Sales & PartnershipsFree
SOC 2 Report Summary for Buyers
Every question this buyer asked, typed by whether your report answers it, excludes it, carves it out, or hands it back to them.
Every guide to summarizing a SOC 2 gives the same three instructions. Lead with the opinion, state the scope, address the exceptions transparently. Follow all three and you produce a document that describes what the report contains, which is the one thing a reviewer can already see from the cover page. River builds the other document. It takes the question list this buyer actually sent and types every question by whether your report can carry it, so the summary answers their form instead of narrating your audit.
Five states, and the count goes on the front page. Answered, and the control drew no exception. Answered, and it did. Out of scope, because the criterion was never examined. Carved out, because a subservice organization sits outside the engagement entirely. And theirs, because the control is one your report expects the buyer to run. That last state is the one no vendor summary volunteers, and it is the one that closes a review rather than starting another thread.
Built for whoever gets the questionnaire forwarded on Thursday and owns the answer by Monday: the security lead, the account executive, the founder who wrote the policies. Reach for it when the report is finished and the buyer wants something shorter than eighty pages. The security questionnaire response pack answers the form itself, the trust package pack governs which document you are allowed to send, and the tool index covers the rest of the review.
Three reasons a clean report still cannot answer the question
Start with what the opinion actually says. Read the model scope paragraph published for service auditor reports and the assurance is conditional. The controls are suitably designed to achieve the stated objectives if those controls were complied with satisfactorily, and user organizations applied the controls contemplated in the design. The second half of that sentence is a list of jobs belonging to the buyer. A summary that quotes the clean opinion and drops the condition is presenting a conditional as an absolute.
Then the carve-out. A service organization choosing that method states that the subservice organization's relevant control objectives and controls are excluded from the description and from the scope of the service auditor's engagement. Most software vendors carve out their hosting provider, so the questions about data centre access, hardware disposal and hypervisor patching are answered by a report that is not yours. Naming the provider and its report costs you nothing. Letting a reviewer hunt for controls that were never in the file costs a week.
Third, the reviewer is following instructions. When four federal banking agencies set out how to evaluate a third party, they told firms to weigh whether the scope and the results of the SOC reports, certifications, or assessments are relevant to the activity to be performed. Relevance to the activity, not the existence of a report. A summary organized around your control list leaves that mapping to them. A summary organized around their question list has already done it.
How it works
Paste the report
The whole document or the sections you have. Partial reports work and the missing parts get flagged.
Add their questions
Their questionnaire, their spreadsheet or their email. Whatever form the ask actually arrived in.
River types the rows
Each question against the opinion, the criteria examined, the carve-outs and the user entity controls.
Send the summary
One document leading with the exceptions, closing with the five things the buyer has to do.
What you get
- Every buyer question typed answered, excepted, out of scope, carved out, or theirs to run
- The complementary user entity controls pulled out and rewritten as the buyer's own task list
- Each exception stated with its sample size, its cause and what management did next
- Carved-out subservice organizations named, with the report the buyer should go and ask for
- A count on the first page of what this report covers and what it will never cover
- Two versions of the summary: one safe to send before an NDA, one for after
Common questions
What does it need from me?
Your report and their questions. The report matters most in the parts nobody reads: the system description, the carve-out language and the user entity controls at the back. Their questions can arrive as a spreadsheet, an email or a portal export. Anything you already promised this buyer is worth adding, because the summary has to survive contact with it.
Why would I tell a buyer what my report does not cover?
Because they are going to find out, and the order matters. A reviewer who reaches the scope section and discovers Availability was never examined stops trusting the twenty-four answers they already read. A reviewer who was told on page one spends their time on the nine real questions instead of auditing your summary for what else it left out.
Is leading with the exceptions actually a good idea?
Yes, and not for the reason usually given. Volunteering them is not a trust gesture. It is the only way to control how they are read. Two of forty sampled changes missing an approver, both from one on-call engineer during one incident, is a very different fact from two exceptions found somewhere in ninety-six controls.
We only have Security in scope. Does that sink us?
Rarely, if you say so early and say where the answer does come from. Recovery time lives in the contract, not the audit. Uptime lives in your status history. The summary routes each out-of-scope question to the artifact that does answer it, so a narrow report reads as a scoped one rather than an evasive one. The gap brief says whether this buyer must ask about what is missing.
What if they have not signed an NDA yet?
Then you get the pre-NDA version, which carries the criteria examined, the opinion type, the period and the user entity control list, and holds back the tested control detail and the exception specifics. The trust package pack is what decides which tier a given buyer sits in and records what you sent them.
How does this sit alongside the questionnaire itself?
The summary is the covering document, not the answers. When the buyer's form has to be filled in row by row, the security questionnaire response pack does that and tracks which answers you can actually evidence. This tool tells you which of their rows the audit report was ever capable of supporting.
The security review is holding up the deal. Does this help?
It helps by converting an open review into a finite list. Nine questions for you and five for their access team is a workstream someone can own and date. Put those rows on the mutual action plan with names against them and the review stops being the reason the close date keeps moving.
SOC 2 Report Summary for Buyers
Fill in the form and your workspace opens with the work already underway.