How to read a vendor SOC 2 report (the parts that matter)
What to look for when a vendor hands you 200 pages of compliance.
A SOC 2 report proves a vendor has been audited on security controls. You don't need to read every page.
**Focus on:**
- **Type II vs Type I** — Type II covers months of operation, not a single point in time
- **Exceptions** — Any failed controls or caveats in the auditor's opinion
- **Scope** — Does it cover the product you actually use?
- **Subservice organizations** — Who else handles their data (AWS, etc.)?
**Red flags:** Type I only, expired report, scope that doesn't match your use case, or lots of exceptions with no remediation plan.