Finally Compliant
Apply

Report test

Will your SOC 2 report survive a real security review?

Four questions a buyer’s security team asks before they accept a report. You can run all four yourself in about ten minutes. If any answer is a no, the report will not survive procurement, and it is better to know this week than in a deal cycle.

  1. 01

    Is the signing firm in the AICPA peer-review program?

    How to check: Open the report’s opinion letter, take the firm name, and look it up in the AICPA Peer Review Public File. Two minutes. AICPA Peer Review Public File.

    The tell: A firm that is not enrolled, or whose last review is older than three years, is the first thing a security team flags. It is the first thing that came apart for the reports sold through low-cost platforms in 2025 and 2026.

  2. 02

    Does the report name exceptions?

    How to check: Go to Section 4, the tests of controls. Count the exceptions and read how management responded to each.

    The tell: Zero exceptions across a full observation period with zero incidents is the tell. Real environments produce findings: a stale access review, a late offboarding, a log gap. A report that found nothing usually tested nothing.

  3. 03

    Can you produce the evidence behind any control on request?

    How to check: Pick three controls at random from the report and pull the evidence yourself: a pull request, a log export, a ticket, a screenshot with a date on it.

    The tell: If the evidence lives only inside a compliance dashboard, or nobody on the team knows where it is, a buyer’s security team will ask the same question and get the same silence.

  4. 04

    Does the observation period match what was actually monitored?

    How to check: Compare the report’s observation window with the date your monitoring, logging and access reviews were switched on. The dates are in the platform and in your git history.

    The tell: A Type 2 window that starts before the controls were running is the most common way a report fails a real review, and the one buyers have learned to check first.

What a no costs

Finding out in procurement costs one deal cycle, usually one to two quarters, plus a Type 2 observation window you start again from the day the controls actually run. Finding out now costs ten minutes. The fix is the same work you were sold the first time, done properly: controls running in the infrastructure, with evidence an independent auditor can trace to a commit.

Two ways to use us

If we emailed you, reply “run it” and we run the four questions on your report from the outside. You send us nothing. Otherwise, fifteen minutes on a call is enough to tell you whether audit-ready in 14 business days is realistic for your environment.

Book a 15-minute Quick Fit callApply for a build slot

The audit stays independent: you pick from named, peer-reviewed CPA firms and we never perform it. What we do is the engineering, with senior engineers merging the pull requests and the commit history as the evidence.