The buyer requires SOC 2. You do not have the report.
The buyer’s questionPlease provide a current SOC 2 Type 2 report covering the proposed service. This is a mandatory requirement.
Answer the evidence question first: the requested report is not available. A roadmap, a hosting provider's report or a different assurance document is not automatically a substitute. Establish whether the buyer's authorised process permits an exception before treating the bid as eligible.
A response to adapt
We cannot provide the requested SOC 2 Type 2 report for [legal entity and proposed service] as of [response date]. We therefore do not currently meet this evidence requirement as written. The assurance evidence presently available is [exact document, issuing organisation, scope and date; omit if none]. This is offered for your assessment, not represented as an equivalent SOC 2 report. [Only if verified and approved: Our audit engagement covers [scope], with [current milestone]. The planned reporting date is [approved estimate], subject to completion and issuance; no report has yet been issued.] Please confirm through [authorised clarification channel] whether the procurement permits consideration of [precisely identified alternative evidence or an exception], and what approval and submission conditions apply. Unless an authorised change or exception is confirmed in writing, we will continue to record this requirement as unmet.
Replace every bracketed field with verified facts. Remove any optional sentence you cannot substantiate. Do not submit this wording unchanged.
What makes the wording defensible
State the SOC 2 evidence gap precisely, distinguish an audit plan from an issued report, and determine whether the buyer permits an alternative before committing.
Identify what is missing, not just the acronym
Read the requirement for report type, named entity, service, assurance categories, reporting period and permitted age. An existing report can still fail the request because it excludes the proposed service or covers the wrong period. AICPA's review checklist directs readers to inspect system coverage, report period, opinion, exceptions and subservice exclusions. Treat these as distinct checks, not a logo-based yes/no.
Do not turn a project milestone into assurance
An engagement letter proves an engagement, not an issued examination result. A readiness assessment describes preparation. Neither establishes operating effectiveness for the buyer's requested period. If an audit is underway, identify the actual milestone and its owner; do not promise a favourable opinion or a delivery date that the auditor has not committed to. Keep speculative future evidence out of the present compliance column.
Separate the evidence gap from the underlying controls
Missing assurance does not, by itself, tell the buyer which controls are absent. Explain only controls you can substantiate. Equally, having controls or an ISO certificate does not establish that the requested SOC 2 evidence exists. A hosting provider's report may support review of that provider; it does not become your service organisation's report by attachment. The buyer decides what it can accept under its process.
Four evidence states. Four different answers.
Use this triage before drafting. It prevents every difficult assurance request becoming the same vague “in progress” answer.
- No report issued
- Disclose absence. Seek an authorised alternative only if the procurement permits one; do not imply that preparation equals assurance.
- Report exists, wrong scope
- Identify the entity, service or category mismatch. Explain the uncovered part rather than attaching a report that cannot answer it.
- Report period does not meet the request
- Disclose the dates and current evidence available. A temporal update is not a replacement examination.
- Requested report is available
- Check sharing permissions, scope and relevant exceptions before confirming compliance and releasing the correct version.
The evidence to obtain
The buyer's requirement and exception route
Retain the exact clause, document version, mandatory or scored designation, questions deadline and approved submission channel. Obtain any published clarification or authorised written decision that permits alternative evidence. A buyer contact's informal reassurance should not silently override published instructions; the Bid Manager must establish who has authority and how the decision is incorporated.
An inventory the security owner can stand behind
List issued reports, scope, entity, period, sharing restrictions and responsible owner. For each alternative, state the control question it can help answer and what it does not establish. Remove confidential report content from public material; agree the buyer's secure sharing route. Ask for a controlled review package, not every internal policy the team happens to possess.
A bounded, approved audit-status statement
If relevant, obtain the signed engagement's applicable scope, confirmed work completed and a status statement approved by the security owner. Keep estimates explicitly conditional. If a report exists but its period leaves a gap, seek the relevant current evidence and assess the buyer's instructions; do not use a management update to pretend a new audit period has been examined.
The decision to approve
- Decision owners
- The security or assurance owner validates evidence; the Bid Manager controls eligibility and clarification; the commercial owner and legal reviewer approve any proposed commitment.
- Proceed
- Proceed only when the requested evidence actually satisfies the requirement, or the buyer's authorised process explicitly allows the disclosed alternative or exception. Carry the exact scope and conditions into the response.
- Do not proceed
- If the report is an unchanged mandatory submission condition and is unavailable, record an unmet requirement. Better wording cannot make the bid eligible; do not mark it compliant to keep the opportunity moving.
- Escalate
- Escalate uncertainty about acceptable report age, service coverage, disclosure restrictions or exception authority before submission. An unanswered clarification is not approval.
Keep the decision in the final files
Before release, compare the compliance cell, security narrative, exception schedule and evidence attachments. They must describe the same report status and the same buyer decision. REQVERA's final-control positioning concerns coherence between requirements, approved evidence, responses and final files; this editorial example does not certify controls or decide procurement eligibility.
See the authentic final-control workflowScope & primary references
Illustrative vendor-response guidance, not a claim about REQVERA's assurance status. SOC reporting references are AICPA sources; buyer acceptance and procurement procedure depend on the actual solicitation. This is not an audit opinion or legal advice. Replace every bracketed field with verified information or remove the conditional sentence.
- AICPA & CIMA — System and Organization Controls
Primary authority for SOC assurance services and current warnings about the credibility of inadequately performed engagements; reviewed 11 October 2026.
- AICPA — Illustrative SOC 2 Report Review checklist
Illustrative review tool covering report type and period, relevant system scope, opinion, control exceptions and subservice exclusions. It is not a buyer acceptance rule.