Skip to content
Cogio
Security· 9 min read· by Alexandre Sauvageau

SOC 2 Type II: reading a vendor report without being sold a story

SOC 2 explained for Quebec executives: the AICPA attestation report, Type I versus Type II, how to read a report, and its limits against the CLOUD Act.

Rack-mounted servers in a data centre
Photo: Panumas Nikhomkhai, Pexels

An attestation report, not a certification

Your cloud vendor displays “SOC 2 certified” on its home page, blue badge and all. One small detail: SOC 2 certification does not exist. SOC 2 is an attestation report governed by the AICPA, the American institute of certified public accountants. An independent CPA firm examines the vendor’s controls, then expresses a professional opinion in a document that often runs to dozens of pages. Nobody awards a seal, nobody “passes” SOC 2: you obtain a report, with its strengths and its reservations.

The distinction is not pedantry. A certification such as ISO 27001 produces a public certificate, valid for a set period. A SOC 2 report is a confidential document the vendor hands over on request, usually under a non-disclosure agreement. It describes the system audited, the controls tested, the test results and the exceptions noted. That level of detail is exactly what makes it useful: the badge on the website tells you nothing, the full report tells you everything. A public, summarized version does exist, called SOC 3, and it is rarely enough for a business decision.

In practice, if you run IT at an SME in Granby and you are shopping for cloud payroll software, the right question is not “do you have SOC 2?” but “can you send me your most recent SOC 2 Type II report?” The reaction is already telling: a serious vendor has an established process for sharing it.

The five trust services criteria

The report assesses the vendor’s controls against the trust services criteria defined by the AICPA. There are five of them.

What many executives do not realize: only the security criterion is mandatory. The other four are optional, at the vendor’s discretion. A SOC 2 report can therefore be perfectly genuine while covering neither confidentiality nor privacy. Before you feel reassured, check which criteria are in scope: for an AI tool processing your clients’ or your employees’ personal information, a report limited to security leaves large blind spots.

5

trust services criteria defined by the AICPA

1

the only mandatory criterion in any SOC 2 report: security

  • Security: protection against unauthorized access, physical and logical. This is the foundation of the framework, also called the “common criteria.”
  • Availability: the service stays accessible and operational in line with the commitments made.
  • Processing integrity: data is processed completely, accurately and in a timely way.
  • Confidentiality: information designated as confidential (contracts, pricing, intellectual property) is protected against disclosure.
  • Privacy: personal information is collected, used, retained and destroyed in line with the vendor’s commitments.

Type I or Type II: the photograph and the film

A Type I report answers the question: were the controls well designed on such-and-such a date? That is a photograph. The auditor observes that the policies exist, that encryption is configured and that access is documented, on one particular day. A Type II report answers a far more demanding question: did those controls actually operate throughout the observation period, generally 3 to 12 months? That is a film. The auditor tests samples of logs, access requests and incident reports to check that each control was carried out week after week.

The practical difference is enormous. A company can obtain a Type I in a few weeks with impeccable documentation and an embryonic implementation. Type II does not take makeup: if the quarterly access review never happened, the exception appears in the report. That is why Type II is the only report that attests how the controls really worked. When a vendor stays vague about which type it holds, prudence says assume Type I, or an audit still in progress.

3 to 12 months

typical length of a Type II observation period

A photograph shows the door was locked that day. A film shows it stayed locked for months. For your data, ask for the film.
Type I and Type II at a glance
AspectSOC 2 Type ISOC 2 Type II
Question askedAre the controls well designed?Did the controls operate?
Time coverageA single moment (a specific date)A continuous period of 3 to 12 months
What the auditor testsDesign and implementationDesign and operating effectiveness
Evidentiary weightLow: a well-framed photographHigh: a verified track record
Reasonable useA young company awaiting its first Type IIThe normal requirement for sensitive data

Four checks before you file the report away

Receiving the report is only half the work. A controller handed an 80-page PDF instinctively files it and ticks the “vendor audited” box. Resist: four checks take less than an hour and often change the conclusion.

Those four readings turn a marketing badge into management information, and they document your diligence if an incident happens at the vendor.

  • The period covered. A Type II that ended 18 months ago says nothing about today. Insist on a period that closed less than 12 months ago; for the remaining gap, ask for a bridge letter.
  • The auditor’s opinion. It can be unqualified, qualified or adverse. A qualified opinion signals that some controls did not operate as intended; you need to check which ones and judge whether your data is affected.
  • The exceptions. The test results section lists the deviations found. Minor exceptions are normal; exceptions on access management or incident response, far less so.
  • The subcontractors. Most reports use the carve-out method: the vendor’s host, often a cloud giant, is excluded from scope. The report then attests the vendor’s controls, not the whole chain’s. Also check the complementary user entity controls: the report assumes you do your part, for example managing your own user accounts.

SOC 2 or ISO 27001: two answers to two different questions

Both frameworks come up constantly in tenders, and they are often confused. ISO/IEC 27001 certifies an information security management system (ISMS): the organization has put governance, risk management and continuous improvement in place, verified by an accredited certification body on a 3-year cycle with annual surveillance audits. SOC 2, for its part, produces a detailed opinion on specific controls applied to the data clients entrust to the vendor, observed over a given period.

Neither is “better”: they answer different questions. ISO 27001 says “this vendor manages security in a structured way”; a SOC 2 Type II says “here is the detailed evidence that its controls operated from this date to that date.” Mature vendors often hold both. To assess a processor that will host your data, the SOC 2 Type II report is the richest document to read; the ISO 27001 certificate is the simplest signal to verify.

SOC 2 and ISO 27001 compared
CriterionSOC 2ISO/IEC 27001
NatureAttestation report (a CPA firm’s opinion)Certification by an accredited body
FrameworkAICPA trust services criteriaISO/IEC international standard
SubjectControls over data entrusted to the vendorThe security management system (ISMS)
Time horizonObserved period (Type II: 3 to 12 months)3-year cycle, annual surveillance
Document providedDetailed confidential report (under agreement)A one-page public certificate
Market footingNorth AmericaInternational

What SOC 2 does not tell you

Even the most favourable report is silent on three matters that weigh heavily in Quebec. First, jurisdiction. SOC 2 assesses controls, not laws. An American-owned vendor can hold a flawless Type II and remain subject to the CLOUD Act, the 2018 American statute that lets US authorities demand data even when it is stored in Canada. The physical location of the servers is no protection: what counts is the owner’s jurisdiction, and no audit changes that reality.

Second, AI model training. The report attests controls against the commitments the vendor describes; if those commitments say nothing about using your data to train its models, the report will say nothing either. Yet under Law 25, reusing personal information to train a model amounts to a new purpose that needs its own legal basis. The no-training guarantee has to be in the contract, in black and white, not inferred from a logo.

Third, your own legal obligations. Law 25 requires you to govern your processors by contract (section 18.3) and to carry out an assessment before any disclosure of personal information outside Quebec (section 17). A SOC 2 report is excellent material to file with that assessment, but it does not replace it. The auditor never claimed to check your Quebec compliance.

When to require a SOC 2 report, and what to accept instead

Require a recent SOC 2 Type II as soon as a vendor hosts or processes personal information, financial data or trade secrets on your behalf: SaaS platforms, AI tools, payroll services, hosts, IT subcontractors. In a tender, specify “Type II,” the minimum period expected and the trust services criteria required, otherwise you will harvest ambiguous answers.

Stay proportionate, though. A SOC 2 Type II audit is expensive in time and fees; your 12-person regional integrator probably will not have one, and that is not necessarily disqualifying. Alternatives exist: a detailed security questionnaire, solid contractual clauses (data residency, incident notification timelines, no training, reversibility), a right to audit, or an architecture that avoids the transfer altogether. That is the logic of sovereign hosting: when the AI and the data stay inside your environment, the vendor’s audit report loses much of its weight.

For transparency: Cogio holds no SOC 2 report and claims no certification. What we deliver instead is a timestamped evidence register (audit logs, flow mapping, documented decisions) that belongs to the client, and we apply the reading grid described here to our own suppliers.

Where to start with your current vendors

Draw up the list of vendors that touch personal information or strategic data: the register Law 25 requires already gives you most of it. For each one, ask for the most recent SOC 2 Type II report, apply the four checks (period, opinion, exceptions, subcontractors) and record the outcome. The holes you find (expired reports, Type I presented as certification, hosts carved out of scope) become negotiating points at the next renewal.

If you would rather have an outside eye, our approach starts with exactly that kind of audit of data flows and vendors, with a Law 25 grid built in. You come away with a clear picture and precise questions to put to each vendor. The 12-step compliance checklist is also a good starting point for placing third-party assessment among all your obligations.

Frequently asked questions

Is a SOC 2 report mandatory for vendors in Quebec?

No. No Quebec law requires SOC 2. Law 25 does require you to govern your processors by contract (section 18.3) and to assess any disclosure of personal information outside Quebec (section 17). A SOC 2 Type II report is a recognized way of documenting that diligence, not an obligation in itself.

Can a company be described as “SOC 2 certified”?

Technically, no. SOC 2 is an attestation report issued by a CPA firm against the AICPA criteria; there is no SOC 2 certificate and no SOC 2 certification body. The phrase circulates in marketing, but a rigorous vendor speaks of its “SOC 2 Type II report” and shares it under a non-disclosure agreement.

What is the difference between SOC 2 Type I and Type II?

Type I assesses the design of the controls on a specific date: a photograph. Type II verifies their operating effectiveness over a continuous period, generally 3 to 12 months: a film. Only Type II attests that the controls really operated, which makes it the benchmark requirement for sensitive data.

How long does a SOC 2 Type II report stay relevant?

The report has no official expiry date, but it only covers the period observed. In practice you should require a report whose observation period ended less than 12 months ago. To bridge the gap between the end of the period and today, ask for a bridge letter signed by the vendor.

Is a SOC 2 Type II enough to comply with Law 25?

No. The report documents the vendor’s controls, but it replaces neither your assessment before a disclosure outside Quebec (section 17), nor your processor contract (section 18.3), nor your privacy impact assessment where one is required. It also says nothing about the vendor’s jurisdiction, and therefore nothing about its exposure to the CLOUD Act.

What should we do if a vendor only offers a Type I report?

Ask when its first Type II will be available: a serious company mid-audit can give you a date. In the meantime, compensate through the contract: precise security clauses, incident notification timelines, a right to audit and limits on what data you actually send. For highly sensitive information, waiting for the Type II or choosing an architecture with no transfer remains the prudent path.

Sources and references

This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.