Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What happens if you have SOC 2 audit exceptions?

Last verified

An exception is a deviation the auditor found when testing a control: a sampled item without the expected evidence, or a control that did not operate as described. Exceptions appear in the report with your management response. They do not automatically produce a qualified or adverse opinion.

SOC 2 audit exceptions, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.

This is what an exception is, not a verdict on YOUR report

Audience: a CISO, compliance owner, or founder reading a draft report with exceptions in it, and buyers trying to interpret one. This page explains the mechanism. It does not determine that YOU need SOC 2, does not predict your opinion, and does not issue a SOC 2 report.

The central point: an exception is not the same as a modified opinion. A Type II report can contain exceptions and still carry an unmodified opinion, and buyers routinely accept such reports. Whether a deviation is reported as an exception, and whether the accumulation of exceptions modifies the opinion, is the practitioner's professional judgement under AT-C section 205. It is not client discretion, not negotiable, and not something a management response overrides.

SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, and an exception is not a regulatory finding or a violation of law. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate to be revoked over an exception. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, which is where exceptions almost always arise, because that is where operation is tested. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Last verified 10 September 2026. Not legal advice.

Exception, deficiency, opinion — three different things

The vocabulary is used loosely in conversation and precisely in the report. The table draws the lines.

Deviation, exception, and opinion (paraphrase of the attestation standards; not legal advice; not a prediction about YOUR report)
TermWhat it meansWho decidesKind of text
DeviationA sampled item where the control did not operate as described — a change without approval, a leaver whose access lingered, a review not performed.Observed by the practitioner during testing.Attestation-standard requirement — the practitioner evaluates what they find.
ExceptionA deviation the practitioner concludes should be described in the report's test results, with its nature and extent.The practitioner's professional judgement under AT-C section 205, not yours.Attestation-standard requirement — reported in the description of tests and results.
Management responseYour written explanation next to the exception: cause, scope, and what you did or will do.You write it; the firm decides whether to include it and does not adopt it as its own conclusion.Best practice — a response is customary and useful, and it is your representation, not an audit finding.
Modified opinionA qualified or adverse opinion, or a disclaimer, where the practitioner concludes the criteria were not met in some or all respects.The practitioner alone.Attestation-standard requirement — the opinion types come from AT-C section 205.
"Failure"Not a term the report uses. There is no pass or fail; there is an opinion.Nobody — the framing itself is wrong.Market observation — the word survives in sales conversations and misleads everybody in them.

Why exceptions happen

Almost all exceptions in a first Type II come from a small set of causes, and none of them is exotic. Market observation, drawn from where testing concentrates.

  • Access not removed promptly when someone left, or removal with no dated record. The highest-volume source in most first examinations.
  • A production change approved by its own author, or deployed outside the pipeline with no record.
  • A periodic control — an access review, a vendor review, a risk assessment — performed later than the policy promised, or not at all in one quarter of the period.
  • Evidence that exists for part of the period only, because capture started after the period opened.
  • A policy that promises a cadence nobody keeps. The policy manufactures the exception; changing the policy to match reality before the period would have prevented it.
  • An onboarding or training step skipped for one hire in a sampled population.

How to respond well

A management response cannot remove an exception. It can determine whether a reader sees a team that understands its own control environment or one that does not. Best practice throughout.

  • State the cause plainly. "Deprovisioning was manual and one termination was missed" reads better than a paragraph of process language.
  • Quantify the extent honestly: how many items, out of what population, over what part of the period.
  • Say what changed, with a date. A remediation already implemented reads differently from one promised.
  • Do not blame the auditor, dispute the sampling, or argue the deviation is immaterial. Materiality is not yours to assert here.
  • Do not overpromise. A response committing to a control you will not sustain becomes next period's exception, now with a written record that you knew.
  • Ask the firm about wording, and accept that the exception description is theirs. You are writing the response, not the finding.
  • Track each exception in a risk or remediation register with an owner and a date, so the next period does not repeat it. SRM recommendation.

How buyers read exceptions

Worth knowing before you panic, and worth knowing if you are the one reading a vendor's report. Market observation about vendor-risk practice, not a rule.

  • Experienced reviewers expect some exceptions in a first Type II and read the pattern rather than the count.
  • One missed deprovisioning with a documented fix is usually a non-event. A cluster of access exceptions across the whole period is a theme.
  • A thoughtful management response with a dated remediation reassures; a defensive or vague one does the opposite.
  • An exception in a control the buyer specifically depends on matters more than an exception elsewhere, regardless of how the report weights them.
  • Repeat exceptions across consecutive periods are the strongest negative signal in the document, because they show nothing was done.
  • Some reviewers ask for the prior period's report to check exactly that. Best practice: assume they will.

Kinds of text on this page

Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.

How to read the claims on this page (not a ranking; not legal advice; last verified 10 September 2026)
Kind of textWhat it meansWhat it is not
Attestation-standard requirementSSAE 18 — AT-C sections 105 and 205 — including how deviations are evaluated and how opinions may be modified.Not a statute, and it binds the practitioner rather than you. An exception is not a legal finding.
Trust Services Criteria referenceA pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100.Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase.
Best practiceHow to write a management response and track remediation.Not required by any attestation standard, and it does not change the practitioner's conclusion.
Market observationHow buyers commonly read exceptions, and where exceptions commonly come from.Not a rule, and not a prediction about YOUR report or YOUR buyer.
SRM recommendationSomething this product suggests doing, such as tracking exceptions in a register.Not a legal requirement, not an attestation requirement, and not an audit opinion.

What to do now

If exceptions are in a draft in front of you, this is the order that helps. If they are not yet, the same list prevents them.

  • Read each exception and identify the population, the number of items, and the part of the period affected. Facts before framing.
  • Ask whether more evidence exists that was simply not provided. If it does, provide it now — the practitioner decides whether it changes anything.
  • Fix the underlying control immediately where you can, so the response can cite a date rather than an intention.
  • Write a short, factual management response per exception. Cause, extent, remediation, date.
  • Log every exception with an owner in a remediation or risk register, and put the next period's date on the calendar.
  • Tell your sales team what the report will say before a buyer reads it. Being surprised in front of a customer is worse than the exception.
  • Do not argue the deviation away. Whether it is an exception, and whether the opinion is modified, is the practitioner's judgement under the attestation standards.

Checklist

An exception-handling list, labelled by kind of text. Not a determination about your report.

  • Each exception's population, item count, and affected period understood? Attestation-standard requirement that the report describe nature and extent.
  • Additional evidence searched for and provided where it exists? Attestation-standard requirement that the practitioner evaluate sufficiency.
  • Root cause identified rather than described? Best practice.
  • Management response factual, quantified, and dated? Best practice — it is your representation.
  • Remediation implemented or scheduled with a named owner? SRM recommendation.
  • Exceptions logged so next period can be checked against them? SRM recommendation — repeat exceptions are the worst signal in a report.
  • Sales and leadership briefed before buyers read the report? Best practice.
  • Nobody arguing that an exception is automatically a qualified opinion, or that a response removes it? Attestation-standard requirement.

Where this shows up in ShipReady Metrics

The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner.

If you already have a session: evidence review with the met-verdict overlay is the surface most relevant here, because a named human recording that a control's evidence does not yet support it is the same finding you would rather not meet during fieldwork. That verdict is a human judgement inside your organisation, never an auditor's conclusion and never an opinion. The cyber risk register under the security area is where remediation for a deviation can be tracked with an owner and a date. Evidence collection and connector-sourced evidence — dependency, code-scanning, and secret-scanning ingest — reduce the class of exception caused by evidence that was never captured.

Nothing in this product decides whether a deviation is an exception, and nothing in it can change an opinion. Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.

Primary sources (last verified 10 September 2026)

Exception and opinion mechanics come from the AICPA attestation standards. How buyers react is labelled market observation, because no authority publishes that.

AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205, including the reporting requirements and the circumstances in which an opinion is modified. AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, proprietary AICPA material cited by reference and paraphrased, never reproduced. AICPA SOC 2 guidance for service organisations, including the presentation of tests and results in a Type II report. These are not a complete list, and none of them is legal advice.

The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.

Frequently asked questions