How to Answer SOC 2 Questions When a Customer Asks
Your customer asked: “Are you SOC 2 compliant, certified, or do you have a SOC 2 report?”
The short answer
SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
Customers often use imprecise language such as “SOC 2 certified” or “SOC 2 compliant.” The useful question is whether your organization has undergone a SOC 2 examination and has a report that covers the relevant service, system, criteria, and period. AICPA describes SOC 2 as reporting on controls relevant to security, availability, processing integrity, confidentiality, or privacy.
How to answer accurately
Start with the version that matches reality.
If you have a SOC 2 report
State the report type and scope accurately and follow your company's rules for sharing it. Do not imply that the report covers systems or periods outside its actual scope.
If an examination is in progress
You may say that only if it is true and approved for disclosure. “In progress” is not the same as having a completed report.
If you do not have a SOC 2 report
Say that directly. You can still answer underlying security questions using documented practices and evidence without claiming SOC 2 status.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Current SOC 2 report
- Engagement documentation if an examination is genuinely in progress and disclosure is approved
- Bridge letter or other approved period-gap communication, when applicable
- Underlying policies and evidence for individual security questions
What not to say
- “SOC 2 certified.”
- “SOC 2 compliant” merely because you follow some similar practices.
- That using a SOC 2-audited cloud provider gives your company its own SOC 2 report.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra must never manufacture SOC 2 status. If the approved company profile does not contain a valid report or supported status, the questionnaire answer should remain explicit about that limitation.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do you maintain a written information security policy?
Answer “yes” only if a written policy actually exists in a current, approved form. A policy describes expectations and requirements; it does not by itself prove that every stated practice or control is operating.
Do you assess the security of vendors and third parties?
Describe how your company evaluates vendors that can affect customer data or important operations. A small business may perform practical due diligence without running a formal enterprise vendor-risk program; the answer should reflect the process that actually exists.
Are you ISO 27001 certified?
ISO/IEC 27001:2022 defines requirements for an information security management system. A company can use the standard without being certified. Answer “certified” only when the organization actually holds a valid certificate covering the relevant scope.