• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » SOC 2 Outsourcing

SOC 2 Outsourcing

Definition

SOC 2 Outsourcing

SOC 2 outsourcing is the use of a provider’s SOC 2 report, which tests controls for security, availability, processing integrity, confidentiality and privacy. The exceptions section carries the information, not the opinion at the front that buyers stop reading after.

Almost nobody reads past the first page, which is where the value starts.

A SOC 2 is not a certificate — it is an examination report running to dozens of pages, containing the provider’s own description of its system, the auditor’s tests, and the results of those tests.

Two features decide whether the report actually covers your arrangement: what the provider carved out, and what it expects you to do yourself.

Key takeaways

  • SOC 2 is a report, not a certification, and its detail sits behind the opinion.
  • Complementary user entity controls are the things the provider assumes you operate.
  • The carve-out method excludes a provider’s own subservice organisations from testing.
  • Access normally requires a non-disclosure agreement, unlike the general-use SOC 3.

How it works

SOC 2 falls inside the AICPA’s System and Organization Controls suite. The examination tests a provider’s controls against trust services criteria covering security, availability, processing integrity, confidentiality and privacy.

Security is the only criterion every report includes. The other four are optional, so a report may legitimately say nothing about availability or privacy while still being a genuine SOC 2.

Complementary user entity controls are the part buyers skip. These are controls the provider assumes its customers operate — user access reviews, for instance, or configuration of the features you were given.

If you never read that list, you have accepted obligations without knowing it. The report’s conclusion depends on controls sitting inside your organisation, not the provider’s.

The second trap is subservice organisations. A provider using a cloud host can carve that host out of scope, in which case its controls were not tested, or include it, in which case they were.

Report featureWhat to check
Criteria coveredWhether privacy and availability are actually in scope
Type 1 or type 2Whether operating effectiveness was tested over a period
Period coveredWhether it aligns with your own reporting year
Carve-out or inclusiveWhether subservice providers were tested at all
Complementary controlsWhich obligations land on you
Exceptions notedWhat the testing actually found

AWS notes that an NDA is required to review the AWS SOC 1 and SOC 2 reports. Expect to sign one, and expect a provider that refuses entirely to have a reason.

Examples

SOC 2 reports get collected far more often than they get read, and the difference shows up during an incident. Each situation here was resolved in a contract, not in a marketing claim.

A buyer files a provider’s report without opening it. The complementary user entity controls list twelve obligations its own team never took on, which surfaces only after an access breach.

A company accepts a report whose scope covers security alone. Its availability concerns were never examined, so the document says nothing about the uptime it actually cared about.

An insurer finds its provider carved out its cloud host. The infrastructure running the service was untested, a distinction that vendor management outsourcing teams are paid to catch.

A bank reads the exceptions and finds four deviations in change management. The opinion was unqualified, and the findings still changed how it monitored the relationship.

Related terms

SOC terminology collides with an unrelated security acronym and with certification schemes that work differently. The terms below are separated on purpose, since buyers routinely treat them as interchangeable.

FAQ

Is SOC 2 a certification?

No. It is an attestation report produced by a CPA firm. There is no SOC 2 certificate, and providers describing one are using the word loosely.

What are complementary user entity controls?

Controls the provider assumes you operate at your end. The report’s conclusions depend on them, so the list is effectively a set of obligations for you.

What is the carve-out method?

An approach that excludes a provider’s own subservice organisations from the examination. Their controls were not tested, which matters if they run your infrastructure.

Does a SOC 2 cover privacy?

Only if privacy was included. Security is the sole mandatory criterion, so check which of the five the report actually addresses.

How is it different from ISO 27001?

ISO 27001 certifies a management system against a standard. SOC 2 reports an auditor’s opinion and test results over a defined period.

Do I need to sign an NDA?

Usually yes. Detailed SOC 2 reports are restricted, which is why the general-use SOC 3 summary exists alongside them.

Compare source partners in the Outsource Accelerator hubs directory and read the exceptions section before the opinion.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image