Skip to main content
Compliance

SOC 2 when your buyer is a government prime: which report, what scope, what they actually need

A prime sends a security package with one line in it: maintain a current SOC 2. It does not say which report, over which system, covering which criteria, for what period. Those four blanks decide whether the audit you buy answers the question or misses it entirely.

The request usually arrives without a scope

The line in the flowdown package almost never specifies the report. It says the subcontractor shall maintain a current SOC 2. It does not say Type 1 or Type 2, does not name the system, does not name the trust services categories, and does not say what observation period the prime expects. That vagueness is rarely carelessness. It usually means the request came out of a supply-chain risk or vendor-management function applying a commercial template to a federal subcontract, without asking whether SOC 2 is the instrument the contract needs.

Before spending money on an examination, work out which of three questions the prime is trying to answer. A SOC 2 answers two of them well. The third it does not answer at all, and the third is the one that shows up on a defense program.

Is this vendor run by adults? The prime wants evidence that access is provisioned and revoked, that changes are reviewed, that someone owns incident response, that backups get tested. A SOC 2 answers this well. It is the report's best use, and for a commercial buyer it is often the only question being asked.

Will this vendor hold up when our own customer's assessor pulls the thread? The prime carries an obligation of its own and wants to show it exercised diligence over its suppliers. A SOC 2 Type 2 answers this well, because it contains a table of the tests the auditor performed and the exceptions found. That table is the part diligence teams read.

Does this vendor satisfy the security clauses that flow down from our prime contract? A SOC 2 does not answer this. Federal safeguarding clauses name specific control sets and specific evidence artifacts, and none of them names SOC 2. Getting this confused is the expensive mistake.

What a SOC 2 actually is

A SOC 2 is an attestation engagement performed by a licensed CPA firm. The service organization's management makes an assertion about its system and its controls; the practitioner examines that assertion and expresses an opinion. It is not a certification, and no body issues a pass. The output is a report with an opinion paragraph in it.

The standards moved more recently than most buyers realize. SSAE No. 21 amended AT-C section 105, Concepts Common to All Attestation Engagements, and redrafted AT-C section 205 as Assertion-Based Examination Engagements. It took effect for practitioners' reports dated on or after June 15, 2022, and it applies to SOC 2 and SOC 3. SOC 1 stayed where it was, under SSAE No. 18 and AT-C section 320.

The control criteria come from TSP section 100, the 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus — 2022). The 2022 update revised the points of focus and, in the AICPA's own words, does not in any way alter the criteria in the 2017 TSC. So a report issued in 2026 rests on criteria that have been stable since 2017, with better application guidance layered on top.

Here is the property buyers most often miss. The trust services criteria set outcomes, not a control list. The AICPA states it directly: the criteria are intended for evaluation and reporting regardless of the specific controls management implements, in contrast to frameworks that mandate a set of controls. They align to the seventeen COSO principles plus supplemental criteria covering logical and physical access controls, system operations, change management, and risk mitigation. Security is carried entirely by the common criteria — CC1 control environment, CC2 information and communication, CC3 risk assessment, CC4 monitoring, CC5 control activities. Availability, processing integrity, confidentiality, and privacy each add a series on top.

Two consequences follow. Two companies can both hold clean SOC 2 reports and run wildly different security programs, because each chose its own controls to meet the same outcomes. And a SOC 2 cannot be read as compliance with any external control catalog unless the report explicitly maps to it. The AICPA contemplates that mapping: if a service organization commits to meeting the requirements of a named process or control framework, those requirements are likely to be treated as additional points of focus in the examination. That is the mechanism behind the mapped reports marketed as "SOC 2 plus," and it has to be scoped in at the start.

How much of the question a scoped SOC 2 Type 2 answers on its own

A prime's internal vendor-risk questionnaire
92%
A commercial customer's security schedule in an MSA
88%
FAR 52.204-21 basic safeguarding of Federal Contract Information
62%
NIST SP 800-171 under DFARS 252.204-7012
40%
A posted assessment score under DFARS 252.204-7020
10%
FedRAMP authorization for a cloud offering sold to an agency
5%

Our coverage judgement, not a measured statistic. A high score means the report substantially answers that buyer's question by itself; a low score means the report is the wrong instrument and a different artifact is required.

The bottom three rows are the point of the whole page. The work a SOC 2 puts into access control, change management, and monitoring genuinely overlaps the fifteen basic safeguarding requirements in FAR 52.204-21, which is why that row sits mid-chart rather than at the bottom. But overlap is not evidence: nobody tested your controls against the FAR list, so the report does not say you met it. And once the requirement is a posted assessment score or a government authorization, no amount of SOC 2 work substitutes. Different instruments, different issuers.

The SOC family, and which report to send

Six report types share the SOC brand and they are not interchangeable. Sending the wrong one wastes a diligence cycle and makes the vendor look unfamiliar with its own paperwork.

ReportWhat the opinion coversDistributionWhen a buyer should ask for it
SOC 1Controls relevant to user entities' internal control over financial reporting. Performed under SSAE No. 18 and AT-C 320.RestrictedYour service feeds the customer's financial statements — payroll, claims, transaction handling.
SOC 2 Type 1Whether the description follows the description criteria and controls were suitably designed, at a point in time. No effectiveness opinion, no tests of controls.RestrictedFirst year only, while the Type 2 observation period runs.
SOC 2 Type 2All of Type 1, plus an opinion that controls operated effectively throughout a period, plus the tests performed and their results.RestrictedNearly always. This is what a prime's diligence team means.
SOC 3An opinion on design and operating effectiveness, without the detailed tests of controls and results.General useA public trust page, or an early sales question with no NDA in place.
SOC for CybersecurityWhether the description of the entity-wide cybersecurity risk management program follows the description criteria and its controls were effective.General useA board or insurer wants an entity-level rather than system-level view.
SOC for Supply ChainControls in a production, manufacturing, or distribution system, against the trust services categories.RestrictedYou make or move goods and the customer's concern is the physical supply chain.

The distribution column trips people up. SOC 1 and SOC 2 reports are restricted to specified parties under the attestation standards; SOC 3 is general use. A prime asking you to post your SOC 2 publicly is asking for something the report is not built to do. The answer is a SOC 3 for the public page and the SOC 2 under NDA for the diligence file.

Type 1 or Type 2, and why the answer is almost always Type 2

The distinction is precise and worth stating in the AICPA's own terms. A Type 2 engagement covers the suitability of design and the operating effectiveness of controls throughout a specified period, and the report includes a detailed description of the tests of controls the service auditor performed and the results of those tests. A Type 1 addresses the same subject matter but contains no opinion on operating effectiveness and no description of tests or results.

Put plainly: a Type 1 says the controls were designed sensibly on one day. A Type 2 says they ran for months and here is what happened when we tested them, including the times they did not run. Nearly everything a buyer wants to know lives in that difference. When a diligence reviewer opens a Type 2, the first place they go is the tests-and-results section and the second is the exceptions. A report with zero exceptions across a twelve-month period does not read as reassuring to an experienced reviewer; it reads as a scope drawn small.

There is one honest use for a Type 1. If a deal is live and the buyer needs to see motion, a Type 1 dated now, with the Type 2 observation period already running behind it, is defensible. Say exactly that in writing: here is the Type 1, the window opened on this date, the Type 2 is expected in this month. Offering a Type 1 as the permanent answer does not work. A second year without a Type 2 reads as a company that could not pass one.

Scope is the entire engagement

Two decisions define a SOC 2: the system boundary and the categories. Everything else is execution.

The AICPA defines system boundaries as the specific aspects of an entity's infrastructure, software, people, procedures, and data necessary to perform a function or provide a service, and notes that when services share components the systems overlap while the boundaries still differ. Those same five things are the system components you enumerate in the description. Write the boundary around the service the customer buys, not around the whole company. A production platform, its supporting infrastructure, the engineers who operate it, and the processes governing change and access is a scope. "The company" is not, and a description that reads that way produces either a very expensive audit or a very hollow one.

Then pick the categories. Security is mandatory and is carried by the common criteria alone. The other four are elective, and each one you add brings its own criteria series and its own evidence burden:

  • Availability — add it when you have committed to an uptime or recovery number. The criterion is that information and systems are available for operation and use to meet the entity's objectives. It does not set a minimum performance level by itself; your own service commitments do.
  • Confidentiality — add it when you hold customer information under a contractual restriction on access, use, retention, or disclosure. On a federal subcontract this is usually the right second category.
  • Processing integrity — add it when the customer relies on the correctness of a computation you perform, not merely on your holding data safely. Model outputs, scoring, and settlement calculations sit here.
  • Privacy — add it only when you handle personal information. It is the most demanding addition, and a defense prime asking about safeguarding almost never needs it. Confidentiality covers sensitive information generally; privacy applies only to personal information.
A company can buy a clean Type 2 report and still be unable to receive the subcontract, because federal safeguarding clauses name specific control sets and specific evidence artifacts, and none of them names SOC 2.

Your cloud provider is inside the scope whether you like it or not

If your service runs on a hyperscaler, that provider is a subservice organization and the description has to say how it is handled. Two methods exist. Under the carve-out method the subservice organization's controls are excluded from the description and from the auditor's testing, and the description says so. Under the inclusive method they are pulled in and tested, which requires the provider's cooperation and is therefore rare for a major cloud platform.

Carve-out is normal and nobody holds it against you. What people do hold against you is not knowing what it implies. A carve-out report leaves a hole where the infrastructure controls would be, and the reader fills it with the provider's own report. Your description must also state the complementary controls the subservice organization is assumed to be performing, and, separately, the complementary user entity controls your own customers must perform for your controls to work as described.

Read your provider's report before your auditor does. The complementary user entity controls in it are assignments to you, and they are the most common source of a first-year finding. More on that mapping problem in inheriting controls from your cloud provider.

The clause the prime probably meant

Now the part that changes what you buy. On a federal subcontract, the security obligation that binds you comes from a clause flowed down from the prime contract, and those clauses are specific about both the control set and the evidence.

FAR 52.204-21. Basic safeguarding of covered contractor information systems. Fifteen requirements, listed at paragraph (b)(1)(i) through (xv), covering access limitation, media handling, boundary protection, and malicious-code protection among others. Paragraph (c) requires the contractor to include the substance of the clause, including paragraph (c), in subcontracts where federal contract information may reside in or transit through the subcontractor's system. There is no report and no score. It is a set of things you must do.

DFARS 252.204-7012. Safeguarding covered defense information and cyber incident reporting. It requires implementation of NIST SP 800-171, rapid reporting of cyber incidents — defined as within 72 hours of discovery — to DoD at dibnet.dod.mil, and at paragraph (m)(1) requires the contractor to include the clause, including that paragraph, in subcontracts without alteration. A subcontractor submitting a variance request to NIST must notify the prime, and must give the prime the incident report number when it reports.

DFARS 252.204-7020. Most vendors have never read this one, and it is the clause that most often explains a prime's real urgency. It requires assessment summary scores to be posted in the Supplier Performance Risk System, and defines three levels: a Basic self-assessment carrying low confidence, plus government-conducted Medium and High assessments carrying more. Paragraph (g) flows it down. Paragraph (g)(2) is the sentence to know: the prime shall not award a subcontract subject to the implementation of NIST SP 800-171 security requirements unless the subcontractor has completed, within the last three years, at least a Basic assessment for the applicable covered systems.

Read that again. The prime is not permitted to award you the work until a score exists, and no SOC 2 satisfies it, because the artifact the regulation names is a posted score rather than an opinion. When the request lands late in the deal cycle with an urgent tone, this is usually why. A self-assessment posted to SPRS needs no CPA firm at all.

What the buyer needsGoverning authorityArtifact that satisfies itDoes a SOC 2 do it
Basic safeguarding of federal contract informationFAR 52.204-21, flowdown at (c)Implementation of the fifteen listed requirementsNo. Overlaps heavily, tests nothing against the list.
Protection of covered defense informationDFARS 252.204-7012, flowdown at (m)(1)NIST SP 800-171 implementation, system security plan, plan of action, 72-hour reportingNo. Useful supporting evidence for some controls.
Proof of assessment before subcontract awardDFARS 252.204-7020, flowdown at (g); bar on award at (g)(2)An assessment score posted in SPRS within the last three yearsNo. Different issuer, different artifact.
CMMC status on a defense contract48 CFR CMMC rule, effective November 10, 2025; DFARS 252.204-7021 and -7025The level and assessment type the contracting officer specifiesNo.
Selling a cloud service to an agencyFedRAMPA FedRAMP authorization for the offeringNo.
Commercial supplier assuranceThe prime's own vendor-risk policyA current SOC 2 Type 2 scoped to the service being boughtYes. The report's home ground.

Where CMMC stands right now, stated plainly

This one is genuinely in flux, and any vendor being told otherwise should push back. The acquisition-side CMMC rule was published on September 10, 2025 and took effect on November 10, 2025, adding DFARS 252.204-7021 for contracts and DFARS 252.204-7025 for solicitations. Phase 2, which would have required third-party certification from a C3PAO for most contractors handling covered defense information, was scheduled for November 10, 2026.

On July 13, 2026 the Department of War suspended Phase 2 and stood up a reform task force with a sixty-day reporting deadline. During the suspension, contracting officers may include Level 1 and Level 2 self-assessment requirements, and existing contracts carrying a C3PAO or Level 3 assessment requirement are to be amended to remove it. The underlying obligation did not change: DFARS 252.204-7012 is unaffected, and enforcement runs through self-assessments and selected government-led assessments against NIST SP 800-171.

One wrinkle sits in the standard itself. NIST published SP 800-171 Revision 3 as final on May 14, 2024, superseding Revision 2 from January 2021, while defense enforcement during the pause has proceeded against Revision 2. If a prime hands you a spreadsheet of 800-171 controls, ask which revision it reflects before mapping to it. The two do not line up control for control.

The practical read: do not buy a third-party CMMC assessment assuming Phase 2 arrives on the old schedule, and do not treat the pause as permission to stop implementing 800-171. The self-assessment and the score are still the gate. For the level distinction, see our walkthrough of Level 1 versus Level 2.

Adjacent frameworks people confuse with SOC 2

Three come up in nearly every one of these conversations.

FedRAMP is a government authorization for a cloud offering sold to federal agencies, not a commercial audit, and it is mid-reform. Its 20x path and consolidated 2026 ruleset changed how offerings get certified; as of early August 2026 the FedRAMP marketplace listed 529 certified offerings, 28 of them through 20x. A SOC 2 does not shorten that road. If an agency will use your hosted service, the authorization is the requirement and the SOC 2 is supporting material at most. Our comparison of FedRAMP and DoD impact levels covers where each binds.

GovRAMP is what StateRAMP became. The rebrand was announced on February 14, 2025 to reflect participation from local, tribal, and educational entities alongside states; the legal entity remains StateRAMP, operating as GovRAMP. A state or county buyer asking for StateRAMP status means the same program under its former name.

ISO/IEC 27001 is a certification against a management-system standard, issued by an accredited certification body. SOC 2 is an attestation report carrying an auditor's opinion. They overlap in the controls they exercise and differ completely in what the buyer receives. If your customers sit mostly outside the United States, 27001 travels better. If they are American primes and enterprises, SOC 2 is the expected artifact.

Bridge letters, report age, and the renewal treadmill

A SOC 2 Type 2 covers a defined period, which means the report starts aging the day that period ends. The gap between the period end and the buyer's diligence date gets filled with a bridge letter, sometimes called a gap letter. Understand what it is: a letter written by your management asserting that nothing material changed. Your auditor did not write it, did not test it, and expresses no opinion on it. Diligence teams accept bridge letters for short gaps and grow uncomfortable as the gap widens. Treat a long one as a signal that the audit calendar slipped, not as a solution.

The renewal cadence is annual once you start. Budget it as a recurring operating cost rather than a project, and set the observation period so the report lands before your largest customer's renewal review, not after it.

The conversation to have before you sign an engagement letter

Every question below has to be answered by the prime, not guessed at by you. Send them as a short list. A prime that cannot answer them has not thought the request through, which is itself useful information.

  • Which clause is flowing down to us — FAR 52.204-21, DFARS 252.204-7012, DFARS 252.204-7020, a CMMC clause, or none of them?
  • Will federal contract information or covered defense information touch our systems, and if so, which of our systems?
  • Do you need an assessment score posted in SPRS before award, and by what date?
  • Is the SOC 2 request contractual, or is it your vendor-risk team's standard package?
  • Type 2 with what minimum observation period, and which trust services categories beyond security?
  • Which of our services must the system boundary cover?
  • Will a Type 1 plus a dated observation window satisfy you at award, with the Type 2 to follow?

Two of those answers usually collapse the whole problem. If the flowdown is DFARS 252.204-7020, the urgent artifact is a posted score and the SOC 2 can be sequenced deliberately over the following year. If it is the vendor-risk team's standard package with no clause behind it, you are negotiating, and a Type 1 with a running observation window is frequently accepted.

Sequencing it without wasting a year

The order that works is unglamorous. Establish the boundary and the categories first and write them down before talking to auditors, because a firm quoting against a vague scope quotes against the largest plausible one. Run a readiness assessment against the criteria you selected and treat its output as an engineering backlog with owners and dates. Remediate design gaps before the observation window opens, since a control that did not exist for the first two months of the period surfaces in the tests-and-results table for everyone to see.

Pick the observation period against your commercial calendar rather than the auditor's convenience. Short first-year windows are common and legitimate, and a reviewer will notice one, so be ready to say why and to name the longer period that follows. If a federal clause is in play, run the SPRS self-assessment in parallel. It sits on a different track, it is the thing that unblocks award, and it does not wait on the audit.

Frequently asked questions

Does a SOC 2 satisfy NIST SP 800-171 or CMMC?

No. Those requirements name specific control sets and specific evidence — a system security plan, a plan of action, an assessment score posted in SPRS, or a CMMC assessment at the level the contracting officer specifies. A SOC 2 is an opinion by a CPA firm against outcome-based criteria that the service organization maps to its own controls. Work done for one supports the other, but neither substitutes for the other.

Type 1 or Type 2 — which does a prime want?

Type 2, in nearly every case. A Type 2 opines on operating effectiveness throughout a period and includes the auditor's tests and their results; a Type 1 covers design at a point in time with no tests and no effectiveness opinion. A Type 1 is defensible as a first-year stake in the ground when the Type 2 observation window is already running and you say so in writing.

Can we publish our SOC 2 on our website?

Not as such. SOC 2 reports are restricted to specified parties under the attestation standards. The general-use report in the family is SOC 3, which carries an opinion on design and operating effectiveness without the detailed tests and results. Publish a SOC 3 and share the SOC 2 under NDA.

Our platform runs on a hyperscaler. Does their SOC 2 cover us?

No. The provider is a subservice organization in your report, almost always handled by the carve-out method, which excludes their controls from your description and your auditor's testing. Their report covers their layer; yours covers yours. Read their complementary user entity controls first, because those are assignments to you and they are a common source of first-year findings.

What changed with CMMC in July 2026?

The Department of War suspended CMMC Phase 2 on July 13, 2026 and opened a sixty-day reform review. Contracting officers may still require Level 1 and Level 2 self-assessments, and contracts carrying third-party or Level 3 assessment requirements are to be amended to remove them. The underlying DFARS 252.204-7012 obligation is unaffected, and enforcement continues through self-assessments and selected government-led assessments.

1 business day response

A prime asked you for SOC 2 and you need the scope right

We build and operate federal and commercial software with the control work designed in — system boundaries, control mapping, evidence pipelines, and the engineering behind them.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE