Skip to main contentChat with us

Learn · SOC Reports

Does a SOC 2 Report Replace
Security Questionnaires?

No — and understanding exactly why saves a great deal of friction. A SOC 2 report answers one question: did an independent CPA firm test these controls against these criteria over this period, and what did it find. A questionnaire asks a far wider set, most of which the report was never scoped to address.

The goal is compression, not elimination. A well-mapped report turns most of a questionnaire into a reference and a page number. The remainder — residency, sub-processors, contract terms, product configuration, anything current rather than historical — still has to be answered.

0TSC criteria addressing data residency
4question types in a typical questionnaire
250+SOC 2 engagements supported by TCSA

Plain-English explainer · AT-C 205 examination · TSC 2017 (rev. 2022) · DC 200 description criteria · Last reviewed August 2026

A SOC 2 report does not replace a security questionnaire, because the two answer different questions. The report states what an independent CPA firm tested against the AICPA Trust Services Criteria over one closed period, and what it found. A questionnaire asks that, then keeps going — into today’s facts, into what the buyer configures in their own tenant, into contract terms, and into the buyer’s own regulatory obligations. Neither instrument is defective. A SOC 2 is an examination under AT-C section 205, with the concepts common to all attestation engagements in AT-C section 105. Its subject matter is management’s description of the system and the suitability of design — and, in a Type 2, the operating effectiveness — of the controls in it, measured against stated criteria; management provides a written assertion about that subject matter, which is what makes the engagement assertion-based. The content of Section 3 is governed too: the AICPA description criteria (DC 200) set what a service organisation must disclose about its system boundary, its subservice organisations and the method used for them, its complementary user entity controls, and identified incidents that meet the disclosure threshold. A questionnaire is a procurement instrument, and its subject matter is whatever the buyer’s risk, legal and regulatory obligations require on the record before signature. The overlap is large, and the remainder is where the arguments happen.

Sort before you answer

The four kinds of question in every questionnaire

Fast teams triage the whole document before writing a single response. Every question falls into one of four buckets, and only the first is one a SOC 2 report answers.

Type A — tested control questions

Is access reviewed? Are changes approved before deployment? Is the incident-response plan exercised? A Type 2 examines exactly these, and answers them better than any self-declaration: someone independent tested them and printed the result.

Type B — current-state facts

When was the last penetration test, by whom, over what scope? Who are your sub-processors today? The report is historical, about a closed period; these questions are about the week the buyer is asking in.

Type C — product and configuration questions

Is SSO available on our plan? Can we enforce IP allow-listing, or export audit logs? These describe what the buyer switches on, and many are the mirror image of a complementary user entity control.

Type D — contractual and jurisdictional questions

Where is data processed? What is the notification window in our agreement? Will you sign a DPA, a BAA, standard contractual clauses? No attestation over controls opines on any of it.

The instruments you will actually receive

Four documents account for nearly all inbound volume. None is a subset of the Trust Services Criteria, and the last one is the one that consumes the time.

InstrumentPublisherApproximate sizeWho sends itWhat a Type 2 realistically covers
CAIQ v4.1Cloud Security AllianceDerived from Cloud Controls Matrix v4.1, released 27 January 2026 — 207 control specifications across seventeen domains. The earlier v4.0.x pairing, 261 questions against 197 controls, stays accepted for STAR submissions through CSA’s published transition window.Cloud and SaaS buyers, and any reviewer who checks the STAR registry before writing to you.Most of the control-design and control-operation questions map onto the common criteria. Residency, plan-tier and contract questions fall outside a SOC 2 entirely.
SIG Lite and SIG CoreShared AssessmentsTwo tiers drawn from one licensed question bank that is re-issued annually: Lite for screening a vendor, Core for a full assessment.Financial services, insurance and other regulated buyers, and third-party risk teams that license the bank.The control domains map well. The resilience tiers assume Availability was in scope, and the privacy tiers assume Privacy was — check your categories before answering either.
HECVAT Full and HECVAT LiteEDUCAUSEFull for a complete review, Lite for lower-risk purchases, plus an accessibility section the other instruments omit.Universities, colleges, research institutes and their consortium purchasing groups.The security sections map. Accessibility, student-data handling and consortium contract terms are answered from product documentation and Legal.
The buyer’s own formThe buyer’s third-party risk teamUnbounded — thirty questions or five hundred, in the buyer’s own spreadsheet, with wording nobody else uses.Enterprises with a mature TPRM function. This is the majority of real inbound volume.Whatever overlaps by accident. The answer library earns its keep here, because nothing maps in advance and every question has to be routed by hand.

One lever reduces inbound volume at source. Publishing a completed CAIQ to the CSA STAR registry as a Level 1 self-assessment lets a reviewer check the registry and stop there, which pre-empts a share of bespoke forms before they are ever drafted. STAR Level 2 pairs the same self-assessment with third-party work — either a certification against ISO/IEC 27001 extended to the Cloud Controls Matrix, or a STAR Attestation, which is a SOC 2 engagement extended to cover the CCM. A Level 1 entry carries no independent testing behind it, and a reviewer who knows the difference will treat it as a starting point.

The mapping

Questionnaire theme to report section

Where the answer genuinely lives, and where the report is silent. References are to the 2017 Trust Services Criteria with points of focus revised in 2022; optional-category criteria apply only where that category was in scope. Section 3 references follow the AICPA description criteria, DC 200.

Questionnaire themeWhere the report answers itWhere it genuinely does not
Identity and access managementSection 4, criteria CC6.1–CC6.3 — provisioning, periodic review, termination, with procedures and results.Whether SSO, SCIM or enforced MFA exists on the buyer’s plan tier, and who administers roles in their tenant. A product answer, usually a CUEC.
EncryptionCC6.1 (logical access architecture) and CC6.7 (restricting transmission, movement and removal of information, and protecting it in transit).Cipher suites, key custody, BYOK or HYOK, and whether keys sit in a stated jurisdiction. The criteria are outcome-worded and name no algorithm.
Vulnerability management and pen testingCC7.1 — detection and monitoring to identify configuration changes introducing new vulnerabilities, and susceptibilities to newly discovered ones.The date, firm, scope and summary letter of the last penetration test, and any remediation SLA. A penetration test is an input the service auditor may inspect; the examination produces an opinion, and the test report remains a separate document from a separate firm.
Logging, monitoring and alertingCC7.2 (monitoring components for anomalies indicative of malicious acts, errors and disasters) and CC7.3 (evaluating security events against objectives).How long logs are retained for the buyer, and whether they can be streamed or exported. Retention promised to a customer is a commercial term.
Incident response and breach notificationCC7.4 and CC7.5 — responding under a defined programme, and recovering. Under description criteria DC 200, the Section 3 description must disclose relevant details of identified security incidents that resulted from controls that were not suitably designed or operating effectively, or that caused a significant failure in achieving service commitments and system requirements. That is a disclosure threshold; routine incidents the controls handled as designed sit below it.The contractual notification window, and who tells which regulator. Where Privacy is in scope, P6.6 covers notification as the entity’s own commitment; the window promised to this buyer lives in the agreement.
Change management and SDLCCC8.1 — authorising, configuring, documenting, testing, approving and implementing changes to infrastructure, data, software and procedures.Where engineering sits, whether contractors hold production access from a named country, and which SAST or DAST tooling is used.
Sub-processors and fourth-party riskCC9.2 (vendor and business-partner risk), plus the Section 3 disclosure DC 200 requires of subservice organisations and of whether the carve-out or the inclusive method was used for each.The named sub-processor list with processing locations, the notice period before one is added, and the right to object — contract terms under GDPR Article 28(2) and 28(3)(d).
Business continuity and disaster recoveryA1.2 (backup processes and recovery infrastructure) and A1.3 (testing recovery-plan procedures), only where Availability is in scope. CC9.1 covers disruption risk in every report.Your RTO and RPO commitment, SLA credits, and the last failover result. Where Availability is out of scope the report is silent on the theme.
Data retention and deletionC1.1 and C1.2 (identifying, maintaining and disposing of confidential information) where Confidentiality is in scope; P4.2 and P4.3 where Privacy is; CC6.5 for retired assets.Retention periods for the buyer’s data, deletion timelines on termination, and certificates of destruction — set per customer, in the DPA.
Data residency and cross-border transferNothing directly. A description may name hosting regions when listing infrastructure components, though the Trust Services Criteria contain no residency criterion.The whole theme. DORA Article 30 puts processing locations in the contract; EU transfers need SCCs and a transfer assessment.
GDPR, HIPAA and PCI DSS obligationsPrivacy criteria P1–P8, only where that category was in scope — and even then they measure the entity against its own stated commitments, not against a statute.An Article 28 processing agreement; a business associate agreement under 45 CFR 164.308(b) and 164.314(a); an Attestation of Compliance for PCI DSS requirement 12.8.4. A “HIPAA mapping” in Section 5 is other information, outside the opinion.
AI use and model training on customer dataNo criterion. The 2017 criteria predate the question, and the 2022 revision of the points of focus left it untouched.All of it. Answer from contract terms, or — for an examined answer — from an ISO/IEC 42001 management system alongside the SOC 2.

Two patterns fall out. The report is strongest exactly where a questionnaire is weakest — on whether a control actually operated, under independent testing — and silent wherever the answer is a promise rather than a practice. Residency, retention, notification windows and sub-processor notice are promises; promises live in contracts.

Why they cannot just accept it

The buyer’s regulator writes the questions

A long questionnaire arriving after a clean report reads as empire-building. Usually the reviewer is discharging an obligation written in a rule that does not mention SOC 2 — the view from the other side of the table is set out in what a buyer should require of a vendor.

GDPR Article 28 — the audit right that survives your report

A controller must hold a written processing agreement covering sub-processor authorisation under Article 28(2) and 28(3)(d), and the Article 28(3)(h) obligation to make available the information needed to demonstrate compliance and to allow for and contribute to audits. EDPB Guidelines 07/2020 treat third-party certifications and audit reports as one means of verifying a processor’s guarantees, which leaves the contractual audit provision standing where the controller has specific concerns.

DORA Article 30 — locations and subcontracting, in the contract

For EU financial entities, Regulation (EU) 2022/2554 requires the parties’ rights and obligations to be set out in writing: a description of all functions and ICT services, whether subcontracting of a service supporting a critical or important function is permitted and on what conditions, and the locations where services are provided and data is processed. Firms also keep a register of information on those arrangements for their competent authority.

US banking supervision and NYDFS

The June 2023 Interagency Guidance on Third-Party Relationships: Risk Management — issued jointly by the Federal Reserve, FDIC and OCC, published at 88 FR 37920 — replaced each agency’s earlier guidance and sets expectations across planning, due diligence, contracting, monitoring and termination. New York’s 23 NYCRR 500.11 separately requires written third-party policies covering risk assessment of providers, the minimum practices required of them, and the due diligence used to evaluate them.

Scheme rules that name a different artefact

PCI DSS v4.0.1 requirement 12.8.4 expects a programme to monitor service providers’ PCI DSS compliance status at least once every twelve months, and the artefact it contemplates is an Attestation of Compliance. HIPAA requires a business associate agreement with satisfactory assurances under 45 CFR 164.308(b) and 164.314(a). Where a scheme names an artefact, that artefact closes the question.

A worked example — illustrative, not a client engagement

284 questions, sorted

The figures below are constructed for illustration. A payments-adjacent SaaS vendor holds a Type 2 covering Security, Availability and Confidentiality for 1 April 2025 to 31 March 2026, reported 15 May 2026. In June 2026 an EU bank in scope for DORA sends 284 questions, due in ten working days.

171

Answered by reference to Section 4

Access management, change control, monitoring, incident response, encryption in transit, vendor management, backup and recovery. Each response gives the criterion, the control identifier, the tested result and the page — verifiable in the report the bank already holds.

42

Answered from the contract and the DPA

Notification window, deletion on termination, sub-processor notice and objection right, liability, insurance limits, exit assistance. Legal owns these; compliance never drafts them from scratch.

38

Product and configuration answers

SSO and SCIM on the bank’s tier, IP allow-listing, session timeout, audit-log export, role granularity. Product owns them, each answered with a documentation link.

19

Redirected to the CUEC section

Who administers users in the tenant, who reviews the bank’s own access, who sets retention, who monitors the bank’s administrators. The answer is a numbered citation plus the configuration guide.

14

Genuinely new work

Processing locations per service under DORA Article 30, whether customer data trains models, the current named sub-processor list, and the exit plan. Nothing in the report touches them.

What the answers looked like

Three shapes cover most of the document. Each carries its own limits with it, so a reviewer reading the answer can see what was tested, what was promised and what is simply current as at the date given. Bracketed values are yours to fill.

A tested control

“Yes. User access is reviewed quarterly by the system owner. This control was examined in our SOC 2 Type 2 for 1 April 2025 to 31 March 2026 (criterion CC6.3, control ID [x], Section 4 page [n]); the service auditor selected two of the four quarterly reviews and reported no exceptions.”

A contractual commitment

“Our security-incident notification commitment is [x] hours from confirmation, at clause [n] of the data processing agreement in your agreement dated [date]. That is a contractual commitment; the SOC 2 tests our incident-response controls under CC7.4, and the notification window itself is set in the contract.”

A current-state fact

“Our most recent penetration test was completed in March 2026 by an independent testing firm, covering [scope]. A summary letter is available under NDA. Penetration tests are evidence the service auditor may inspect during the examination; the SOC 2 report itself does not produce or publish one.”

One question, end to end

The bank’s question 212 read: “List every location, by country, at which the service is provided and at which customer data is processed or stored, including by subcontractors supporting a critical or important function.” It comes straight from DORA Article 30, and it lands in the fourteen. The Trust Services Criteria contain no residency criterion, so Section 4 offers nothing; the description in Section 3 names hosting regions when it lists infrastructure components, which is descriptive text carrying no test result behind it. The answer was assembled from the sub-processor register and the DPA annex, cross-checked against the cloud provider’s region configuration, and owned by the DPO with an engineering confirmation attached.

The time split is the part worth internalising. The 171 mapped answers took roughly half a day, because the library already held the criterion, control identifier and page for each. The 42 contractual answers took a further day of Legal review against the executed agreement. The fourteen new questions consumed the remaining eight working days: two needed Legal sign-off on wording that would be incorporated into the contract by reference, and one needed an engineering confirmation that took three days to schedule. The report did not replace the questionnaire. It cut 284 open questions to fourteen needing original thought, and turned 171 assertions into verifiable references — a better story than “we have a SOC 2, so we do not complete questionnaires.”

The legitimate redirect

CUECs send questions back to the buyer

Section 3 lists complementary user entity controls — controls the service organisation assumes its customers operate, without which the applicable criteria cannot be met end to end. They state where the control boundary sits. The CPA firm evaluated the described system assuming they exist on the customer’s side — and did not test them. CUECs are assumed to be implemented by user entities; the examination covers neither their design nor their operation, which is why the buyer still owns that control. Asked “do you enforce MFA for all users of the platform?”, the honest answer for most multi-tenant products is that the vendor enforces it for its own administrative access and the buyer enforces it for the buyer’s users.

Seven recur in almost every multi-tenant SaaS report, so a reader can check their own Section 3 against this list:

  1. Configuring and administering users inside the customer’s own tenant.
  2. Enforcing MFA or single sign-on for the customer’s own users.
  3. Reviewing the customer’s own user list and entitlements periodically.
  4. Notifying the vendor promptly when the customer’s own people leave.
  5. Safeguarding the API keys and service credentials issued to the customer.
  6. Setting retention and deletion options where the product exposes them.
  7. Reading the report and assessing whether these controls operate in the customer’s environment.

The numbering is report-specific. Cite the number as printed in your own Section 3, never the position in a list like this one.

“Our report identifies this as a complementary user entity control (CUEC 4). The platform provides the capability and we enforce it for our own administrative access; enforcement for your users is configured in your tenant. Configuration guide attached.”

— the shape of an answer that survives a second reading

Use the redirect only where the report genuinely places the control on the customer side. Answering half a questionnaire with “that is a CUEC” reads as evasion and costs more time than answering would have. The test: if you cannot point to the numbered CUEC in Section 3 and hand over the documentation that lets the customer operate it, it is not a CUEC answer.

Why a report answer outweighs a form answer

What the CPA firm actually requested

A tick in a questionnaire box costs a keystroke. The equivalent line in Section 4 cost a defined population, a sample, and artefacts that survived inspection. The last column names the questionnaire question each cadence lets you answer with a reference instead of an assertion. AT-C 205 requires sufficient appropriate evidence and prescribes no sample sizes; the figures below reflect common CPA-firm practice derived from the AICPA’s audit sampling guidance, set in each engagement by the service auditor’s judgement.

Control cadencePopulationTypical sampleArtefact that satisfies itWhat gets rejectedThe questionnaire question it lets you answer
Annual — risk assessment, policy approval, DR testThe single occurrence in the period.Tested in full.The dated deliverable, the approval record, the approver’s identity.An undated document, or one approved a month after the period closed.“Do you test your disaster recovery plan, and when did you last test it?”
Quarterly — access reviews, vendor reviewsFour scheduled runs.Commonly two.The listing reviewed, the reviewer’s decisions on it, and proof each revocation was actioned, with dates.A signed review with no listing attached; a review that flagged three accounts for removal where all three are still active at fieldwork.“How often do you review user access, and who signs it off?”
Monthly — scans, patching, backup checksTwelve runs.Commonly two or three.Historical scan output for the months selected, with remediation tickets and dates.A screenshot of today’s dashboard in place of the month selected. Current state is evidence of today, and the period closed months ago.“What is your vulnerability scan cadence, and what is your remediation SLA?”
Weekly — log review, alert triageFifty-two occurrences.Commonly around five.A system-generated record of who reviewed what, when, and what they concluded.“We look at it every week” with no record. An unevidenced routine is an unevidenced control.“Who reviews security alerts, and how do you demonstrate a review happened?”
Daily or continuous — monitoring, alerting, backupsTwo hundred and fifty or more.Commonly twenty to twenty-five.Logs or alert histories with timestamps and the disposition of each selected item.A hand-filtered spreadsheet. If the auditor cannot see how the export was produced, they cannot rely on it.“Do you monitor for anomalous activity, and who triages the alerts?”
Event-driven — joiners, leavers, changes, incidentsEvery event in the period, reconciled to an independent source: HR system, identity provider, ticketing database.Scaled to population; twenty-five is common for large ones.The ticket with its approval, its timestamps, and the artefact it produced.An incomplete population — the most common failure, and a fatal one. If the list is not demonstrably complete, no sample drawn from it means anything.“How quickly is access revoked when someone leaves?”

Take the quarterly row and put the two answers side by side. On the form, “how often do you review user access, and who signs it off?” is answered “quarterly, by the system owner” — three seconds of typing, backed by whoever typed it. In Section 4 the same question is answered by naming the population of four scheduled reviews, the two the service auditor selected, the entitlement listing each one worked from, the revocations it produced, and the tested result. The reviewer can check the second answer without asking you anything.

One theme runs through the rejection column: completeness of the population, and the reliability of information produced by the entity. Before sampling a listing of changes, terminations or incidents, the auditor must satisfy themselves it is complete and accurate — by reconciling it to an independent system of record and inspecting how the export was generated. A sample drawn from a list somebody curated proves nothing about the list nobody saw.

The durable fix

An answer library keyed to the report

Most teams build the library the wrong way round, storing previous answers keyed to previous questionnaires. It goes stale silently. Key each entry to its source instead, and the refresh becomes mechanical.

Answer typeWhere it livesEvidence anchorOwnerRefresh trigger
Tested controlSOC 2 Section 4Criterion, control ID, tested resultComplianceEvery new report
System boundarySOC 2 Section 3Heading reference in the descriptionCompliance, EngineeringNew report or architecture change
Customer-side controlSection 3 CUEC listCUEC number plus configuration guideCompliance, SupportEvery new report
Product capabilityProduct docs or trust centreDocument link and the plan tierProductAny release that changes it
Contractual commitmentMSA, DPA, SLAClause reference in the current templateLegalEvery template revision
Current-state factA live internal registerDated entry — pen test, sub-processors, insuranceSecurity operationsRolling; stamped with the date given
Not held, out of scopeNowhere — and say soA plain “we do not”, with compensating detailComplianceReviewed quarterly

Two additions make it hold. Give every entry a confidentiality tier — a SOC 2 is restricted-use, and quoting its exception detail into an open portal is a different act from citing a criterion. And date every current-state answer: “penetration test completed March 2026 by an independent firm” ages honestly, while “we test annually” quietly becomes false.

Objection handling

What security teams push back on and the answer

“Just answer yes or no. We do not accept references to a report.”

Answer the yes or no, then attach the reference. A bare affirmation is a self-declaration that becomes a warranty in the contract; the same affirmation with a criterion, a control identifier and an independently tested result is more information for the reviewer and less exposure for you. Offer a mapped appendix that travels alongside the completed form.

“Your report is from a firm we have never heard of.”

A SOC 2 opinion may only be issued by a licensed CPA firm, subject to AICPA and state board requirements including peer review. Provide the licence details and let them verify. The real question underneath is usually scope: point at the categories examined, the length of the period, and the size of the control set in Section 4.

“There are three exceptions in your report. We are escalating.”

Exceptions are normal and do not by themselves modify an opinion. Walk the reviewer through it in order: the opinion in Section 1, the exception language in Section 4, then management’s response. Say what the deviation was, how many items out of how large a sample, whether it recurred, and what changed. Narrating your own exceptions calmly reads as maturity.

“Upload the report to our third-party risk portal.”

SOC 2 reports are restricted-use documents intended for the service organisation, its user entities and other specified parties, so a platform that may redistribute one is worth pausing over. Ask about onward-sharing terms, share under the existing non-disclosure agreement where possible, and where only a general-use artefact is needed, offer a SOC 3.

“Complete our questionnaire anyway — it is policy.”

Accept it, and negotiate the shape of the exercise. Ask whether the programme has a reduced set for vendors holding a current Type 2, whether report references are acceptable in place of prose, and whether an annual refresh can replace a per-deal repeat. Many programmes support all three without advertising them.

There is a narrow case for pushing back outright: where the questionnaire restates, question by question, controls the report already shows as tested with no exceptions over a period covering the buyer’s evaluation window. The framing that works is “here is the same answer, independently tested, with the page reference — tell us which you still need in your format and we will complete those today.” That converts a refusal into a shortlist.

Edge cases

Where this gets contested

The mapping holds for the routine cases. These are the situations that generate the calls.

The product being bought is not the system described

A vendor with several products may have scoped the examination to one. If the buyer is purchasing a different module, an acquired platform or a self-hosted deployment, a clean opinion covers none of it. Say so before they find it in Section 3 — the most common cause of a review collapsing late.

The buyer asks about a carved-out subservice organisation

Where a cloud provider is carved out, the report describes the controls you expect it to operate but tests none of them. Point to the provider’s own report and the complementary subservice organisation controls in Section 3 — and expect the reply that you are the contracting party and therefore accountable, because contractually that is right.

The period does not cover the buyer’s evaluation window

A report closing 31 March 2026 says nothing about June. A bridge letter from management covers a short gap but carries no assurance, since the CPA firm performs no procedures over it. Where the gap is long, expect the questionnaire to expand — the questions are filling the uncovered months.

Only a Type 1 exists

A Type 1 opines on control design at a single date, with no operating-effectiveness testing behind it. Almost none of the mapping applies: there is no tested result to cite, only a described control. The questionnaire does most of the work until the first Type 2 lands.

Availability or Confidentiality was not in scope

A Security-only report is a complete and legitimate SOC 2, and it means the A and C criteria were never examined, so resilience, capacity, backup and confidential-data handling get answered from your own documentation. Being explicit about the categories stops a reviewer inferring coverage that does not exist.

The questionnaire is a contract in disguise

Many enterprise agreements incorporate questionnaire responses by reference, turning every answer into a warranty. Once that is true, “yes, with the following qualification” is worth far more than “yes”, and Legal belongs in the review. Check the incorporation clause before the compliance team starts typing.

Frequently Asked Questions

Does a SOC 2 report replace security questionnaires?

No. It replaces a large share of the questions inside one. Sort the document first, into four kinds: tested-control questions, which a Type 2 answers better than any self-declaration; current-state facts such as the date and scope of the last penetration test; product and configuration questions about what the buyer switches on in their own tenant; and contractual or jurisdictional terms. In the illustrative example on this page, a 284-question bank from an EU bank split into 171 answerable from Section 4, 42 from the contract and the DPA, 38 from product documentation, 19 redirected to complementary user entity controls, and 14 that needed original work.

Why does a buyer still send a questionnaire after receiving a clean SOC 2?

Usually because a rule or an internal policy requires it, and the rule does not mention SOC 2. GDPR Article 28(3)(h) obliges a processor to make available the information needed to demonstrate compliance and to allow for and contribute to audits; EDPB Guidelines 07/2020 treat third-party certifications and audit reports as one means of verifying a processor’s guarantees rather than a substitute for the contractual audit provision. DORA Article 30 requires processing locations and subcontracting conditions to sit in the written arrangement. NYDFS 23 NYCRR 500.11 and the June 2023 US interagency guidance at 88 FR 37920 require documented, evidenced due diligence of the provider itself.

The questionnaire asks about a control our report shows an exception against. What do we write?

Answer it directly and show your working, because the reviewer will read Section 4 anyway. Quote the exception language as printed, give the denominator — two of the twenty-five terminations selected were processed outside the stated window, say — and state whether it recurred in a later test or a later period. Point at management’s response in Section 4, noting that it is the service organisation’s own text and carries no assurance from the CPA firm, then say what changed, when it changed, and how you know it held. An exception narrated calmly with a date and a fix reads as maturity; the same exception discovered by the reviewer reads as concealment.

What is a CUEC and when should I use it as an answer?

A complementary user entity control is one the report assumes the customer operates. Three recur in almost every multi-tenant SaaS report: administering users inside the customer’s own tenant, reviewing that user list periodically, and notifying the vendor promptly when the customer’s own people leave. They appear in Section 3, and the CPA firm evaluated the described system assuming they exist — and did not test them, since the examination covers neither their design nor their operation. Use one as an answer only where you can cite the CUEC by the number printed in your own Section 3 and hand over the documentation that lets the customer operate it.

Does a SOC 2 report cover data residency?

No criterion addresses it. The 2017 Trust Services Criteria, with points of focus revised in 2022, say nothing about where data is stored or processed, so a clean opinion carries no residency assurance. A description may name hosting regions when it lists infrastructure components, but that text is descriptive and carries no test result behind it. Send three things instead: the hosting-region page from your product documentation, the annex to your data processing agreement listing processing locations and sub-processors, and the standard contractual clauses module that applies where transfers leave the EEA. For EU financial entities, DORA Article 30 puts processing locations in the written arrangement itself.

How do I build an answer library that stays current?

Key every entry to its source rather than to the questionnaire it arrived in. Tested-control answers point at a Section 4 criterion and control identifier; boundary answers at Section 3; customer-side answers at a numbered CUEC plus a configuration guide; product answers at documentation and the plan tier it applies to; commitments at a clause in the current contract template; current-state facts at a dated internal register. Give each entry a named owner, a refresh trigger and a confidentiality tier — because quoting exception detail from a restricted-use report into an open portal is a different act from citing a criterion.

Is a SOC 2 report enough for GDPR, HIPAA or PCI DSS?

No, in three different ways. For GDPR, a report can support the Article 28(3)(h) demonstration while leaving the processing agreement, sub-processor authorisation, transfer safeguards and the audit right in place. For HIPAA, a business associate agreement with satisfactory assurances is required under 45 CFR 164.308(b) and 164.314(a). For PCI DSS, requirement 12.8.4 expects a programme monitoring service providers’ compliance status at least once every twelve months, and the artefact it contemplates is an Attestation of Compliance. A framework mapping appendix in Section 5 is other information accompanying the report; the CPA firm’s opinion does not extend to it.

Are questionnaire answers riskier than a report reference?

Frequently, and teams underrate it. Many enterprise agreements incorporate questionnaire responses by reference, converting each answer into a contractual warranty made by whoever filled in the form, usually under a deadline and often without Legal reading it. Check the incorporation clause before anyone starts typing. A report reference carries its own limits with it — a stated period, a described system, named criteria and an independently tested result — so the reader can see exactly what was covered. Where a question outruns what the report shows, “yes, subject to the following” is worth far more than a bare yes.

What do I send a buyer who asks for the report before an NDA is in place?

Send the SOC 3, if you have one. It is a general-use report the CPA firm issues from the same examination, covering the same criteria but omitting the description of tests and results, so it can be published or handed over without a non-disclosure agreement. It answers the threshold question — is there a current examination, by whom, over what period, with what opinion — and buys the time to get a mutual NDA signed before the Type 2 is released. A SOC 3 has to be commissioned; it is a separate deliverable the CPA firm issues on request. SOC 2 reports themselves are restricted-use documents intended for the service organisation, its user entities and other specified parties.

Our report period ended two months before the questionnaire arrived. What changes?

Expect the questionnaire to grow, because the extra questions are filling the uncovered months. Issue a bridge letter: management’s written statement that the description remains accurate and that no material changes to the control environment occurred between the period end and a stated date, usually kept to three months or less. It is management’s representation — the CPA firm performs no procedures over the gap and the letter carries no assurance — so say that plainly and let the reviewer price it in. Pair it with dated current-state evidence covering the gap: the latest scan summary, the most recent access review, and any change to sub-processors or hosting regions.

Related reading: how to read a SOC 2 report, CUECs and CSOCs, subservice organizations, opinions and exceptions, who you can share the report with, what buyers should require of vendors, how long a report stays usable, SOC 2 for enterprise sales, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations