What your customer's reviewer checks
A first-pass vendor review takes about fifteen minutes. Four things decide it, and none of them is the control matrix you spent four months building.
The person reviewing you at your customer opens the auditor's opinion first, then the scope and the period covered, then the exceptions, then the complementary user entity controls. That is roughly fifteen minutes, and it decides most vendor reviews. The control matrix you spent months producing gets skimmed. A clean opinion covering the wrong system is worth less to them than a qualified opinion covering the right one.
15 min Typical first pass over a report
4 Sections that decide most reviews
The order they read it in
- The opinion. Unqualified, qualified, adverse or a disclaimer. They are looking for the word, not the paragraph. A qualified opinion does not end the review, it starts a different conversation about what was qualified and whether it touches them.
- The scope and the system description. Is the product they are buying inside the boundary. This is where Canadian vendors most often fail a review with a good report: it covers the platform, and the buyer is purchasing a module that was carved out.
- The period covered. A Type 2 period that ended seven months ago is stale, and they will ask for a bridge letter to cover the gap. A Type 1 gets a note in their file and a question about when the Type 2 lands.
- The exceptions. They read what was excepted, whether management responded, and whether the exception touches the control they care about. Two minor exceptions with clear responses read better than none. None can read as an audit that did not look hard.
- The complementary user entity controls. These are the controls the report says are the customer's job. A careful reviewer checks whether their own organisation can perform them. An unreasonable list is a real objection, not a formality.
Reading it from their side is the fastest way to understand this, and how to read a SOC 2 report walks the same document as a buyer. Why the reviewer is doing any of it is on why your customer is asking, and it is not because they wanted to.
What makes a reviewer stop and escalate
| What they find | What happens next |
|---|---|
| The purchased product is outside the report scope | The review effectively restarts. They now need assurance on a system nobody audited |
| The period ended more than six months ago with no bridge letter | Held until you provide one, which your auditor can usually issue quickly |
| An exception in access control or change management | Escalated to their security team, with follow-up questions about remediation dates |
| Subservice organizations carved out without explanation | Questions about what your cloud provider is responsible for and what you are |
| Complementary user entity controls their side cannot perform | A contractual conversation, sometimes a compensating control on their end |
| The report says "SOC 2 certified" anywhere | Credibility damage out of proportion to the error. Reports do not say this, so it means somebody wrote a summary that is wrong |
| No penetration test mentioned anywhere in the package | A direct request for one, usually in the same message |
What they ask for besides the report
The report answers question one, and ten to fifteen more follow that your audit did not produce. Expect the penetration test summary, a current vulnerability scan, proof of cyber insurance, your subprocessor list, a data flow diagram, your breach notification commitment in hours, and where data physically resides. For a Canadian vendor selling into a US enterprise that last one is rarely a single question. The whole package is on what a US buyer asks for besides SOC 2.
The pack to have ready before you are asked
Assemble this once and the review moves from three weeks to one. Every item is something a reviewer requests within the first two rounds.
0 of 0 ready ·
Send the scope note unprompted
The one-page scope note is the highest-return item on that list. Most escalations here come from a reviewer being unable to tell whether the thing they are buying is inside the report, and reading a system description to find out is slow. One paragraph naming the products, the environments and the cloud regions removes the most common reason a good report gets held up.
If there is no report yet
The same reviewer, given a questionnaire instead, reads it for internal contradictions rather than for perfect answers. An honest "no, and here is our compensating control with a date" scores better than a yes that the next question contradicts. What to send in place of a report, and what buyers accept, is on what to offer instead of a SOC 2 report.
Does the reviewer read the whole control matrix?
Rarely on a first pass. They read the opinion, scope, period, exceptions and the complementary user entity controls. The matrix gets read when something in those five raises a question.
Are exceptions in a report a problem?
Usually not by themselves. Reviewers expect a first-year report to contain one or two. What matters is whether the exception touches a control they depend on and whether management responded with a date. A report with no exceptions and a very narrow scope reads worse.
How current does the report have to be?
Most buyers want a period that ended within the last twelve months, and they ask for a bridge letter once more than about three months have passed since the period end. Beyond twelve months they generally want the next report.
Can we send the report without an NDA?
You can, and most companies do not. The report describes your controls in detail and is normally shared under the confidentiality terms already in the contract or a short NDA. Requiring one is standard and does not slow a review.
What if the reviewer asks about PIPEDA?
Answer it separately. A SOC 2 report says nothing about Canadian privacy obligations, and conflating the two is a mistake a careful reviewer will catch. Have a short written statement of your PIPEDA position, and a Law 25 one if you handle personal information in Quebec, covered on SOC 2 and Law 25.
Get the pack ready before the review
The evidence tracker keeps the artifacts a reviewer asks for in one place.
Open the tracker