How to answer
Do you maintain a current SOC 2 Type II report?
If you have one, the cover page answers this question. The mistakes are all in the details it also contains: the type, the criteria, and the dates.
Yes. We hold a current SOC 2 Type II report covering the Security, Availability and Confidentiality trust services criteria, for the period [start] to [end]. It is available under NDA.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- The report itself. If you have one, this question is answered by its cover page: the trust services criteria in scope and the observation period.
- Evidence to attach
- The report, under NDA. Say so in the answer rather than attaching it.
- Where it is asked
- CAIQ v4.0 · A&A-02SIG LiteVSA Core
If you have a SOC 2 Type II, this is the easiest question on the questionnaire and you should answer it with the specifics rather than a yes. Name the type, the trust services criteria in scope, and the observation period. Those three facts are on the report's cover page, they are what the reviewer is going to check anyway, and volunteering them saves a round trip that would otherwise cost you a week.
Three things reviewers actually look at:
Type I or Type II. A Type I is an auditor's opinion that your controls were suitably designed at a point in time. A Type II is an opinion that they operated effectively across a period, usually six or twelve months. The second is the one enterprise procurement asks for. Answering "yes, SOC 2" when you hold a Type I is not a lie you will get away with, because the report says which it is on the first page.
The criteria in scope. Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are each optional. Most startups scope Security alone, sometimes with Availability. That is a completely normal answer. Implying more coverage than you bought is not.
The dates. A Type II covers a window, and a window that closed more than a year ago will be treated as stale. Between windows, the thing that keeps a deal moving is a bridge letter from your auditor covering the gap.
If you do not have one, say so plainly and say what you do have: an ISO 27001 certificate, a pen test report, a completed CAIQ, a Trust Center page. "Not yet; certification is planned for [quarter], and in the meantime here is our [X]" is an answer a reviewer can work with. A blank cell is not.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes for a Type I. A Type I says the controls were designed sensibly on one day; a Type II says they operated over a period. Reviewers know the difference and the report's cover page says which it is.
- Omitting the criteria in scope. Security only is common and fine; presenting it as though Availability and Confidentiality were also covered is not.
- An expired observation period. A report whose window closed fourteen months ago is a report a reviewer will treat as no report.