SOC 2 compliance: what it tells you about a document processing vendor

For teams buying document processing or workflow automation software: what a SOC 2 report covers, how to read one, and the security questions it leaves open.

Key takeaways

  • SOC 2 is an AICPA framework: an independent CPA firm examines a service organization's controls and issues a report, not a certification.
  • Every SOC 2 covers Security. Availability, Processing Integrity, Confidentiality and Privacy are added when they matter to the service.
  • A Type 1 report checks control design on a single date; a Type 2 report tests whether controls worked over a period, usually 3 to 12 months.
  • When you read a vendor's report, check the scope, period, exceptions, carved-out subservice organizations and the controls left to you.
  • SOC 2 doesn't answer everything: also ask whether your data trains shared models, where it's hosted, how long it's kept and whether the vendor signs a BAA or DPA.
On this page
  1. What is SOC 2 compliance?
  2. The five trust services criteria
  3. SOC 2 Type 1 vs Type 2
  4. How to read a vendor's SOC 2 report
  5. How a SOC 2 audit works
  6. Security questions to ask before you deploy workflow automation
  7. SOC 2 vs ISO 27001, HIPAA and GDPR
  8. The bottom line
  9. Frequently asked questions

SOC 2 compliance means an independent CPA firm has examined a service organization's controls against the AICPA's trust services criteria and reported on them in a SOC 2 report. It's a report, not a certification, and the Type 2 version shows whether the controls worked over a period, usually 3 to 12 months. For a buyer, the report is the evidence behind a vendor's security claims, such as how a document processing platform protects the files you send it.

This guide covers the five criteria, Type 1 vs Type 2 reports, how to read a vendor's report and the security questions a report leaves open.

What is SOC 2 compliance?#

SOC 2 (System and Organization Controls 2) is one of the AICPA's reports for service organizations, such as software vendors that hold or process customer data. A CPA firm examines the vendor's description of its system and tests its controls, so customers can see how those controls are designed and whether they work.

Vendors usually share the full report on request, often under a nondisclosure agreement. Two related reports serve other readers:

ReportWhat it coversWho reads it
SOC 1Controls relevant to customers' financial reportingCustomers and their financial auditors
SOC 2The trust services criteria in detail, with the auditor's tests and resultsCustomers, prospects and their security teams
SOC 3The same criteria as SOC 2, with less detailAnyone: it's a general-use report

The five trust services criteria#

Every SOC 2 covers Security, the common criteria. The vendor adds the other four when they matter to the service it provides.

  • Security

    Systems and data are protected against unauthorized access. Required in every SOC 2.
  • Availability

    Systems are up and usable as the vendor committed, with backups and recovery tested.
  • Processing integrity

    Processing is complete, valid, accurate, timely and authorized.
  • Confidentiality

    Information designated as confidential is protected from collection to disposal.
  • Privacy

    Personal information is collected, used, kept, disclosed and disposed of as the vendor committed.

When each is in scope, and what auditors test:

CriterionIn scope whenEvidence auditors test
SecurityAlwaysAccess logs, encryption settings, vulnerability scans
AvailabilityThe vendor commits to uptime or recovery timesUptime monitoring, disaster recovery tests, incident logs
Processing integrityOutput accuracy affects customers' decisionsReconciliations, validation rules, audit trails
ConfidentialityThe vendor holds sensitive business dataClassification policies, data loss prevention settings, retention schedules
PrivacyThe vendor processes personal informationConsent records, data subject request logs, privacy notices

Check which criteria a vendor's report includes, and that they match what you rely on the vendor for.

SOC 2 Type 1 vs Type 2#

ReportWhat the auditor testsTime coveredGood for
Type 1Whether controls are designed and in placeA single dateA vendor's first report, or an early conversation
Type 2Whether controls are designed and worked in practice, by testing samplesA period, usually 3 to 12 monthsMost enterprise security reviews

A Type 1 says there's a lock on the door. A Type 2 shows it was locked every night of the period.

How to read a vendor's SOC 2 report#

The useful detail is in the scope, the tests and the exceptions, not the opinion letter. Ask for the report before you send a security questionnaire: a well-scoped Type 2 answers many of its questions.

  • ScopeThe system description covers the product you're buying, not just the vendor's corporate IT.
  • Type and periodA Type 2 whose period ended recently. For the months since, ask for a bridge letter: signed by the vendor, not the auditor, and usually no longer than 3 months.
  • OpinionUnqualified means the controls were found designed and operating effectively. A qualified opinion names what fell short.
  • ExceptionsRead each one and the vendor's response. An isolated miss with a fix is normal; a pattern isn't.
  • Subservice organizationsCloud hosts are often carved out, so their controls weren't tested. Ask for their own reports.
  • Your controlsComplementary user entity controls are steps the report assumes you take, such as removing your users' access when they leave.
  • The auditorA licensed CPA firm and a report written for this system, not boilerplate. The AICPA's Journal of Accountancy has warned that rushed reports can rest on the vendor's word instead of testing.

How a SOC 2 audit works#

Preparation often takes longer than the audit itself. First audits tend to stumble on evidence rather than controls: an access review that happened but wasn't recorded counts as not done.

  1. Set the scopePick the services, systems and criteria the report will cover.
  2. Assess readinessMap existing controls to the criteria and list the gaps.
  3. Close the gapsFormalize access reviews, change approvals and incident response, and keep records of each.
  4. Run the periodFor a Type 2, controls run through the review period while evidence is collected.
  5. Auditor testingThe CPA firm samples evidence, interviews control owners and records exceptions.
  6. Report, then repeatThe report is issued and the cycle restarts, so customers always have a recent one.

Security questions to ask before you deploy workflow automation#

A SOC 2 report shows that a vendor's controls were tested, not everything you need to know before sending it your documents. Ask these too, for a document processing platform or any other workflow automation tool:

  • Model training

    Do your documents or extracted data train models shared with other customers or third parties?
  • Hosting

    Which cloud and region hold your data, and can you choose? Is on-premise an option if you need it?
  • Access

    Single sign-on, multi-factor authentication and roles that limit each user to what their job needs.
  • Audit logs

    Who viewed, changed, approved and exported what, and whether you can search and export the log.
  • Retention

    How long files and extracted data are kept, and how deletion is confirmed when the contract ends.
  • Contracts

    A business associate agreement (BAA) for health information and a data processing agreement (DPA) under GDPR.

Docsumo, an intelligent document processing platform, has a SOC 2 Type 2 report and ISO/IEC 27001:2022 certification, and supports HIPAA and GDPR with a BAA and DPA available. Customer data isn't used to train shared or third-party models. Audit logging is on the Business plan. Docsumo runs in the cloud only, with no on-premise option. It doesn't make you compliant on its own: your access policies and retention rules still decide that. See the security page and the platform overview.

SOC 2 vs ISO 27001, HIPAA and GDPR#

These overlap, and vendors often hold several. The difference is the proof you can ask for.

FrameworkWhat it isProof you can ask for
SOC 2An AICPA attestation on a service organization's controlsThe CPA firm's report, Type 1 or Type 2
ISO/IEC 27001An international standard for managing information securityA certificate from an accredited certification body
HIPAAUS law protecting health informationNo official certification: a signed BAA and the vendor's safeguards
GDPREU law on personal dataA data processing agreement setting out the processor's obligations

HHS doesn't recognize private certifications of HIPAA Security Rule compliance, so ask for the BAA and the safeguards behind any HIPAA badge. More on HIPAA compliance, audit trails and access control and data encryption.

The bottom line#

A SOC 2 report is the best single piece of evidence about a vendor's security, if you read it: the scope, the period, the exceptions and the controls it leaves to you. Pair it with the questions it doesn't answer, such as model training, hosting and retention, before your documents go anywhere.

Book a demo to walk through Docsumo's security with your team, or start a free trial.

Frequently asked questions#

Is SOC 2 a certification?

No. SOC 2 is an attestation: a CPA firm examines a service organization's controls and issues a report on them. ISO/IEC 27001 is a certification, and HIPAA has no official certification at all.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report checks that controls are designed and in place on a single date. A Type 2 report tests whether they worked over a period, usually 3 to 12 months, which is why most buyers ask for Type 2.

What is a SOC 2 bridge letter?

A letter from the vendor's management that covers the gap between the end of its last report period and today, saying whether its systems or controls have changed. The vendor signs it, not the auditor, so it isn't assurance, and it usually covers no more than 3 months.

What is the difference between SOC 1, SOC 2 and SOC 3?

SOC 1 covers controls relevant to customers' financial reporting. SOC 2 covers security, availability, processing integrity, confidentiality and privacy in detail. SOC 3 covers the same criteria as SOC 2 in a short general-use report anyone can read.

What security questions should you ask before deploying workflow automation?

Start with a recent SOC 2 Type 2 report. Then ask whether your data trains shared models, where it's hosted, how single sign-on and user roles work, what the audit log records, how long data is kept, and whether the vendor signs a BAA or DPA.

Is Docsumo SOC 2 compliant?

Yes. Docsumo has a SOC 2 Type 2 report, is ISO/IEC 27001:2022 certified and supports HIPAA and GDPR compliance, with a BAA and DPA available. See security.

See Docsumo read your own documents

Bring a few real samples. We'll show the fields extracted, the checks that ran and what a reviewer would see.