How to verify a SOC 2 report comes down to eight checks: the opinion type and its exact wording, whether the report covers a period or a single date, the signing firm's CPA license and peer review status, the sample sizes in Section 4, whether test descriptions vary between controls, whether the complementary user entity controls section says anything specific, how subservice organizations are handled, and whether the system description in Section 3 matches the product you are buying. All eight can be done in about twenty minutes.
Most people receiving a SOC 2 report do none of them. They confirm the file exists, note the logo, and move the vendor to approved. For years that was a defensible shortcut. In 2026 it is not, because the industry now has a documented example of what happens when nobody checks.
Why you now need to know how to verify a SOC 2 report
In March 2026, an anonymous account publishing as DeepDelver alleged that the compliance automation startup Delve had produced fraudulent SOC 2 and ISO 27001 reports for hundreds of customers. The allegations, first reported in detail on Substack and subsequently covered by Inc. and multiple compliance and legal publications, described auditor conclusions written before client evidence was submitted, near-identical language repeated across hundreds of reports, and sign-offs by firms other than the US CPA firms customers believed had performed the work. Y Combinator removed the company from its portfolio in early April 2026. Delve disputed aspects of the allegations, and reported figures vary between outlets.
The specifics matter less than the structural lesson. Every organization holding one of those reports had a document that looked correct. The document was the control, and the document was not tested. That is the failure mode a verification procedure exists to catch, and it applies to any report from any provider, not just one company.
The checks below are the ones a service auditor applies when reading another firm's report. None of them require accounting expertise.
How do you read a SOC 2 report? The five sections
Before you can judge whether a SOC 2 report is legitimate, you need to know what a complete one contains. A SOC 2 report has a standard structure. Knowing it tells you immediately whether you are holding a real report or a summary.
- Section 1: Independent service auditor's report. The opinion. Signed by the CPA firm on firm letterhead, with a city and a date.
- Section 2: Management's assertion. The service organization's own statement about its system and controls, signed by management.
- Section 3: Description of the system. Prepared by management in accordance with DC section 200. This is where the system boundary, the services, the subservice organizations, and the complementary user entity controls live.
- Section 4: Description of tests of controls and results. The auditor's tests and what they found. This section exists only in a Type 2 report.
- Section 5: Other information provided by management. Optional, and explicitly outside the scope of the opinion.
If what you received is a one-page certificate, a badge, a trust page screenshot, or a PDF with no Section 4, you do not have a SOC 2 Type 2 report. Ask for the full report under NDA. A vendor that will not provide it is telling you something.
One point of terminology that separates people who read these reports from people who forward them: SOC 2 is an attestation report, not a certification. There is no such thing as being SOC 2 certified. A vendor whose sales team uses that phrasing is not disqualified, but it tells you how deeply they understand what they bought.
Check 1: Read the opinion type, and its exact wording
Turn to Section 1 and find the opinion paragraph. There are four possible opinions and the difference is not cosmetic.
| Opinion | What it means | How to treat it |
|---|---|---|
| Unqualified | The auditor concluded controls were suitably designed and, for a Type 2, operated effectively throughout the period. | The clean result. Proceed to check 2. |
| Qualified | The auditor identified one or more matters where the description, design, or operating effectiveness fell short, and the opinion is modified "except for" those matters. | Read the exception. A qualification over one late access removal is not the same as a qualification over system monitoring. |
| Adverse | The auditor concluded controls were not suitably designed or did not operate effectively. | Serious. Requires explanation and remediation evidence before reliance. |
| Disclaimer | The auditor could not obtain sufficient evidence to form an opinion. | No assurance was provided. Treat as if no report exists. |
Read the words rather than looking for a label. A qualified opinion contains the phrase "except for" and then names the matter. Search the PDF for "except for" and for "exception" and read every hit. Vendors routinely forward qualified reports with a cover note describing them as clean, not always dishonestly, because whoever sent it did not know what a qualification looks like.
Also confirm the opinion names the correct criteria. A SOC 2 opinion should reference the trust services criteria in TSP section 100 and the description criteria in DC section 200. An opinion that references neither is not a SOC 2 opinion.
Check 2: Confirm the period, not just the date
Find the period in Section 1. It reads either "as of [single date]" or "throughout the period [date] to [date]."
"As of" is a Type 1. It reports on the suitability of design at a point in time. It contains no test of whether anything operated. A Type 1 is a legitimate report and a reasonable step for a young company, but it does not tell you that controls worked, and it should never be accepted where your requirement is a Type 2.
"Throughout the period" is a Type 2. Now check three things about that period:
- Length. Three months is the short end. Six to twelve is normal. A three-month window on a renewal, after prior twelve-month windows, is worth asking about.
- Distance from today. A report whose period ended fourteen months ago tells you about a system that no longer exists. Ask when the next report is due.
- Coverage of your own fiscal year. If your assessment cycle runs January to December and their period ran October to September, three months of your year are uncovered. That gap is what a bridge letter addresses, and a bridge letter is issued by the vendor's management, not by the auditor. It carries no independent assurance. Treat it as a management representation, which is what it is.
Check 3: Verify the SOC 2 auditor's CPA license
This is the check almost nobody performs and the one that would have caught the most in 2026.
A SOC 2 examination must be performed by an independent CPA firm. That is a licensing requirement, not a best practice. So:
- Find the firm name, city, and state on the Section 1 signature block. A signature with no city, or with a location that does not match the firm's stated jurisdiction, is a flag on its own.
- Look the firm up in the state board of accountancy register for the state named. Every US state board maintains a public license lookup. Confirm the firm holds a current license in good standing under the exact name that signed the report. NASBA's CPAverify service covers many states in one search.
- Check the AICPA Peer Review public file. Firms performing attestation engagements are subject to peer review, and results are publicly searchable through the AICPA Peer Review public file search. Absence from the file, or a peer review report with a rating other than pass, is material information about the report you are holding.
- Check the firm's own website for the engagement type. A firm that performs SOC examinations says so. A firm whose practice is tax preparation and bookkeeping, signing a SOC 2 opinion for a software company on the other side of the world, warrants a question.
If the report was arranged through a compliance automation platform, ask directly which CPA firm performed the examination and confirm that firm independently. The platform is not the auditor. It cannot be, because the platform that helps you build and monitor controls cannot then independently attest to them without impairing independence.
Check 4: Read the sample sizes in Section 4
Section 4 is a table. For each control it states the test performed and the result. Somewhere in each test description you will find a sample size, usually phrased as a count of items examined out of a population. This is the single most informative page in the report, because sample sizes reveal whether testing happened.
What normal looks like. Sample sizes scale with how often the control operates. An annual control has a population of one, so it is tested once. A quarterly control is usually tested with two or three items. A monthly control with two to five. A weekly control with five to eight. A daily or event-driven control with a large population is commonly tested with twenty to forty items. Firms differ, because the AICPA does not mandate sample sizes for SOC examinations, but the pattern of scaling with frequency is universal.
What is wrong. A sample size of one for a control that operates daily across a twelve-month period. The same sample size, say five, applied to every control in the report regardless of frequency. No sample size stated at all. A population figure that does not change between two consecutive annual reports for a company that grew from forty to two hundred people.
What is missingLook for whether population completeness is addressed. Strong reports describe how the auditor established that the population was complete, for example by reconciling the termination list to HR records. This is the hardest part of a real SOC 2 audit and its presence is a positive signal.
Check 5: Look for repeated language, the clearest fake SOC 2 report signal
Read ten consecutive test descriptions in Section 4. Then read ten more from a different criterion.
In a report produced by testing, the descriptions differ, because the procedures differ. Inspecting a change management ticket is not the same activity as reobserving a firewall configuration or reperforming an access review. The language reflects that.
In a report produced from a template, descriptions repeat with only the control name swapped, and often the same phrasing appears for controls that could not possibly be tested the same way.
The allegations at the center of the 2026 case included identical auditor conclusion language repeated across hundreds of reports, down to a shared grammatical error.
You can test this in seconds. Copy three test descriptions into a document and compare them side by side. If you have two SOC 2 reports from different vendors that used the same provider, compare across reports. Identical narrative language for two different companies with different architectures is not a coincidence.
Also read the exceptions, if any. A report with zero exceptions across a twelve-month period and a hundred-plus controls is possible, but it is uncommon in a growing company. Exceptions with a management response describing remediation are a sign of a real audit, not a weakness.
Check 6: Read the complementary user entity controls section
Section 3 should contain a subsection on complementary user entity controls. CUECs are the controls the vendor assumed you would operate, and that are necessary in combination with theirs for the system to meet its commitments.
This matters to you directly, because anything listed as a CUEC is your responsibility and is explicitly outside the scope of the auditor's opinion. Section 1 will say so.
Read the list and ask two questions:
- Is it specific? "User entities are responsible for security" is not a CUEC, it is filler. "User entities are responsible for configuring multi-factor authentication for their administrative accounts and for removing access for terminated personnel within one business day" is a CUEC.
- Are you actually doing these things? This is where the report creates work for you rather than closing a checkbox. A vendor's clean SOC 2 does not cover the control it assumed you were running and you were not.
A missing or one-line CUEC section suggests the description was not prepared against DC section 200 with any care, which raises questions about the rest of Section 3.
Check 7: Check how subservice organizations are handled
Almost every SaaS vendor runs on infrastructure someone else operates. DC section 200 requires the description to address this, using one of two methods.
Carve-out method. The subservice organization's controls are described but excluded from the scope of the vendor's report. The description then lists complementary subservice organization controls, which are the controls the vendor assumes its provider operates. Carve-out is the normal choice and there is nothing wrong with it.
Inclusive method. The subservice organization's relevant controls are brought inside the report and tested. Rare, because it requires the provider's cooperation.
What you are checking: are the subservice organizations actually named, or does the description gesture at "cloud providers"? If carve-out, does the report say so explicitly, and does the auditor's opinion note that the examination did not include those controls? Have you separately obtained assurance over the carved-out providers? For a hyperscaler this is usually straightforward. For a smaller data processor handling your customer data, it may not be, and the vendor's report gives you nothing on it.
The carve-out is where a lot of risk quietly sits. A vendor can hold a clean report while the component that actually stores your data was never in scope.
Check 8: Confirm Section 3 describes the product you are buying
The final check is the one that catches scope games. Read the description of services and the system boundary in Section 3. Then compare it to what you are purchasing.
Look for the product name: is the specific product in scope, or a different platform the same company sells? The environment: does the boundary cover the region and infrastructure your data will sit in? The trust services categories in scope: Security is the only mandatory category. Availability, Processing Integrity, Confidentiality, and Privacy are optional. If your requirement is uptime, a Security-only report does not address Availability. If you are sending regulated personal data, a report without Confidentiality or Privacy in scope may not address what you need. Section 1 names the categories in scope, and this is one of the most common mismatches between what a buyer needs and what a report covers. And significant changes during the period: DC section 200 requires disclosure of significant changes in a Type 2. A migration, a major re-architecture, or an acquisition mid-period changes what the testing means.
The SOC 2 report review checklist: red flags at a glance
| Check | Pass condition | Flag |
|---|---|---|
| 1. Opinion | Unqualified, or qualified with an exception you have read and accepted | Adverse, disclaimer, or "except for" you did not know about |
| 2. Period | Type 2 covering a period ending within the last 12 months, aligned to your cycle | "As of" a single date when you needed a Type 2, or a stale or short period |
| 3. Auditor | CPA firm license confirmed with the state board, peer review on file | Firm not in the register, no city on the signature, platform named as auditor |
| 4. Sample sizes | Scale with control frequency, populations stated | Sample of 1 on frequent controls, uniform samples, no sizes given |
| 5. Language | Test descriptions vary by control | Identical narrative repeated, or matching another vendor's report |
| 6. CUECs | Specific, and you are meeting them | Absent, or generic filler |
| 7. Subservice orgs | Named, method stated, separately assured | Unnamed, or carved out with no coverage |
| 8. Scope | Product, environment, and categories match your purchase | Different product, wrong region, missing category you rely on |
What if you are the vendor being verified?
Everything above is now being applied to your report by the more sophisticated buyers in your pipeline, and increasingly by TPRM platforms doing it at scale.
Run the eight checks on your own most recent report before your next enterprise deal. Specifically: look at your Section 4 sample sizes and ask whether a sample of one appears anywhere it should not. Read your CUEC section and ask whether it says anything a customer could act on. Confirm your signing firm's license and peer review status are what you believe them to be. Check whether the description in Section 3 still matches the product you sell.
If any of those checks fails, the fix is not a better trust page. It is re-verification: an independent review of whether the evidence behind the report would survive scrutiny, and remediation of what would not, before a buyer finds it first. A report that fails a buyer's check costs you the deal the report was bought to unlock. That is what re-verification and audit rescue is built for.
Verification tools referenced above: CPAverify for state CPA licensing, the AICPA Peer Review public file, and IAF CertSearch if you are checking an ISO 27001 certificate rather than a SOC 2 report.
Frequently asked questions
Is there a public database where I can verify a SOC 2 report?
No. There is no central registry of SOC 2 reports, because SOC 2 produces a confidential attestation report rather than a public certificate. This is the structural reason verification falls to the recipient. What you can verify publicly is the auditor: state boards of accountancy publish license lookups, NASBA's CPAverify covers many states, and the AICPA Peer Review program maintains a public file of peer review results.
How do I check whether a SOC 2 auditor is a real CPA firm?
Take the exact firm name and location from the Section 1 signature block and search the license register of the state board of accountancy for that state. Confirm the firm license is current and in good standing. Then search the AICPA Peer Review public file for the firm's most recent peer review result. If the report came through a compliance automation platform, ask which CPA firm performed the examination and verify that firm, not the platform.
Can a compliance automation platform issue a SOC 2 report?
No. A SOC 2 examination must be performed by an independent CPA firm. A platform can help an organization implement controls and collect evidence, and it can introduce you to auditors, but it cannot issue the opinion, and a firm cannot independently attest to controls it helped design and monitor without impairing its independence.
What is the difference between a SOC 2 report and a SOC 3 report?
A SOC 2 report is confidential, distributed under NDA, and contains the system description and detailed test results. A SOC 3 report is a general-use summary that can be posted publicly. A SOC 3 contains no Section 4 and therefore cannot be verified in the way described here. If a vendor offers only a SOC 3, they hold the underlying report and you should ask for it.
What does a qualified SOC 2 opinion actually mean for us as a buyer?
It means the auditor found something material enough to modify the opinion. Read the "except for" language and the related exception in Section 4. A qualification arising from two late access revocations in a twelve-month period, with documented remediation, is a different risk from a qualification over the absence of system monitoring. Ask for the management response and evidence that the issue was fixed, then decide.
Is a bridge letter acceptable to cover a gap between reports?
It is common practice and often acceptable for short gaps, typically up to three months, but understand what it is. A bridge letter is written and signed by the vendor's management, not by the auditor, and it asserts that no material changes have occurred since the report period ended. It carries no independent assurance. Treat it as a management representation and weight it accordingly.
How many exceptions in Section 4 should worry me?
There is no threshold, and zero is not automatically the best answer. What matters is the nature of the exception, whether it affects a control you rely on, whether a root cause is identified, and whether remediation is evidenced. A report with a handful of documented, remediated exceptions is often stronger evidence of a real audit than a report with none.
We received a "SOC 2 certificate" from a vendor. Is that valid?
SOC 2 does not produce a certificate. There are badges and trust pages that reference a report, and those are marketing artifacts, not assurance. Ask for the full Type 2 report under NDA, including Sections 1 through 4. If none exists, the vendor does not have what they are claiming to have.
Related reading: is SOC 2 a report or a certificate, what CPA firms and certification bodies now require, and what an independent re-verification gives you.