The Honest No · Decision note 04

The buyer requires SOC 2. You do not have the report.

Illustrative situation · Not a customer case
The buyer’s question

Please provide a current SOC 2 Type 2 report covering the proposed service. This is a mandatory requirement.

Answer the evidence question first: the requested report is not available. A roadmap, a hosting provider's report or a different assurance document is not automatically a substitute. Establish whether the buyer's authorised process permits an exception before treating the bid as eligible.

A response to adapt

We cannot provide the requested SOC 2 Type 2 report for [legal entity and proposed service] as of [response date]. We therefore do not currently meet this evidence requirement as written. The assurance evidence presently available is [exact document, issuing organisation, scope and date; omit if none]. This is offered for your assessment, not represented as an equivalent SOC 2 report. [Only if verified and approved: Our audit engagement covers [scope], with [current milestone]. The planned reporting date is [approved estimate], subject to completion and issuance; no report has yet been issued.] Please confirm through [authorised clarification channel] whether the procurement permits consideration of [precisely identified alternative evidence or an exception], and what approval and submission conditions apply. Unless an authorised change or exception is confirmed in writing, we will continue to record this requirement as unmet.

Replace every bracketed field with verified facts. Remove any optional sentence you cannot substantiate. Do not submit this wording unchanged.

What makes the wording defensible

State the SOC 2 evidence gap precisely, distinguish an audit plan from an issued report, and determine whether the buyer permits an alternative before committing.

  • Identify what is missing, not just the acronym

    Read the requirement for report type, named entity, service, assurance categories, reporting period and permitted age. An existing report can still fail the request because it excludes the proposed service or covers the wrong period. AICPA's review checklist directs readers to inspect system coverage, report period, opinion, exceptions and subservice exclusions. Treat these as distinct checks, not a logo-based yes/no.

  • Do not turn a project milestone into assurance

    An engagement letter proves an engagement, not an issued examination result. A readiness assessment describes preparation. Neither establishes operating effectiveness for the buyer's requested period. If an audit is underway, identify the actual milestone and its owner; do not promise a favourable opinion or a delivery date that the auditor has not committed to. Keep speculative future evidence out of the present compliance column.

  • Separate the evidence gap from the underlying controls

    Missing assurance does not, by itself, tell the buyer which controls are absent. Explain only controls you can substantiate. Equally, having controls or an ISO certificate does not establish that the requested SOC 2 evidence exists. A hosting provider's report may support review of that provider; it does not become your service organisation's report by attachment. The buyer decides what it can accept under its process.

Four evidence states. Four different answers.

Use this triage before drafting. It prevents every difficult assurance request becoming the same vague “in progress” answer.

No report issued
Disclose absence. Seek an authorised alternative only if the procurement permits one; do not imply that preparation equals assurance.
Report exists, wrong scope
Identify the entity, service or category mismatch. Explain the uncovered part rather than attaching a report that cannot answer it.
Report period does not meet the request
Disclose the dates and current evidence available. A temporal update is not a replacement examination.
Requested report is available
Check sharing permissions, scope and relevant exceptions before confirming compliance and releasing the correct version.

The evidence to obtain

  • The buyer's requirement and exception route

    Retain the exact clause, document version, mandatory or scored designation, questions deadline and approved submission channel. Obtain any published clarification or authorised written decision that permits alternative evidence. A buyer contact's informal reassurance should not silently override published instructions; the Bid Manager must establish who has authority and how the decision is incorporated.

  • An inventory the security owner can stand behind

    List issued reports, scope, entity, period, sharing restrictions and responsible owner. For each alternative, state the control question it can help answer and what it does not establish. Remove confidential report content from public material; agree the buyer's secure sharing route. Ask for a controlled review package, not every internal policy the team happens to possess.

  • A bounded, approved audit-status statement

    If relevant, obtain the signed engagement's applicable scope, confirmed work completed and a status statement approved by the security owner. Keep estimates explicitly conditional. If a report exists but its period leaves a gap, seek the relevant current evidence and assess the buyer's instructions; do not use a management update to pretend a new audit period has been examined.

The decision to approve

Decision owners
The security or assurance owner validates evidence; the Bid Manager controls eligibility and clarification; the commercial owner and legal reviewer approve any proposed commitment.
Proceed
Proceed only when the requested evidence actually satisfies the requirement, or the buyer's authorised process explicitly allows the disclosed alternative or exception. Carry the exact scope and conditions into the response.
Do not proceed
If the report is an unchanged mandatory submission condition and is unavailable, record an unmet requirement. Better wording cannot make the bid eligible; do not mark it compliant to keep the opportunity moving.
Escalate
Escalate uncertainty about acceptable report age, service coverage, disclosure restrictions or exception authority before submission. An unanswered clarification is not approval.

Keep the decision in the final files

Before release, compare the compliance cell, security narrative, exception schedule and evidence attachments. They must describe the same report status and the same buyer decision. REQVERA's final-control positioning concerns coherence between requirements, approved evidence, responses and final files; this editorial example does not certify controls or decide procurement eligibility.

See the authentic final-control workflow

Scope & primary references

Illustrative vendor-response guidance, not a claim about REQVERA's assurance status. SOC reporting references are AICPA sources; buyer acceptance and procurement procedure depend on the actual solicitation. This is not an audit opinion or legal advice. Replace every bracketed field with verified information or remove the conditional sentence.