Auditor variance
CPA firm variance significant:
- Auditor depth differs widely across firms.
- Some firms produce minimal-substance "compliant" reports.
- Auditor-shopping risk real; not always detectable.
CPA-firm-as-auditor conflict
Same firms providing:
- SOC 2 readiness consulting.
- SOC 2 audits.
- Other consulting.
Independence requirements limit individual auditor conflict; firm-level conflict persists. AICPA rules manage; not eliminated.
Annual cycle burden
Every year requires fresh attestation:
- Same evidence-collection cycle annually.
- No multi-year certificate equivalent.
- Cumulative cost over time exceeds ISO 27001 3-year cycle.
Customer-customizable scope
Service orgs can choose which TSC categories to include. Result:
- Two orgs' SOC 2 Type 2 reports may not be comparable.
- Procurement teams must read scope carefully.
- "We have SOC 2 Type 2" insufficient claim without scope detail.
No public certificate
Reports restricted by NDA:
- Cannot use SOC 2 in marketing (without SOC 3 separate engagement).
- Customer evaluation requires NDA process.
- Trust-building friction.
Subservice org complexity
Carve-out method standard but:
- Customers must read upstream SOC 2 reports also.
- Multi-tier service chain creates SOC 2 report stack.
- CUECs across multiple parties not always coherent.
Privacy TSC vs GDPR overlap
Privacy TSC partially aligns with GDPR; not equivalent:
- Different legal foundations.
- Different enforcement.
- Combined positioning requires both.
Compliance vs security
Same pattern as other frameworks:
- SOC 2 Type 2 attestation does not prevent breaches.
- Real-world breaches at SOC-2-attested orgs occur.
- Attestation is procurement signal, not security guarantee.
"Pass the audit" optimization
Some orgs optimize for pass-the-audit rather than substantive security:
- Control activities designed for auditability.
- Evidence collection focused on auditor expectations.
- Operational security can be detached from compliance posture.
Counterpoint: what SOC 2 still does well
- US procurement signal.
- Type 2 operational-effectiveness rigor real.
- Mature ecosystem.
- Combined-audit infrastructure with ISO 27001 efficient.
- Privacy TSC supports cross-border privacy work.
See also
- cluster MOC · SOC 2 Trust Services Criteria · SOC 2 vs ISO 27001
- ISO 27001 Controversies (parallel critique)