Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why does an unqualified SOC 2 opinion still…
Cyber Security

Why does an unqualified SOC 2 opinion still require follow-up when the report notes issues?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

An unqualified opinion means the tested controls operated as intended, but it does not erase any issues the auditor highlighted. Readers will look closely at those exceptions, especially if they affect customers or third parties. The practical response is to explain the issue, show the mitigation in place, and demonstrate that the control gap is being resolved.

Why the auditor’s opinion is only one part of the story

An unqualified SOC 2 opinion speaks to the controls the auditor tested, not to every operational weakness, exception, or forward-looking concern that may appear elsewhere in the report. A reader can still reasonably ask whether the noted issue affects real-world reliability, customer commitments, or third-party trust, especially when the exception sits near a sensitive control area such as access, logging, or change management.

That is why follow-up matters: the opinion answers “did the system meet the criteria in scope,” while the issue note answers “what should be watched, explained, or remediated next.” If the report includes a qualified-looking narrative exception, management commentary, or a known control gap, stakeholders will usually weigh that context alongside the clean opinion rather than ignoring it.

  • Use the issue language to determine whether the exception is isolated, recurring, or evidence of a control design weakness.
  • Check whether the note concerns a customer-facing control, a shared service, or a third-party dependency, since those often carry more commercial weight.
  • Separate the auditor’s tested population from the broader environment, because a narrow test can still leave meaningful exposure outside the sample.

A useful comparator is the AICPA’s SOC 2 Trust Services Criteria, which makes clear that the report is built around specific criteria and scope, not a universal guarantee about every control in the organisation.

What the note on issues means for customers and third parties

The practical concern is not whether the opinion is unqualified, but whether the disclosed issue changes the reader’s confidence in the service. Customers, procurement teams, and partners often focus on the exception itself because it may indicate temporary compensating controls, incomplete remediation, or a control environment that is functioning but not yet stable.

That distinction matters in vendor assurance. A clean opinion can coexist with a problem that is too limited to change the overall conclusion, yet still important enough to require explanation, mitigation evidence, or a committed fix date before the report is treated as low-risk. In other words, the report may be acceptable, but still not be the end of the conversation.

  • Assess whether the issue affects confidentiality, availability, or processing integrity in a way that maps to your own contractual or regulatory obligations.
  • Look for evidence of interim controls, monitoring, or segregation that reduce the practical impact of the issue.
  • Ask whether the issue was remediated after the audit period, and whether that remediation has been independently verified or only promised.

For broader third-party and systemic exposure concerns, the ENISA Threat Landscape is useful background for understanding why control exceptions, supply-chain dependencies, and operational gaps tend to draw scrutiny even when no single report finding changes the opinion.

How to respond without overreacting or underexplaining

The right response is usually measured, not defensive. Explain the issue in plain language, state whether it is already remediated or under active remediation, and show what reduced the exposure in the meantime. If the control gap was non-material to the auditor’s conclusion, say so, but do not hide behind the opinion as though it neutralises the exception.

Practitioners often underestimate how much clarity matters here. A short, specific response that distinguishes root cause, interim containment, and permanent fix usually builds more trust than a general assurance statement. If the issue touches access, secrets, or another control that can spread quickly across systems, the explanation should also cover blast radius and whether similar weaknesses were searched for elsewhere.

  • Document the exact issue, the business impact, and the remediation status in the same narrative.
  • Show whether the gap is local to one control or indicative of a wider pattern.
  • Be ready to explain why the issue does not invalidate the opinion while still acknowledging why it matters.

NHIMG’s Ultimate Guide to NHIs is relevant here because many audit exceptions ultimately trace back to overprivileged, poorly governed, or poorly rotated access material, which is exactly the kind of weakness that can survive a clean overall opinion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategySOC 2 issues affect assurance risk and stakeholder trust.
GV.OV — OversightException narratives require governance-level visibility and accountability.
Recommendation — Align issue follow-up to organizational risk acceptance and remediation thresholds. Route material SOC 2 exceptions to accountable owners with tracked remediation.
CIS Controls v88 — Audit Log ManagementAudit report exceptions often involve logging or evidence gaps.
6 — Access Control ManagementMany SOC 2 exceptions arise from overbroad access or weak entitlement control.
Recommendation — Verify logging coverage and preserve evidence that supports the remediation claim. Review and reduce excessive access that underlies the reported exception.

Practitioner Guidance

What to prioritise: Treat the exception as the primary object of follow-up, not the opinion. If the note affects customer-facing controls, third-party access, or a shared operational dependency, it deserves a clearer remediation statement than a generic “audit passed” summary.

What to verify: Confirm whether the issue was sampled narrowly, compensated for by another control, or remediated after the audit window. If you cannot show that distinction, assume readers will read the exception as a live risk signal.

Common mistake: Teams often over-rotate on the unqualified opinion and under-document the issue note. That creates avoidable friction because the report may be technically clean while still leaving procurement or assurance reviewers with unanswered questions.

Practitioner takeaway: The opinion settles the auditor’s conclusion, but the issue note still drives trust, so your follow-up should prove containment, remediation, and scope rather than merely repeating that the report is unqualified.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org