Independent comparison · no paid rankings
Home / Blog / Compliance / SOC 2: what a foreign report can—and cannot—tell you

SOC 2: what a foreign report can—and cannot—tell you

Type II SOC 2 reassures a US client — but the report is under NDA, scope often excludes your shared offer, and criteria do not replace GDPR.

Hébergeurs.eu Editorial Team 2 min read Updated Jul 19, 2026

Your US client asks for "SOC 2 Type II." The host sends a "SOC 2 compliant" page without report. You sign. Client audit requires full report: scope "corporate SaaS platform US" — not EU VPS offer. Valid Type II; it does not describe your service.

SOC 2 = independent auditor report on controls related to Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) — on a limited described system.

What the report can tell you

  • Operational controls tested over period (Type II).
  • Exceptions and management responses — where it failed.
  • System scope (infrastructure, data centers, services).
  • Material subservice organizations.

What it cannot tell you

  • Global GDPR compliance.
  • Security of your configuration (OS, app).
  • Automatic coverage of all commercial offers.
  • Details without NDA (often).
DocumentValue
SOC logoLow
Bridge letterMedium if scope clear
Full Type II (NDA)High
ISO 27001 + SOC 2Complementary if scopes aligned

Bridge letter and carve-outs

Letter to customers summarizes scope for clients without NDA. Check carve-outs ("shared hosting not in scope").

The peak: a useful foreign report is read in exclusions

Decide and move forward without blind spots

  1. Require bridge letter or NDA report.
  2. Compare scope to contractual product.
  3. Read Type II exceptions — not only clean opinion.
  4. Complete GDPR: DPA, ISO scope, TIA.

Directory, guides.

Frequently asked questions

SOC 2 = ISO 27001?

No — US attestation vs ISMS certification. Complementary.

Type I vs II?

I = design; II = effectiveness over period — prefer II.

Public report?

Rare — NDA or bridge letter.

SOC 2 = GDPR?

No — DPA + TIA still required.


SOC 2: a foreign report is worth what its scope is worth — not the badge on the site.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →