Your US client asks for "SOC 2 Type II." The host sends a "SOC 2 compliant" page without report. You sign. Client audit requires full report: scope "corporate SaaS platform US" — not EU VPS offer. Valid Type II; it does not describe your service.
SOC 2 = independent auditor report on controls related to Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) — on a limited described system.
What the report can tell you
- Operational controls tested over period (Type II).
- Exceptions and management responses — where it failed.
- System scope (infrastructure, data centers, services).
- Material subservice organizations.
What it cannot tell you
- Global GDPR compliance.
- Security of your configuration (OS, app).
- Automatic coverage of all commercial offers.
- Details without NDA (often).
| Document | Value |
|---|---|
| SOC logo | Low |
| Bridge letter | Medium if scope clear |
| Full Type II (NDA) | High |
| ISO 27001 + SOC 2 | Complementary if scopes aligned |
Bridge letter and carve-outs
Letter to customers summarizes scope for clients without NDA. Check carve-outs ("shared hosting not in scope").
The peak: a useful foreign report is read in exclusions
Decide and move forward without blind spots
- Require bridge letter or NDA report.
- Compare scope to contractual product.
- Read Type II exceptions — not only clean opinion.
- Complete GDPR: DPA, ISO scope, TIA.
Frequently asked questions
SOC 2 = ISO 27001?
No — US attestation vs ISMS certification. Complementary.
Type I vs II?
I = design; II = effectiveness over period — prefer II.
Public report?
Rare — NDA or bridge letter.
SOC 2 = GDPR?
No — DPA + TIA still required.
SOC 2: a foreign report is worth what its scope is worth — not the badge on the site.
