Your SOC 2 auditor will ask how you reviewed the vendors that touch customer data, and the usual answer is each vendor’s own SOC 2 report. Most vendors keep it behind a trust center, a dashboard page or a request form. This page lists where 30 common startup vendors publish theirs and who is allowed to download it, then explains what to check once you have the PDF.
Each entry was checked against the vendor’s own pages on September 28, 2026. Access terms change; confirm on the vendor’s page before you rely on one.
Download through Compliance Reports Manager at no extra cost after signing in with a Google Cloud account; confidentiality terms of your agreement apply.
Customers confirm their email for full trust center access; non-customers complete a clickwrap NDA to see the SOC 2 Type II report.
What to check in a vendor’s SOC 2 report
Downloading the report is not the review. Read these parts and write down what you found:
Type and period. A Type II report covers a period of operation; a Type I is a single date. Note the period end. If it ended long ago, ask for the newer report or a bridge letter.
Scope. Check that the system description covers the product you actually use. Large vendors publish several reports; the one for another product line does not help you.
The auditor’s opinion. An unqualified opinion is the expected result. A qualified opinion means the auditor found a material problem; read which criterion and why.
Exceptions in the test results. Even with a clean opinion, individual tests can show deviations. Decide whether any of them affect how you use the vendor.
Complementary user entity controls. This section lists what the vendor expects you to do, such as enabling MFA, managing your own users or configuring encryption. Those become your controls; check that your policies cover them.
Subservice organizations. The vendor’s own vendors (often a cloud provider) are listed here, usually carved out. Note them in your vendor inventory as fourth parties.
Record the review with the date, the report period, the reviewer, any exceptions and the decision. That record, not the PDF, is the evidence your auditor samples. The Vendor and Third-Party Risk Management Policy template sets out the inventory, the risk tiers and the review cadence, and you can download it as Word in your company’s name from that page.
Keep it proportionate
A small company can easily use dozens of SaaS tools, and not all of them need a SOC 2 review. Tier vendors by the data they touch: the ones that store or process customer data (cloud, database, hosting, email, support tools) get a full review with the report; tools with no customer data get a short documented check. The auditor looks for a consistent rule applied to the whole inventory, not for a PDF from every tool.
Frequently asked questions
Why do I need my vendors' SOC 2 reports?
SOC 2 criterion CC9.2 expects you to assess and monitor the risk from vendors and business partners. For any vendor that stores or processes customer data, a current SOC 2 Type II report is the standard evidence that you did. Your auditor will ask for the vendor inventory and for the reviews of the vendors on it.
What if a vendor has no SOC 2 report?
Ask for an equivalent: an ISO/IEC 27001 certificate with its statement of applicability, a completed security questionnaire, or a penetration test summary. Record which one you received, the risk you accepted and who approved it. For a low-risk vendor that never touches customer data, a short documented review is normally enough.
What is a bridge letter?
A SOC 2 Type II report covers a fixed period that ended some months before you read it. A bridge (or gap) letter is the vendor management's statement that nothing material changed between the end of that period and a later date. Ask for one when the report period ended more than a few months ago.
Do I need to review every vendor every year?
Review vendors on the schedule your vendor policy sets, tiered by risk. Vendors that hold customer data are usually reviewed annually with a fresh SOC 2 report; low-risk tools can be reviewed less often. The auditor tests that you did what the policy says, so set a cadence you will keep.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.