How to Answer SOC 2 Questions When a Customer Asks

Your customer asked: “Are you SOC 2 compliant, certified, or do you have a SOC 2 report?”

The short answer

SOC 2 is an examination and resulting report on controls at a service organization; it is not a SOC 2 certification. If your company does not have a current SOC 2 report, do not describe the business as SOC 2 certified or imply that a policy set makes you SOC 2 compliant.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

Customers often use imprecise language such as “SOC 2 certified” or “SOC 2 compliant.” The useful question is whether your organization has undergone a SOC 2 examination and has a report that covers the relevant service, system, criteria, and period. AICPA describes SOC 2 as reporting on controls relevant to security, availability, processing integrity, confidentiality, or privacy.

How to answer accurately

Start with the version that matches reality.

1

If you have a SOC 2 report

State the report type and scope accurately and follow your company's rules for sharing it. Do not imply that the report covers systems or periods outside its actual scope.

2

If an examination is in progress

You may say that only if it is true and approved for disclosure. “In progress” is not the same as having a completed report.

3

If you do not have a SOC 2 report

Say that directly. You can still answer underlying security questions using documented practices and evidence without claiming SOC 2 status.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Current SOC 2 report
  • Engagement documentation if an examination is genuinely in progress and disclosure is approved
  • Bridge letter or other approved period-gap communication, when applicable
  • Underlying policies and evidence for individual security questions

What not to say

  • “SOC 2 certified.”
  • “SOC 2 compliant” merely because you follow some similar practices.
  • That using a SOC 2-audited cloud provider gives your company its own SOC 2 report.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra must never manufacture SOC 2 status. If the approved company profile does not contain a valid report or supported status, the questionnaire answer should remain explicit about that limitation.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions