SOC 2 Basics for Founders
Why did my SOC 2 report fail an enterprise security review?
What Does an Enterprise Security Team Actually Read?
A SOC 2 report is not a certificate, and enterprise reviewers do not treat it as one. They read it the way an auditor would: the opinion, the system description, the list of controls, the tests the auditor performed on each, and the results. The question they are answering is narrower than "does this vendor have SOC 2." It is "does this report give us evidence that the controls we depend on work, for the system we are buying."
If a customer only needs a report on file, most of what follows never comes up. When a buyer's security team reads the report line by line, it does.
The Common Reasons a Report Fails
| What the reviewer found | Why it fails | What fixes it |
|---|---|---|
| A Type I where the buyer requires a Type II | Type I shows controls were designed at a point in time, not that they operated over a period | A Type II covering an observation window |
| A short or stale period | A brief Type II window gives thin evidence, and a period that ended long ago says little about today | A longer window next cycle; a bridge letter for a gap of a few months |
| Scope that leaves out the product | The system description covers a different environment, or carves out the subservice organizations that run it | A system description that matches what the buyer uses, with carved-out vendors' own reports on hand |
| Exceptions on controls the buyer cares about | Access removal, change management, and logging exceptions are the ones reviewers stop on | Fix the control, then show dated evidence it has held since |
| Tests that relied on inquiry | Section 4 shows the auditor asked or read a policy instead of inspecting samples | Controls that produce evidence an auditor can sample |
| Policies that promise more than the controls do | A policy commits to quarterly reviews or a response time the evidence does not show | Policies written from what you actually run |
| An auditor the reviewer does not trust | An unfamiliar firm with no published peer review, or one chosen and paid through the platform vendor that produced the evidence | An independent firm you choose, with a published AICPA peer review |
The last row is the one you control before the audit starts. In April 2026 the AICPA named bundled fee-setting, tool-driven deadlines, and referral concentration as threats to auditor independence. The question worth asking any vendor before you sign is simple: does your platform vendor also provide your auditor?
For the difference between the two report types, see SOC 2 Type I vs Type II.
What Should You Do Now?
- Get the reason in writing. Ask the reviewer which control, section, or scope question failed. A vague "not sufficient" cannot be fixed; a named control can.
- Fix that control first. Treat it as remediation, not paperwork: change the setting or process, then collect dated evidence that it works.
- Send a remediation plan with the evidence. A documented fix with proof gives the reviewer something to approve, especially when the gap is one control rather than the whole report.
- Close an age gap with a bridge letter. If the only problem is that the period ended months ago, a bridge letter from management may be enough for the current deal.
- Plan the next audit around the reviewer's bar. If the problem was scope, depth of testing, or the auditor, book an independent firm you choose. A Type II at a startup-focused firm costs $7,000–$15,000, and which SOC 2 auditor a startup should choose covers how to check one.
How Do You Avoid It Next Time?
Several of these reasons trace back to remediation that was squeezed to fit the audit budget: exceptions, thin testing, and policies that promise more than the controls do. Budget the two separately, as the guide to budgeting the SOC 2 audit and remediation lays out, and do the control work before fieldwork rather than after a buyer finds the gap.
Screenata is built for the part reviewers read closely. Policies are written from a scan of your real infrastructure, and hard commitments the evidence cannot back are flagged before they reach the auditor. Every artifact is mapped to a control, dated, and signed, so any firm can verify it outside the platform. Screenata does not sell the audit: you choose and pay the firm, which gives you a clean answer if a reviewer asks who picked your auditor.