Compliance
SOC 2 document management controls
SOC 2 is an attestation report describing how a service organisation meets the AICPA trust services criteria for security, availability, processing integrity, confidentiality and privacy. For a document management system it evidences access control, change management, monitoring and incident response over a defined observation period.
What a SOC 2 report actually is
SOC 2 is an attestation report produced by an independent accounting firm, describing how a service organisation meets the AICPA trust services criteria. It is not a certification and there is no pass mark — the report describes controls, tests them, and records any exceptions found. Reading the exceptions is the point; a buyer who only checks that a report exists has not used it.
Type I describes controls at a point in time. Type II tests whether they operated over a period, usually six or twelve months, and it is the one enterprise buyers ask for. A Type I report is a reasonable interim answer for a younger company and should be described as such rather than presented as equivalent.
Five trust services criteria exist: security, availability, processing integrity, confidentiality and privacy. Security is common to every report; the others are included by choice. A report covering security alone is normal, and a vendor should tell you which criteria are in scope rather than letting you assume all five.
What each criterion means for a document system
| Criterion | What it covers | Why it matters here |
|---|---|---|
| Security | Protection against unauthorised access, disclosure and damage | The baseline. Covers access control, authentication, change management, monitoring and incident response — the controls that decide whether your documents stay yours. |
| Availability | The system is available for operation and use as committed | Relevant if you have an uptime commitment or if document retrieval is time-critical, such as answering a statutory disclosure deadline. |
| Processing integrity | Processing is complete, valid, accurate, timely and authorised | Relevant where documents are generated or transformed — OCR, template generation, AI extraction — and the output is relied upon. |
| Confidentiality | Information designated confidential is protected as committed | Directly relevant. Most document repositories hold material that is confidential by contract as well as by policy. |
| Privacy | Personal information is collected, used, retained and disposed of as committed | Relevant where documents contain personal data, which for HR, healthcare, legal and education is almost all of them. |
How to read a SOC 2 report properly
- Section IV, the testing detail — this is where exceptions are recorded, and exceptions are the informative part of any report
- The observation period, and whether it is current. A report covering a period that ended fourteen months ago tells you about a system that has since changed
- The scope statement: which systems and which criteria are covered, and equally which are not
- Complementary user entity controls — the things the report assumes you do. These are obligations transferred to you, and they are routinely ignored
- Sub-service organisations, and whether they are carved out or included. A carve-out means their controls are not tested in this report
- The auditor’s opinion: unqualified, qualified, adverse or disclaimer. A qualified opinion is not disqualifying but requires an explanation
FAQ
SOC 2 questions
Can we see your SOC 2 report?
No Type II report has been issued yet, so there is nothing to send and we will not imply otherwise. What we do share under a mutual NDA is the control matrix mapped to the Security and Confidentiality criteria, our most recent penetration test summary, and a completed CAIQ or your own questionnaire. Ask your account contact and the pack goes out within 2 business days.
Do you have a bridge letter?
Not applicable while no Type II report exists — a bridge letter covers the gap between a report’s observation window and the present, so there is no gap to bridge yet. Once a report is issued we will provide a bridge letter on request, which is the standard ask in any procurement running more than a few months after the report date.
Is SOC 2 better than ISO 27001?
They answer different questions. ISO 27001 certifies that a management system exists and is being run; SOC 2 describes and tests specific controls over a period and reports the exceptions. Many organisations require both. If you can only ask for one, ask for the one your own auditors understand best.
What if you do not have a report yet?
Then a credible answer is a stated intention with a date, plus evidence of the underlying controls — access reviews, change management records, incident response procedure, penetration test summary. Those are the substance a SOC 2 report describes, and a young vendor can show them directly.
Última revisão: 2026-09-01