Join our Newsletter — 33% off our NHI Course

How should security teams respond when a vendor sends a SOC 2 report instead of completing a security questionnaire?

A SOC 2 report should be treated as supporting evidence, not a replacement for due diligence. Security teams should still run the questionnaire because it captures organisation specific risk, control context, and gaps that a report cannot fully address. In regulated environments, both artefacts often matter, and together they give a more complete picture of vendor assurance.

Why a SOC 2 Report Is Useful, but Not Enough

A SOC 2 report is valuable because it gives an independent view of a vendor’s control environment, but it answers a different question than a security questionnaire. The report is typically scoped to defined controls and audit periods, while the questionnaire is your chance to test how the vendor’s controls map to your data, integrations, regulatory obligations, and tolerance for exceptions. Treating them as substitutes creates blind spots.

That distinction matters because vendor assurance is not just about whether controls exist, but whether they are operating in a way that fits your use case. A report can show the vendor passed an audit; it cannot fully capture custom architecture, compensating controls, inherited risk, or gaps in the specific service you plan to consume. The questionnaire helps close that gap.

  • Use the SOC 2 report to confirm the control baseline.
  • Use the questionnaire to probe scope, exceptions, ownership, and edge cases.
  • Compare both against the service, data class, and integration path you are evaluating.

How to Evaluate the Two Artefacts Together

The practical response is to accept the report as evidence and still complete the questionnaire. If a vendor says the report should replace the questionnaire, ask whether the report actually covers the service you are buying, the period you care about, and the control areas your own policy requires. In regulated or high-assurance environments, the two artefacts are complementary, not competing.

This is also where third-party risk teams should avoid over-weighting audit language. A SOC 2 report may demonstrate that controls were designed and tested, but your review still needs to determine whether there are open issues, limitations, carve-outs, subservice dependencies, or control assumptions that affect your risk decision. The questionnaire is where those details are usually made explicit.

For teams assessing vendors at scale, standardise the decision rule: if a report is provided, accept it as one input, then continue with your required due diligence workflow unless policy explicitly allows an exception. That approach keeps the review consistent across vendors and prevents a strong document from being mistaken for complete assurance.

  • Check whether the report scope aligns to the product or service you are buying.
  • Review exceptions, subservice organisations, and management responses before relying on it.
  • Use the questionnaire to capture control details that the report does not surface in enough operational depth.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Vendor assurance decisions depend on risk appetite and third-party risk tolerance.
GV.SC-04 — Supply Chain Risk Management SOC 2 and questionnaires are both supply-chain assurance inputs for vendors.
Recommendation — Define when a SOC 2 report is sufficient evidence and when a questionnaire remains mandatory. Evaluate vendor assurances against your supply-chain risk criteria, not a single audit artefact.
CIS Controls v8 15 — Service Provider Management The topic is third-party assessment and ongoing supplier oversight.
Recommendation — Require contractual and control evidence from vendors before approving access to data or services.

Practitioner Guidance

What to prioritise: Decide first whether the vendor relationship is low-risk, regulated, or business-critical. The higher the assurance bar, the less defensible it is to stop at a SOC 2 report alone.

What to verify: Confirm that the report period, scope, and trust services criteria actually match the service in use, and that any questionnaire exceptions are documented rather than assumed away. In practice, the questionnaire is often where you discover integration-specific exposure, data handling nuance, or control ownership ambiguity.

Decision rule: If the vendor asks you to choose between the report and the questionnaire, treat that as a maturity signal, not a shortcut. A vendor that is comfortable answering both is usually easier to govern than one that wants the audit artefact to stand in for operational transparency.

Practitioner takeaway: A SOC 2 report should reduce review effort, not eliminate review judgment. Good vendor assurance combines audit evidence with structured questioning so you can see both the control baseline and the risk that is specific to your relationship.