Auditen
framework watch

The vanity of the SOC 2 report

Most companies treat a SOC 2 Type II report like a diploma. They hang it on the digital wall, send it to every prospective customer, and assume it means the lights are on and the doors are locked. It's a piece of paper that says an auditor spent some time looking at a few samples and decided the controls were operating effectively.

The problem is that "effectively" is a flexible term.

Take the recent leak from tl;dv. Just over 180k meeting records ended up where they shouldn't have because of a vendor-related security failure. The kicker? They had their SOC 2 certification. This isn't an anomaly; it's the logical conclusion of how we audit third-party risk.

When I'm sitting across from a CISO, I don't care about the certificate. I care about what they can show me on a Tuesday. If you tell me your vendor management is "mature," I immediately start looking for where it's broken. Usually, it's in the gap between the policy and the practice.

A typical SOC 2 audit checks if you have a vendor risk management policy. It checks if you've collected some SOC 2 reports from your own vendors. It rarely checks if those vendors are actually doing what they say, or if you're monitoring them in real-time. The auditor sees a folder of PDFs and ticks a box.

The implication here is simple: the certification has become a procurement hurdle rather than a security benchmark. We've created a system where the goal isn't to be secure, but to be auditable.

Some will argue that SOC 2 provides a necessary baseline. They'll say it's better than nothing and forces a level of discipline on startups that would otherwise ignore security entirely.

That might be true for a seed-stage company, but for any firm handling hundreds of thousands of records, a baseline isn't enough. A "baseline" doesn't stop a leak if your sub-processor has an open S3 bucket. The auditor didn't check that bucket; they checked the policy that says you *should* check buckets.

The second-order effect here hits the insurers and the customers. Cyber insurance underwriters often give discounts or lower premiums to firms with SOC 2 certifications. If those certifications are paper shields, then the risk is being fundamentally mispriced. The customer, meanwhile, thinks they've offloaded their risk to a certified vendor, only to find out they're just one "vendor-related failure" away from a headline in the news.

We see this tension elsewhere too. GDPR fines hit just under €225 million in the second quarter of 2026. Regulators aren't looking at your certifications; they're looking at the fallout. They don't care that you have a SOC 2 report if the data is gone.

If you're relying on your vendors' certifications to sleep better at night, you're making a mistake. Stop asking for the report and start asking for proof of a specific control in action. Ask them to screen-share their current configuration for a high-risk asset.

If they can't do it on a Tuesday afternoon, that PDF in your procurement folder is worthless.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed