the services in scope, the system boundaries, and how information moves through the environment during the review period.

This section is usually the longest part of the report and gives readers practical detail about how the organization operates. It often includes background on the company, the services it provides, key processes, and visual diagrams. The System Description helps report users understand how data is handled and how controls and procedures address risks related to the company’s stated commitments and requirements.

The AICPA allows organizations to present this section in different formats as long as the required disclosures are included and follow DC Section 200.

A System Description commonly covers the following areas.

Section IV: Trust Services Criteria, Related Controls, Tests of Controls, and Results

Section IV of a SOC 2 report is the main testing section where the auditor lists the controls in scope, explains how each control was tested against the applicable Trust Services Criteria, and records the results for the examination period.

Trust Services Category, Criteria, Related Controls, Tests of Controls and Results

This section is where readers find evidence, not high level summaries, because it ties each criterion to specific controls and shows whether those controls worked as intended during the period. Many SOC 2 reports present Section IV as tables, sometimes called a testing matrix, that show the controls tested, what the auditor did to test them, when the testing occurred, and what the auditor found.

Section IV commonly includes the following elements.

When reviewing Section IV, reviewers usually start with controls that show exceptions or failures, then trace each issue back to the related criteria and control objective to understand the impact, since an overall clean opinion can still include isolated exceptions that matter for a specific customer situation.

Section V: Other Information Provided by the Service Organization

Section V of a SOC 2 report is an optional, unaudited section where management shares additional information that sits outside the auditor’s formal opinion and testing.

This section gives helpful context but does not serve as audit evidence because the auditor does not test or opine on its content. Auditors still read it to check for major inconsistencies with the audited sections, but responsibility for the information rests entirely with management.

Management’s Responses to Exceptions Noted

Section V commonly includes the following types of information.