Skip to content

Glossary

SOC 2

An independent audit report describing how a vendor handles security and availability, produced by an outside firm and commonly requested before a tool is approved.

In plain terms

An outside firm examined how a vendor runs its security and wrote a report about it. The report is not a pass mark and not a certificate; it is a description of what the vendor said it does, what the auditor tested, and what the auditor found. That makes it far more informative than a badge and considerably more effort to use.

01

Why it matters

Because it is usually the most substantial evidence a buyer can get about a vendor's practices, and because it is routinely treated as a box rather than a document. A team that collects the report and files it has obtained a fact about whether one exists. A team that reads the scope and the exceptions has obtained something about how the vendor actually operates, which is what the exercise was for.

02

How it works

There are two types and the difference is decisive. One describes how things were arranged at a single point in time; the other describes whether the arrangements actually operated over a period of months. The second is the substantive one, because a control that exists on paper and a control that ran reliably all year are different claims, and only one of them has been tested.

The report defines its own scope, and the scope is where a report can be technically accurate and practically unhelpful. It covers named systems and services, and a vendor with several products may hold a report covering some of them. Checking that the scope includes the thing you are buying is a two-minute step that is skipped more often than any other.

The exceptions section is the part worth reading and the part nobody reads. It records what the auditor found that did not work as described, and a report with a few honestly recorded exceptions and clear responses is generally more reassuring than one with none. What matters is whether the vendor noticed, explained and addressed them.

It is periodic rather than continuous, so it describes a window that has already closed. A report always covers the past, sometimes a while in the past, and nothing in it speaks to what happened since. Asking when the current one ends and what the vendor's cadence is tells you more about the future than re-reading the last one does.

It is not a certification and there is no register to look up. An audit firm produces a report for the vendor, who chooses whom to share it with, usually under a confidentiality agreement. That is why the artefact arrives through a sales conversation rather than being published, and why a claim on a web page is not the same as the document.

Two ways to use the same report

Two ways to use the same reportIt is worth being fair about why the left column happens: the report is long, written for auditors, and arrives at the end of a process when everybody wants to be finished. The reviewer's task is also frequently defined as obtaining the document rather than assessing it, so filing it genuinely completes the assigned work. The argument for the right column is not diligence for its own sake but that three specific questions do nearly all the work and none of them requires reading the document end to end. Type, scope, exceptions. A reviewer who asks only those has spent twenty minutes and knows whether the evidence covers the product being bought, which is the failure mode that matters, because a report that does not include your service is the one case where filing it produces a confident and entirely unfounded conclusion.FiledDo they have one? Yes.Attach to the review.Time spent: two minutes.ReadWhich type, and over whatperiod?Does the scope include what weare buying?What did they find, and whatdid the vendor do?The left use is what mostorganisations make of the mostdetailed evidence they will everreceive about a vendor. Theright use takes perhaps twentyminutes and is the only one thatcould change a decision.
It is worth being fair about why the left column happens: the report is long, written for auditors, and arrives at the end of a process when everybody wants to be finished. The reviewer's task is also frequently defined as obtaining the document rather than assessing it, so filing it genuinely completes the assigned work. The argument for the right column is not diligence for its own sake but that three specific questions do nearly all the work and none of them requires reading the document end to end. Type, scope, exceptions. A reviewer who asks only those has spent twenty minutes and knows whether the evidence covers the product being bought, which is the failure mode that matters, because a report that does not include your service is the one case where filing it produces a confident and entirely unfounded conclusion.
03

Seen in the wild

  • Asking for the report covering an assistant's administered tier before a team's use of it becomes something people depend on.

    ChatGPT
  • Checking that a search tool's report covers the connectors reaching into internal systems, not only the core product.

    Glean
  • Reading what an automation platform's report says about access to the credentials it stores for other services.

    Make
04

Common misconceptions

People assume

Having one means the vendor is secure.

In fact

It means an outside firm examined described practices within a defined scope over a defined window, and wrote down what it found. That is genuinely valuable and it is a description rather than a verdict, which is why the scope and the exceptions carry the information and the existence of the report carries very little.

People assume

A report with no exceptions is the best outcome.

In fact

Not necessarily. A few honestly recorded exceptions with clear responses often indicate an auditor who looked and a vendor who engaged. What matters is whether anything found was understood and addressed, which is a judgement a reader makes rather than a score the document carries.

People assume

It covers the whole company.

In fact

It covers what its scope says it covers, which may be some products and not others, or a core service without the integrations around it. A vendor can hold a genuine report that does not include the specific thing you are about to buy, and nothing is wrong with either party when that happens.

05

Telling them apart

SOC 2 vs ISO 27001

SOC 2

A report describing what was examined and found. Read it.

ISO 27001

A certification that a management system meets a standard. Verify it.

One produces a document with detail in it; the other produces a status. Buyers often accept either.

06

Questions

What should we actually look at?
Three things: which type it is, what the scope covers, and what the exceptions section records. Those carry nearly all the information in the document, and the existence of a report carries almost none. The scope check in particular takes two minutes and is the one most often skipped.
What is the difference between the two types?
One describes how arrangements stood at a point in time; the other describes whether they operated over a period. The second tested something the first did not, which is why it is the substantive one and why it is worth asking which you have been handed.
Why can we not just look it up?
Because it is a report to the vendor rather than an entry on a register, and it is usually shared under confidentiality. That is why it arrives through a sales conversation, and why a compliance claim on a web page is a different thing from the document itself.
How current does it need to be?
Every report covers a window that has closed, so what matters is when the current one ends and whether the vendor produces them on a regular cadence. Asking those two questions tells you more about what happens next than a careful reading of an old report does.
07

Key takeaways

  • It is a description of what was examined and found, not a pass mark.
  • The type tells you whether controls were tested over time or only described.
  • Check that the scope covers the product you are actually buying.
  • The exceptions section carries the information; a clean report is not automatically better.
  • It always describes a window that has already closed.
09

Tools that use this

  • ChatGPT

    The report covering an administered tier people are starting to depend on.

  • Glean

    Whether the scope covers the connectors into internal systems.

  • Make

    What it says about access to credentials stored for other services.

Last checked July 2026

All glossary terms