SOC 2 compliance: what it tells you about a document processing vendor
For teams buying document processing or workflow automation software: what a SOC 2 report covers, how to read one, and the security questions it leaves open.
Key takeaways
- SOC 2 is an AICPA framework: an independent CPA firm examines a service organization's controls and issues a report, not a certification.
- Every SOC 2 covers Security. Availability, Processing Integrity, Confidentiality and Privacy are added when they matter to the service.
- A Type 1 report checks control design on a single date; a Type 2 report tests whether controls worked over a period, usually 3 to 12 months.
- When you read a vendor's report, check the scope, period, exceptions, carved-out subservice organizations and the controls left to you.
- SOC 2 doesn't answer everything: also ask whether your data trains shared models, where it's hosted, how long it's kept and whether the vendor signs a BAA or DPA.
On this page
SOC 2 compliance means an independent CPA firm has examined a service organization's controls against the AICPA's trust services criteria and reported on them in a SOC 2 report. It's a report, not a certification, and the Type 2 version shows whether the controls worked over a period, usually 3 to 12 months. For a buyer, the report is the evidence behind a vendor's security claims, such as how a document processing platform protects the files you send it.
This guide covers the five criteria, Type 1 vs Type 2 reports, how to read a vendor's report and the security questions a report leaves open.
What is SOC 2 compliance?#
SOC 2 (System and Organization Controls 2) is one of the AICPA's reports for service organizations, such as software vendors that hold or process customer data. A CPA firm examines the vendor's description of its system and tests its controls, so customers can see how those controls are designed and whether they work.
Vendors usually share the full report on request, often under a nondisclosure agreement. Two related reports serve other readers:
| Report | What it covers | Who reads it |
|---|---|---|
| SOC 1 | Controls relevant to customers' financial reporting | Customers and their financial auditors |
| SOC 2 | The trust services criteria in detail, with the auditor's tests and results | Customers, prospects and their security teams |
| SOC 3 | The same criteria as SOC 2, with less detail | Anyone: it's a general-use report |
The five trust services criteria#
Every SOC 2 covers Security, the common criteria. The vendor adds the other four when they matter to the service it provides.
Security
Systems and data are protected against unauthorized access. Required in every SOC 2.Availability
Systems are up and usable as the vendor committed, with backups and recovery tested.Processing integrity
Processing is complete, valid, accurate, timely and authorized.Confidentiality
Information designated as confidential is protected from collection to disposal.Privacy
Personal information is collected, used, kept, disclosed and disposed of as the vendor committed.
When each is in scope, and what auditors test:
| Criterion | In scope when | Evidence auditors test |
|---|---|---|
| Security | Always | Access logs, encryption settings, vulnerability scans |
| Availability | The vendor commits to uptime or recovery times | Uptime monitoring, disaster recovery tests, incident logs |
| Processing integrity | Output accuracy affects customers' decisions | Reconciliations, validation rules, audit trails |
| Confidentiality | The vendor holds sensitive business data | Classification policies, data loss prevention settings, retention schedules |
| Privacy | The vendor processes personal information | Consent records, data subject request logs, privacy notices |
Check which criteria a vendor's report includes, and that they match what you rely on the vendor for.
SOC 2 Type 1 vs Type 2#
| Report | What the auditor tests | Time covered | Good for |
|---|---|---|---|
| Type 1 | Whether controls are designed and in place | A single date | A vendor's first report, or an early conversation |
| Type 2 | Whether controls are designed and worked in practice, by testing samples | A period, usually 3 to 12 months | Most enterprise security reviews |
A Type 1 says there's a lock on the door. A Type 2 shows it was locked every night of the period.
How to read a vendor's SOC 2 report#
The useful detail is in the scope, the tests and the exceptions, not the opinion letter. Ask for the report before you send a security questionnaire: a well-scoped Type 2 answers many of its questions.
- ScopeThe system description covers the product you're buying, not just the vendor's corporate IT.
- Type and periodA Type 2 whose period ended recently. For the months since, ask for a bridge letter: signed by the vendor, not the auditor, and usually no longer than 3 months.
- OpinionUnqualified means the controls were found designed and operating effectively. A qualified opinion names what fell short.
- ExceptionsRead each one and the vendor's response. An isolated miss with a fix is normal; a pattern isn't.
- Subservice organizationsCloud hosts are often carved out, so their controls weren't tested. Ask for their own reports.
- Your controlsComplementary user entity controls are steps the report assumes you take, such as removing your users' access when they leave.
- The auditorA licensed CPA firm and a report written for this system, not boilerplate. The AICPA's Journal of Accountancy has warned that rushed reports can rest on the vendor's word instead of testing.
How a SOC 2 audit works#
Preparation often takes longer than the audit itself. First audits tend to stumble on evidence rather than controls: an access review that happened but wasn't recorded counts as not done.
- Set the scopePick the services, systems and criteria the report will cover.
- Assess readinessMap existing controls to the criteria and list the gaps.
- Close the gapsFormalize access reviews, change approvals and incident response, and keep records of each.
- Run the periodFor a Type 2, controls run through the review period while evidence is collected.
- Auditor testingThe CPA firm samples evidence, interviews control owners and records exceptions.
- Report, then repeatThe report is issued and the cycle restarts, so customers always have a recent one.
Security questions to ask before you deploy workflow automation#
A SOC 2 report shows that a vendor's controls were tested, not everything you need to know before sending it your documents. Ask these too, for a document processing platform or any other workflow automation tool:
Model training
Do your documents or extracted data train models shared with other customers or third parties?Hosting
Which cloud and region hold your data, and can you choose? Is on-premise an option if you need it?Access
Single sign-on, multi-factor authentication and roles that limit each user to what their job needs.Audit logs
Who viewed, changed, approved and exported what, and whether you can search and export the log.Retention
How long files and extracted data are kept, and how deletion is confirmed when the contract ends.Contracts
A business associate agreement (BAA) for health information and a data processing agreement (DPA) under GDPR.
Docsumo, an intelligent document processing platform, has a SOC 2 Type 2 report and ISO/IEC 27001:2022 certification, and supports HIPAA and GDPR with a BAA and DPA available. Customer data isn't used to train shared or third-party models. Audit logging is on the Business plan. Docsumo runs in the cloud only, with no on-premise option. It doesn't make you compliant on its own: your access policies and retention rules still decide that. See the security page and the platform overview.
SOC 2 vs ISO 27001, HIPAA and GDPR#
These overlap, and vendors often hold several. The difference is the proof you can ask for.
| Framework | What it is | Proof you can ask for |
|---|---|---|
| SOC 2 | An AICPA attestation on a service organization's controls | The CPA firm's report, Type 1 or Type 2 |
| ISO/IEC 27001 | An international standard for managing information security | A certificate from an accredited certification body |
| HIPAA | US law protecting health information | No official certification: a signed BAA and the vendor's safeguards |
| GDPR | EU law on personal data | A data processing agreement setting out the processor's obligations |
HHS doesn't recognize private certifications of HIPAA Security Rule compliance, so ask for the BAA and the safeguards behind any HIPAA badge. More on HIPAA compliance, audit trails and access control and data encryption.
The bottom line#
A SOC 2 report is the best single piece of evidence about a vendor's security, if you read it: the scope, the period, the exceptions and the controls it leaves to you. Pair it with the questions it doesn't answer, such as model training, hosting and retention, before your documents go anywhere.
Book a demo to walk through Docsumo's security with your team, or start a free trial.
Frequently asked questions#
Is SOC 2 a certification?
No. SOC 2 is an attestation: a CPA firm examines a service organization's controls and issues a report on them. ISO/IEC 27001 is a certification, and HIPAA has no official certification at all.
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report checks that controls are designed and in place on a single date. A Type 2 report tests whether they worked over a period, usually 3 to 12 months, which is why most buyers ask for Type 2.
What is a SOC 2 bridge letter?
A letter from the vendor's management that covers the gap between the end of its last report period and today, saying whether its systems or controls have changed. The vendor signs it, not the auditor, so it isn't assurance, and it usually covers no more than 3 months.
What is the difference between SOC 1, SOC 2 and SOC 3?
SOC 1 covers controls relevant to customers' financial reporting. SOC 2 covers security, availability, processing integrity, confidentiality and privacy in detail. SOC 3 covers the same criteria as SOC 2 in a short general-use report anyone can read.
What security questions should you ask before deploying workflow automation?
Start with a recent SOC 2 Type 2 report. Then ask whether your data trains shared models, where it's hosted, how single sign-on and user roles work, what the audit log records, how long data is kept, and whether the vendor signs a BAA or DPA.
Is Docsumo SOC 2 compliant?
Yes. Docsumo has a SOC 2 Type 2 report, is ISO/IEC 27001:2022 certified and supports HIPAA and GDPR compliance, with a BAA and DPA available. See security.
Sources
- AICPA & CIMA: SOC 2 guide, reporting on an examination of controls at a service organization
- AICPA & CIMA: SOC 3, trust services criteria for general use report
- AICPA & CIMA: System and Organization Controls, SOC suite of services
- Journal of Accountancy: Promises of 'fast and easy' threaten SOC credibility (February 2026)
- Schellman: SOC report Type 1 vs Type 2
- Schellman: How to scope a SOC 2 audit
- Schellman: Carve-out vs inclusive method for subservice organizations
- Linford & Co: How to review SOC 1 and SOC 2 reports
- Linford & Co: Bridge (gap) letters in SOC reports
- HHS: Are we required to certify our organization's compliance with the Security Rule?
- Regulation (EU) 2016/679 (GDPR), Article 28: processors
First published . Last updated .