Where to get your vendors' SOC 2 reports (AWS, Vercel, Supabase, GitHub, Stripe and 25 more)
Your SOC 2 auditor will ask how you reviewed your vendors. Here is where 30 common startup vendors publish their SOC 2 report, who can download it, and what to check once you have it. If you are preparing for SOC 2, sooner or later your auditor asks how you reviewed the vendors that touch customer data. The usual evidence is each vendor's own SOC 2 report, plus a short record of what you checked…
Where to obtain your vendors' SOC 2 reports (AWS, Vercel, Supabase, GitHub, Stripe and 25 more)
When reviewing vendors for your SOC 2 compliance, it's crucial to understand how to acquire these reports and what to look for within them. This process can be complicated, with reports located in various places depending on the vendor. Here's a guide on where to find SOC 2 reports for 30 common startup vendors, along with key elements to examine once you have the documents.
The type of SOC 2 report and the period it covers are important factors. A Type II report covers a period of operation, while a Type I report is a snapshot taken at a single point in time. If a report is outdated, request the most recent version or a bridge letter that connects the old and new reports.
Ensure the scope of the report accurately reflects the product you use. Some vendors publish multiple reports; for example, AWS has a report for its specific services, while others like Stripe provide a single report. The auditor's opinion is usually unqualified, but be aware that a qualified opinion indicates a material issue that requires further investigation.
Some vendors may have exceptions in their test results, which should be reviewed to determine if they affect your usage of the vendor. Even with a clean opinion, you can find individual deviations that warrant attention. Vendors often expect you to implement additional user entity controls, such as enabling multi-factor authentication (MFA), managing your own users, and configuring encryption. These controls become part of your overall compliance strategy.
When reviewing vendor-subservice organizations, such as cloud providers, make sure to note them as fourth parties. This helps maintain a comprehensive view of all the entities handling your data.
Finally, record the date, report period, reviewer, any exceptions, and your decision regarding the vendor's compliance. This record is what the auditor will sample, not just the PDF. To manage this process effectively, small companies can prioritize their SaaS tools based on the data they handle. Tier vendors by the data they touch, focusing on full reviews for those that store or process customer data and shorter documented checks for others.
Auditors appreciate a consistent approach applied universally across your vendor inventory. You can find a free, editable Vendor and Third-Party Risk Management Policy template to help you set these policies and establish a review cadence at https://policyseed.vercel.app/policies/vendor-and-third-party-risk-policy.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.