SOC 2 · Evidence requests
The SOC 2 questionnaire: what buyers are really asking, and how to respond.
"SOC 2 questionnaire" gets used for two different documents, and knowing which one you're holding changes everything about how to respond. This guide untangles the terms, lists what buyers actually request, and shows how to answer credibly — including when you don't have a SOC 2 report yet.
SOC 2 report vs SOC 2 questionnaire — they are not the same thing
A SOC 2 report is an independent audit: a CPA firm examines your controls against the Trust Services Criteria and writes an opinion. Type I covers a point in time; Type II covers a period (usually 6–12 months of evidence).
A SOC 2 questionnaire — what buyers usually mean — is one of:
- A security questionnaire organized around SOC 2 domains, sent because the buyer's risk process is anchored to the Trust Services Criteria.
- A SOC 2 evidence request: "send your report, bridge letter, pen test, and proof of these specific controls."
- A readiness checklist from a buyer assessing whether you're on a credible path to certification.
The first move is always the same: identify which of the three you've received, because the right response to each is different — and only one of them strictly requires a report.
What buyers typically request
- The report itself (under NDA), plus a bridge letter if the audit period has lapsed.
- Penetration test summary — recent, scoped to the product they're buying.
- Control evidence — access review cadence, encryption at rest and in transit, incident response process, backup and recovery testing, vendor management.
- Policies — information security, acceptable use, business continuity; sometimes verbatim, sometimes summarized.
- Subprocessor list — who else touches their data through you.
Responding without a SOC 2 report
Not having the report is common and survivable — smaller vendors win enterprise deals on evidenced answers all the time. What works:
- Answer the underlying question, not the missing document. The buyer wants assurance about access control, not the PDF for its own sake. Describe the control you run and cite the evidence.
- Be specific where you're strong. Named tools, dated reviews, real cadences. Specificity is what substitutes for the auditor's signature.
- Structure the gaps. "Not yet — compensating control today, certification roadmap with timeline." Buyers accept roadmaps; they reject vagueness.
- Never imply a report exists when it doesn't. That one gets discovered in procurement follow-up, and it costs the whole answer set its credibility.
If you do have the report
Lead with it — many buyers will accept it for entire questionnaire domains and only ask deltas. Attach the bridge letter proactively if your period has lapsed, and keep a one-page summary of scope and exceptions ready; it pre-answers the follow-up call.
How to answer a SOC 2 questionnaire, step by step
Whichever of the three documents you've received, the working sequence is the same:
- Map every question to your SOC 2 report — or to the Trust Services Criteria if you don't have one. If you hold a report, tag each question with the report section that already answers it; most of the questionnaire collapses into "covered by the attached report, section X." Without a report, map questions to the TSC domains (Security, Availability, Confidentiality, Processing Integrity, Privacy) so your answers follow the structure the buyer's reviewer is scoring against.
- Reference the auditor's report instead of re-asserting controls. "Access reviews are tested in our SOC 2 Type II, section IV, control CC6.2 — no exceptions noted" carries an independent opinion behind it. Re-describing the control in your own words throws that weight away and invites inconsistencies between your prose and the auditor's.
- Handle the bridge-letter question before it's asked. If your report's period has lapsed, attach a bridge letter covering the gap proactively. Reviewers check report dates first; a lapsed period with no bridge letter reads as a vendor who hasn't looked at their own report lately.
- Answer "do you have SOC 2?" honestly when the answer is no. Describe the control you actually run, cite the evidence, and structure the gap with a roadmap — the full pattern is in responding without a SOC 2 report above. Never imply a report exists when it doesn't.
- Keep the answer library. Save every answer with its report-section or TSC mapping and the date you verified it. The next SOC 2-shaped questionnaire — and the renewal of this one after your next audit period — starts from that library instead of from zero.
When the answer is no: closing SOC 2-specific gaps
SOC 2 questionnaires concentrate on the monitoring, change-management, and logical-access criteria — and those are buildable. Open-source components, deployed and operated, produce exactly the evidence those TSC questions ask for:
- Monitoring (CC7): Managed Wazuh — detection and centralised logging that answers "how would you know?" with an alert pipeline.
- Change management (CC8): Managed SonarQube — quality gates on every merge, so the release-control answer cites a pipeline, not a policy.
- Logical access (CC6): Managed Teleport — access provisioning and session records aligned to the criteria reviewers quote.
Turning it around in days
SOC 2 evidence requests stall for the same reason all questionnaires stall: the answers live in five heads and nobody owns the response. ThinSky's Questionnaire Rescue takes the request end-to-end — truthful answers cited to your actual controls, a gap map before you commit anything to writing, and a reusable answer library — in about 3 days, fixed price quoted up front. If you don't yet have a SOC 2 report and the gap is "we need to BUILD the controls, not just describe them", that's our Rapid Compliance programme: open-source security stack deployed into an adjacent tenant you own, policies written, audit run alongside you.
Common questions.
Is a SOC 2 report the same as a security questionnaire?
No. A SOC 2 report is an independent auditor's opinion on your controls over a period. A security questionnaire is the buyer asking you directly. Having SOC 2 shortens questionnaires — many buyers accept the report for whole domains — but it rarely eliminates them.
Can we answer a security questionnaire without a SOC 2 report?
Yes. Answer to the controls you actually run and cite them specifically. Many buyers accept strong, evidenced answers plus a roadmap in place of a report — especially from smaller vendors. What they won't accept is a vague 'we take security seriously.'
What do buyers ask in a SOC 2 evidence request?
Typically: your most recent SOC 2 report, bridge letter if the report period has lapsed, penetration test summary, proof of specific controls (access reviews, encryption, incident response, vendor management), and sometimes policies themselves. Each item maps to a Trust Services Criteria domain.
How fast can a SOC 2 evidence request be turned around?
If your documentation exists and someone owns the response, days. ThinSky completes SOC 2 evidence requests and security questionnaires as a done-for-you service in about 3 days, citing your real controls — fixed price quoted up front.