A Buyer Wants SOC 2 Before Onboarding—What Service Are They Asking For?
A buyer says SOC 2 is required before onboarding. Classify the requested artifact, owner, period, and decision date, then route the conversation to report access, readiness work, an examination engagement, or questionnaire support.

Most likely, they are asking for one of four services: access to a report you already hold, readiness work before an examination, a new independent examination engagement, or help completing a vendor questionnaire. “SOC 2 is required before onboarding” does not reveal which. Classify artifact, owner, period, and decision date first.
SOC 2 (System and Organization Controls 2) is the AICPA’s framework for reporting on controls at a service organization (security, availability, processing integrity, confidentiality, or privacy). A SOC 2 report is the artifact that reporting produces: an independent service auditor’s opinion, management’s assertion, and a system description, issued by a licensed CPA firm—never by a vendor’s sales team. A vendor questionnaire is the buyer’s control questions your team answers in writing; readiness work is the gap assessment and preparation before it.
As the sales lead who qualifies SOC 2 vendor onboarding requests, “we need SOC 2” is ambiguous by design: AICPA & CIMA’s resource hub (retrieved 2 August 2026) separates practitioner guidance, illustrative reports, and management/user-entity resources. How cybersecurity demand forms in specialist communities explains the difference.
The Request Is Four Services Wearing One Name
Route 1, existing report access: the buyer wants to see the report you already hold (artifact: current report; owner: your company; period: covered; decision date: review deadline).
Route 2, readiness work: gap assessment or control preparation before an examination (artifact: the assessment, no independent opinion; owner: your company or a hired consultant; period: controls in scope; decision date: when preparation starts).
Route 3, examination engagement: a newly issued SOC 2 report from an independent service auditor (artifact: the new report; owner: the CPA firm; period: an upcoming or in-flight window; decision date: engagement start and fieldwork).
Route 4, questionnaire support: the buyer sends a security questionnaire and expects answers (artifact: the completed questionnaire; owner: your answering team; period: the questionnaire’s version; decision date: its due date).
Quick Answer: Classify Before You Route
- If the buyer only needs to confirm you hold a current report whose period and scope match, route to report access.
- If you hold a report that does not cover the requested period or trust services, or the buyer asks for a fresh assessment, route to readiness work.
- If the buyer or their contract requires a report issued by an independent auditor for a period not examined yet, route to an examination engagement.
- If the buyer sent a questionnaire rather than a request for a report, route to questionnaire work.
None of the four is always correct; the period requirement changes most often.
The Decision Matrix: Four Routes on the Same Criteria
| Criterion | Access | Readiness | Examination | Questionnaire |
|---|---|---|---|---|
| Artifact | Current report | Assessment, no opinion | Newly issued report | Completed questionnaire |
| Owner | Your company | You or hired consultant | Independent CPA firm | Your answering team |
| Period | Already covered | Controls in scope now | Upcoming or in-flight | Version or date |
| Decision date | Review deadline | Prep start date | Engagement start, fieldwork | Due date |
| Human cost | Staff share | Consultant days | Auditor days | Staff answer |
Four Questions: Artifact, Owner, Period, Decision Date
-
What artifact? “Do you need our current SOC 2 report, a readiness assessment, a newly issued report from an independent auditor, or a completed questionnaire?”
-
Who owns it? “Who will review it—your security team, procurement, or an external reviewer?” This reveals who has seen reports like yours.
-
What period? “Which period must the report cover, and which trust services criteria must be in scope?” Period mismatches are the most common reason an existing report fails.
-
By when? “What is the date the decision must be made?” This decides whether routes 2 and 3 are feasible—examinations run on fixed calendars.
Key Facts: What the Official Sources Say
These dates come from official AICPA and Telegram sources: what a SOC 2 report is and who issues it, not buyer intent.
- 2 August 2026 (retrieval): AICPA & CIMA, System and Organization Controls suite of services. SOC 2 reports on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy; the hub separates guidance, illustrative reports, and user-entity resources.
- 5 June 2025 (publication): AICPA & CIMA, Key Elements of a SOC 2 Report — Resources for Management, a management review of the key sections: the auditor’s opinion, management’s assertion, and the system description—report artifacts, not readiness or questionnaire work.
- 30 September 2023 (publication): AICPA, Illustrative SOC 2 Report with Illustrative System Description. The 809.8 KB member-access resource contains management’s assertion, a system description, and a Type 2 service auditor’s report.
- 2 August 2026 (access): Telegram Privacy Policy. Bots are independent third-party services that run with or without message access; the interface shows which mode applies; permissions can be revoked.
Measurement context: SOC 2 is a reporting standard; only the independent service auditor issues the report. When a buyer names a compliance document, the official-source ladder verifies which document binds them.
Worked Example: A Composite Onboarding Message
This composite message is illustrative; no real customer sent it; no date is a fact.
Illustrative/composite Telegram message: “Hi—SOC 2 is required before onboarding. We need your report before our quarterly vendor review on the 15th. Can you send it?”
- Artifact: “your report” suggests route 1—but a buyer requiring a current-period examination would write the same sentence.
- Owner: unknown. The sender may be procurement; the reviewer, the buyer’s security team.
- Period: unknown. Quarterly review does not say which criteria or which twelve-month window.
- Decision date: “the 15th” is an illustrative date in this composite message—the review deadline, not the day the security team decides.
Keep the reply short: “Which artifact—our current SOC 2 report, a readiness assessment, a newly issued report, or a completed questionnaire? Who reviews it, for which period, and by what date?” The answers usually route the conversation in one exchange.
Why it matters: routing wrong means sending last year’s report to a buyer whose contract demands a new examination, or quoting a timeline to a buyer who only wanted the PDF. Whether the checklist accepts a Type 1 report, requires a specific auditor, or adds clauses—only the buyer’s security team can verify.
You may also want to watch for similar requests across your conversations. TOP Prospect processes only Telegram groups you intentionally connect and are authorized to access, produces candidates for review rather than fact certification, leaves the final decision to a person, and does not contact group members automatically.
FAQ
Can a buyer’s “we need SOC 2” request be satisfied with our existing report?
Only if the period, trust services criteria, and auditor meet the buyer’s checklist. Ask the four questions first.
What is the difference between SOC 2 readiness work and a SOC 2 examination engagement?
Readiness work is gap assessment and preparation without an independent opinion; an examination engagement is where a licensed CPA firm tests controls and issues the report.
Who can issue a SOC 2 report?
Only an independent service auditor—a licensed CPA firm—after performing the examination. Your sales team cannot issue one; route 3 goes to a qualified provider.
Next time a buyer writes “SOC 2 required before onboarding,” reply with the artifact question first; need, period, and date usually expose the route in one exchange.
Frequently asked questions
Can a buyer's "we need SOC 2" request be satisfied with our existing report?
Only if the period, trust services criteria, and auditor meet the buyer's checklist. Ask the four questions first.
What is the difference between SOC 2 readiness work and a SOC 2 examination engagement?
Readiness work is gap assessment and preparation without an independent opinion; an examination engagement is where a licensed CPA firm tests controls and issues the report.
Who can issue a SOC 2 report?
Only an independent service auditor—a licensed CPA firm—after performing the examination. Your sales team cannot issue one; route 3 goes to a qualified provider.
Sources and further reading
- AICPA & CIMA, System and Organization Controls suite of services (retrieved 2 August 2026)
- AICPA & CIMA, Key Elements of a SOC 2 Report — Resources for Management (5 June 2025)
- AICPA, Illustrative SOC 2 Report with Illustrative System Description (30 September 2023)
- Telegram Privacy Policy (accessed 2 August 2026)
