Your SOC 2 auditor will ask how you reviewed your vendors. Here is where 30 common startup vendors publish their SOC 2 report, who can download it, and what to check once you have it.
If you are preparing for SOC 2, sooner or later your auditor asks how you reviewed the vendors that touch customer data. The usual evidence is each vendor's own SOC 2 report, plus a short record of what you checked in it.
Getting the reports is fiddlier than it should be. Some live in a console, some behind a trust-center request form, and some only on certain plans. A few examples, each checked on the vendor's own pages:
- AWS: download from AWS Artifact in the console, at no charge; an NDA acceptance applies.
- Google Cloud / Google Workspace: Compliance Reports Manager, after signing in.
- Vercel: request access through the Vercel Trust Center.
- Supabase: Team and Enterprise plan customers download it from the organization dashboard.
- GitHub: Enterprise Cloud owners, from the Compliance tab in enterprise settings.
- Cloudflare: Super Administrators, from Compliance Documents in the dashboard, after a confidentiality statement.
- Stripe: provided on request.
The full table of 30 vendors (Azure, Microsoft 365, Okta, Auth0, Datadog, Sentry, PagerDuty, OpenAI, Anthropic, MongoDB Atlas, Snowflake, Notion, Linear, Slack, HubSpot, Zoom, 1Password, Heroku, Netlify and more) is here, with links to each trust page:
https://policyseed.vercel.app/guides/vendor-soc-2-reports
Downloading the PDF is not the review
Read these six parts and write down what you found:
- Type and period. A Type II covers a period of operation; a Type I is a single date. If the period ended long ago, ask for the newer report or a bridge letter.
- Scope. Make sure the system description covers the product you actually use. Big vendors publish several reports.
- The auditor's opinion. Unqualified is the expected result. A qualified opinion means a material problem: read which criterion and why.
- Exceptions in the test results. A clean opinion can still come with individual deviations. Decide whether any affect how you use the vendor.
- Complementary user entity controls. What the vendor expects you to do: enable MFA, manage your own users, configure encryption. Those become your controls.
- Subservice organizations. The vendor's own vendors (often a cloud provider), usually carved out. Note them as fourth parties.
Record the date, the report period, the reviewer, any exceptions and your decision. That record, not the PDF, is what the auditor samples.
Keep it proportionate
A small company can easily use dozens of SaaS tools, and not all of them need a SOC 2 review. Tier vendors by the data they touch: the ones that store or process customer data get a full review with the report; tools with no customer data get a short documented check. Auditors look for a consistent rule applied to the whole inventory.
If you need the policy that sets those tiers and the review cadence, there is a free, editable Vendor and Third-Party Risk Management Policy template (Word or Markdown, no signup) at https://policyseed.vercel.app/policies/vendor-and-third-party-risk-policy. It is part of an open-source (Apache-2.0) set of 22 SOC 2 policies; I built it.
Top comments (0)