SOC 2 Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Auditor variance

CPA firm variance significant:

  • Auditor depth differs widely across firms.
  • Some firms produce minimal-substance "compliant" reports.
  • Auditor-shopping risk real; not always detectable.

CPA-firm-as-auditor conflict

Same firms providing:

  • SOC 2 readiness consulting.
  • SOC 2 audits.
  • Other consulting.

Independence requirements limit individual auditor conflict; firm-level conflict persists. AICPA rules manage; not eliminated.

Annual cycle burden

Every year requires fresh attestation:

  • Same evidence-collection cycle annually.
  • No multi-year certificate equivalent.
  • Cumulative cost over time exceeds ISO 27001 3-year cycle.

Customer-customizable scope

Service orgs can choose which TSC categories to include. Result:

  • Two orgs' SOC 2 Type 2 reports may not be comparable.
  • Procurement teams must read scope carefully.
  • "We have SOC 2 Type 2" insufficient claim without scope detail.

No public certificate

Reports restricted by NDA:

  • Cannot use SOC 2 in marketing (without SOC 3 separate engagement).
  • Customer evaluation requires NDA process.
  • Trust-building friction.

Subservice org complexity

Carve-out method standard but:

  • Customers must read upstream SOC 2 reports also.
  • Multi-tier service chain creates SOC 2 report stack.
  • CUECs across multiple parties not always coherent.

Privacy TSC vs GDPR overlap

Privacy TSC partially aligns with GDPR; not equivalent:

  • Different legal foundations.
  • Different enforcement.
  • Combined positioning requires both.

Compliance vs security

Same pattern as other frameworks:

  • SOC 2 Type 2 attestation does not prevent breaches.
  • Real-world breaches at SOC-2-attested orgs occur.
  • Attestation is procurement signal, not security guarantee.

"Pass the audit" optimization

Some orgs optimize for pass-the-audit rather than substantive security:

  • Control activities designed for auditability.
  • Evidence collection focused on auditor expectations.
  • Operational security can be detached from compliance posture.

Counterpoint: what SOC 2 still does well

  • US procurement signal.
  • Type 2 operational-effectiveness rigor real.
  • Mature ecosystem.
  • Combined-audit infrastructure with ISO 27001 efficient.
  • Privacy TSC supports cross-border privacy work.

See also