What a US buyer asks for besides SOC 2
The report gets you into the review, not through it. Budget two to six weeks and eleven documents, most of which are not produced by your audit.
A US enterprise security review asks for the SOC 2 report in question one and then asks for another ten to fifteen things your audit did not produce. Typically: the penetration test report, a current vulnerability scan, evidence of cyber insurance, your subprocessor list, a data flow diagram, your incident notification commitment in hours, proof of where data physically resides, a completed questionnaire on a template you have never seen, and a security addendum with terms that outrun anything in your SOC 2 scope. For a Canadian company selling into a US enterprise for the first time, plan on two to six weeks of elapsed time from report delivery to security sign-off.
2 to 6 weeks Report delivered to security sign-off
150 to 400 Questions in a large-enterprise questionnaire
24 to 72 hours Breach notification commonly demanded in the addendum
What does the reviewer actually read in the report?
Not all of it. A security reviewer working through a queue reads four things, in this order, and forms a view before reaching section four.
- The opinion paragraph. Unqualified or not, and the date range. A report whose period ended eight months ago gets a bridge letter request before anything else.
- The scope statement, checked against what they are buying. If they are buying your enterprise tier and the report covers the platform generally, they will ask which systems that includes.
- The exceptions table in section four. Every exception generates a question, and a management response written in the report answers most of them before they are asked. Reports with no management responses generate calls.
- The complementary user entity controls. The list of things the report says the customer has to do. A sophisticated reviewer reads it to find out what you are pushing onto them.
The Trust Services Categories you selected matter here too. A security-only report is normal and accepted. Where a buyer stores regulated data with you and your report has no confidentiality or availability criterion, expect that to become a question rather than a rejection.
The eleven artifacts asked for beyond the report
| Artifact | Produced by your SOC 2? | Typical lead time if you do not have it |
|---|---|---|
| SOC 2 Type 2 report, current period | Yes | Months |
| Bridge letter covering the gap since the period end | No, you write it | A day |
| Penetration test report, within 12 months | No | 4 to 8 weeks |
| Recent vulnerability scan output | Partly | Days |
| Cyber liability insurance certificate, often $2,000,000 CAD or more | No | 2 to 4 weeks |
| Subprocessor list with locations | No, though your vendor register feeds it | Days |
| Data flow diagram showing where customer data goes | No, though the system description feeds it | Days |
| Business continuity and disaster recovery plan with tested RTO and RPO | Only if availability was in scope | 2 to 6 weeks |
| Completed questionnaire on their template, often CAIQ or SIG | No | 1 to 3 weeks the first time |
| Security addendum or DPA, signed | No | 2 to 8 weeks with legal |
| Evidence of background screening for staff with data access | Partly | Weeks, and see the Canadian note below |
Six of the eleven have a lead time longer than the deal cycle usually allows. That is why security reviews stall. Produce the bridge letter, the subprocessor list and the data flow diagram before you are asked: all three are a day of work and all three arrive in the first email.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What is different because you are Canadian?
- Data residency comes up whether or not it should
- US buyers in regulated sectors ask where the data lives. A Canadian region is a selling point or an obstacle depending on whether they have a US-only requirement of their own. Have an answer for primary storage, backups, logs and support access: those four often differ, and only the first is usually documented.
- Background checks work differently and reviewers do not know that
- Canadian criminal record checks are consent-based and provincially administered, and there is no direct equivalent of the US county-level search a template asks for. Answer with what you do run and why, rather than leaving the field blank. A blank field reads as no screening.
- The privacy law they name is probably not yours
- Questionnaires ask about CCPA, HIPAA and state breach statutes. If you hold personal information about Canadians you are also under PIPEDA and possibly Quebec Law 25, which is stricter than most of what the form asks about. Saying so is a stronger answer than saying not applicable.
- Cross-border transfer works both ways
- They will ask about their data coming to Canada. Under PIPEDA a transfer for processing does not require consent, but accountability stays with the organization that transferred it, and that framing is what a reviewer wants written down.
- Insurance limits are quoted in the buyer's currency
- A contract requiring $5,000,000 of cyber liability usually means USD. Check before your broker binds a CAD policy at the same number.
Which contract terms actually bite?
| Term | What is commonly asked | What to push back on |
|---|---|---|
| Breach notification | 24 hours from discovery | Ask for 72 hours from confirmation, and define confirmation. 24 hours from discovery starts a clock before you know what happened |
| Audit rights | On-site audit on 30 days notice, annually | Offer the SOC 2 report plus a questionnaire in lieu, which most buyers accept if it is written in |
| Subprocessor change notice | Prior written consent | Ask for notice with a right to object, since consent gives one customer a veto over your architecture |
| Data deletion | Within 30 days of termination, certified | Agreeable, but carve out backups with a stated expiry, because backup deletion on demand is usually a lie |
| Penetration test cadence | Annual, report shared | Agreeable. Share the summary rather than the full findings |
| Liability for a security incident | Uncapped, or a super-cap | The real negotiation. It is a commercial term dressed as a security one |
| Right to require remediation | Fix critical findings in 30 days | Tie it to your own severity definitions, or you inherit theirs |
How do we get ahead of this?
Build the pack once. Everything below is reusable across every review, and assembling it takes a week if the SOC 2 work is done. Most of it restates things the audit already made you write.
0 of 0 done ·
The order the reviewer opens things in tells you which items to send unprompted, and what your customer's reviewer checks walks the report and the pack the way they read it.
Is a security review a reason to buy more compliance?
Usually not. Most of the eleven artifacts above are documents rather than programs, and the two that are programs, the penetration test and the continuity plan, are things you needed anyway. Adding ISO 27001 or a second Trust Services Category because one reviewer asked a hard question is an expensive answer to a question about a missing diagram.
The exception is when the same request arrives from three different buyers. Three independent asks is a market signal, not one reviewer's habit, and that is the point to consider adding a framework or expanding scope. Until then, close the gap with a document.
Will a SOC 2 Type 1 pass a US enterprise security review?
Sometimes, once. A Type 1 with a stated date for the Type 2 is commonly accepted by mid-market buyers and by enterprises where the deal has executive support, and it is commonly rejected by financial services and healthcare buyers whose vendor policy names Type 2. Ask the champion which policy applies before you buy a Type 1 to solve a deal.
How long is a SOC 2 report valid for a US buyer?
There is no expiry in the standard, but the working convention is twelve months from the period end, with a bridge letter covering the months since. Past twelve months most reviewers ask for the next report rather than another bridge letter.
Do we need a US entity to sell to US enterprises?
No. Procurement occasionally asks, and the question is about tax and contracting rather than security. What does come up is which law governs the contract and where disputes are heard, and those are negotiated terms rather than a reason to incorporate.
What is a bridge letter and who writes it?
You write it, on your letterhead, signed by an officer. It states that no material changes to the control environment occurred between the end of the report period and the date of the letter, and it names any that did. Your auditor does not issue it and should not be asked to. What goes in one is on the bridge letter page.
Can we refuse to answer a questionnaire and just send the report?
You can try, and with mid-market buyers it often works if you offer a mapping from their questions to report sections. With enterprises the questionnaire is a workflow in a tool and the reviewer cannot skip it, so refusing costs you the reviewer's goodwill rather than the questionnaire. Keep a completed CAIQ and the work drops to a few hours.
Get help assembling the pack
Tell us which report you hold and which buyer is asking. Canadian firms that do this work will quote on the gaps rather than on a full program.
Get matched