SOC 2 Outsourcing
Definition
SOC 2 Outsourcing
SOC 2 outsourcing is the use of a provider’s SOC 2 report, which tests controls for security, availability, processing integrity, confidentiality and privacy. The exceptions section carries the information, not the opinion at the front that buyers stop reading after.
Almost nobody reads past the first page, which is where the value starts.
A SOC 2 is not a certificate — it is an examination report running to dozens of pages, containing the provider’s own description of its system, the auditor’s tests, and the results of those tests.
Two features decide whether the report actually covers your arrangement: what the provider carved out, and what it expects you to do yourself.
Key takeaways
- SOC 2 is a report, not a certification, and its detail sits behind the opinion.
- Complementary user entity controls are the things the provider assumes you operate.
- The carve-out method excludes a provider’s own subservice organisations from testing.
- Access normally requires a non-disclosure agreement, unlike the general-use SOC 3.
How it works
SOC 2 falls inside the AICPA’s System and Organization Controls suite. The examination tests a provider’s controls against trust services criteria covering security, availability, processing integrity, confidentiality and privacy.
Security is the only criterion every report includes. The other four are optional, so a report may legitimately say nothing about availability or privacy while still being a genuine SOC 2.
Complementary user entity controls are the part buyers skip. These are controls the provider assumes its customers operate — user access reviews, for instance, or configuration of the features you were given.
If you never read that list, you have accepted obligations without knowing it. The report’s conclusion depends on controls sitting inside your organisation, not the provider’s.
The second trap is subservice organisations. A provider using a cloud host can carve that host out of scope, in which case its controls were not tested, or include it, in which case they were.
| Report feature | What to check |
|---|---|
| Criteria covered | Whether privacy and availability are actually in scope |
| Type 1 or type 2 | Whether operating effectiveness was tested over a period |
| Period covered | Whether it aligns with your own reporting year |
| Carve-out or inclusive | Whether subservice providers were tested at all |
| Complementary controls | Which obligations land on you |
| Exceptions noted | What the testing actually found |
AWS notes that an NDA is required to review the AWS SOC 1 and SOC 2 reports. Expect to sign one, and expect a provider that refuses entirely to have a reason.
Examples
SOC 2 reports get collected far more often than they get read, and the difference shows up during an incident. Each situation here was resolved in a contract, not in a marketing claim.
A buyer files a provider’s report without opening it. The complementary user entity controls list twelve obligations its own team never took on, which surfaces only after an access breach.
A company accepts a report whose scope covers security alone. Its availability concerns were never examined, so the document says nothing about the uptime it actually cared about.
An insurer finds its provider carved out its cloud host. The infrastructure running the service was untested, a distinction that vendor management outsourcing teams are paid to catch.
A bank reads the exceptions and finds four deviations in change management. The opinion was unqualified, and the findings still changed how it monitored the relationship.
Related terms
SOC terminology collides with an unrelated security acronym and with certification schemes that work differently. The terms below are separated on purpose, since buyers routinely treat them as interchangeable.
- SOC 2: the report and its criteria, considered apart from any outsourcing arrangement.
- Security operations center (SOC): an entirely different SOC — a monitoring team, not an audit report.
- Cybersecurity outsourcing: buying security capability, rather than obtaining assurance over a provider.
- Compliance outsourcing: delegating regulatory work as a service line.
- Information security analyst: the role operating the controls a report examines.
- Vendor management outsourcing: running supplier assurance, including reading these reports properly.
- ISO 27001: a certifiable management system, where SOC 2 is an attestation report.
FAQ
Is SOC 2 a certification?
No. It is an attestation report produced by a CPA firm. There is no SOC 2 certificate, and providers describing one are using the word loosely.
What are complementary user entity controls?
Controls the provider assumes you operate at your end. The report’s conclusions depend on them, so the list is effectively a set of obligations for you.
What is the carve-out method?
An approach that excludes a provider’s own subservice organisations from the examination. Their controls were not tested, which matters if they run your infrastructure.
Does a SOC 2 cover privacy?
Only if privacy was included. Security is the sole mandatory criterion, so check which of the five the report actually addresses.
How is it different from ISO 27001?
ISO 27001 certifies a management system against a standard. SOC 2 reports an auditor’s opinion and test results over a defined period.
Do I need to sign an NDA?
Usually yes. Detailed SOC 2 reports are restricted, which is why the general-use SOC 3 summary exists alongside them.
Compare source partners in the Outsource Accelerator hubs directory and read the exceptions section before the opinion.







Independent




