Skip to content

SOC 2 Report Structure

 

Learn about Section 1, Section 2 & Section 3 in a SOC 2 Report, Complementary User Entity Controls (CUECs) in SOC 2, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization. 

Table of Contents

What does Section 1 of a SOC 2 Report contain? 

 

Section 1 contains the Independent Service Auditor’s Report, the CPA’s formal opinion letter. It states the auditor’s professional opinion (unqualified, qualified, adverse, or disclaimer of opinion), identifies which Trust Services Criteria were examined, describes the scope and period covered, and summarizes the auditor’s methodology and conclusion. Section 1 is what procurement teams, compliance officers, and auditors read first. The opinion type stated here determines whether the report serves its intended commercial and compliance purposes. 

 

What does Section 2 of a SOC 2 Report contain? 

 

Section 2 contains the Management Assertion, the organization’s formal written statement that the system description is accurate and complete, and that controls are suitably designed and/or operating effectively to meet the applicable Trust Services Criteria. This section carries management’s direct accountability for the accuracy of what is attested in the report. It is a required component in every SOC 2 Report, Type 1 and Type 2, and cannot be omitted. 

 

What does Section 3 of a SOC 2 Report contain? 

 

Section 3 contains the System Description, a detailed account of the services, infrastructure, software, personnel, procedures, and data covered by the examination. It defines the scope boundary, identifies sub-processors and their inclusion method (carve-out or inclusive), and lists the Complementary User Entity Controls (CUECs), the controls that customer organizations are responsible for implementing. Buyers reviewing a vendor’s report must read Section 3 carefully to understand what the examination actually covers, which sub-processors are excluded from scope, and what security responsibilities remain with their own organization. 

 

What does Section 4 of a SOC 2 Report contain? 

 

Section 4 contains the Control Testing Results. In a Type 1 Report, it documents whether controls are suitably designed. In a Type 2 Report, it documents the specific tests performed by the auditor, the samples examined, the observation period covered, any exceptions or deviations identified, and the auditor’s conclusions about operational effectiveness over time. Section 4 is where procurement teams, regulators, and B2B auditors apply the most scrutiny, it is where the substantive evidence of the entire examination is recorded and where any exceptions are documented with full context.

 

What are Complementary User Entity Controls (CUECs)? 

 

Complementary User Entity Controls (CUECs) are security controls that a vendor’s SOC 2 Report explicitly identifies as the customer organization’s responsibility to implement. Many controls only function as intended when both the vendor and the customer fulfill their respective obligations, a SaaS vendor’s access control environment may depend on the customer promptly de-provisioning departed employees from their end, for example, and if the customer fails to do this, the vendor’s control is undermined regardless of how well it is designed. CUECs are listed in Section 3 of every SOC 2 Report. Customers reviewing a vendor’s report must read the CUECs section to understand what security responsibilities they are accepting, failure to fulfill CUECs leaves the combined security posture weaker than the report alone suggests. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data
Sam-IT-Solutions Logo
SAM IT Solutions

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties