Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What happens if you fail SOC 2?
Last verifiedYou cannot fail SOC 2, because there is no pass or fail. The examination produces an opinion: unmodified, qualified, adverse, or a disclaimer. A qualified opinion names specific criteria that were not met; an adverse one is broader. All are recoverable through remediation and a new examination period.
What happens if you fail SOC 2, last verified 10 September 2026 against the AICPA Trust Services Criteria (TSP section 100 — 2017 criteria with the 2022 revised points of focus) and the AICPA attestation standards SSAE 18, AT-C sections 105 and 205. SOC 2 is an attestation examination performed by a licensed CPA firm and delivered as an opinion — a report, not a certification. This page is not legal advice, does not determine that YOU need SOC 2, and does not issue a SOC 2 report.
There is no pass or fail — there is an opinion
Audience: a founder or CISO worried about the outcome, or one holding a report with a modified opinion. This page corrects the framing and lays out the recovery path. It does not determine that YOU need SOC 2, does not predict your opinion, and does not issue a SOC 2 report.
"Failing SOC 2" is not a thing the report can say. Under AT-C section 205 the practitioner expresses an opinion, and the possible forms are an unmodified opinion, a qualified opinion, an adverse opinion, or a disclaimer of opinion. Which one you receive is the practitioner's professional judgement on the evidence they obtained. It is not client discretion, not negotiable, and not something a management response changes.
SOC 2 is market and contractual, not statutory: no statute requires a SOC 2 report, so a modified opinion is not a regulatory violation, not a fine, and not a legal finding. It is a commercial problem with your buyers. "SOC 2 certified" is a misnomer — there is no SOC 2 certificate to lose, and nobody revokes anything. Type I addresses the design of controls at a point in time; Type II addresses operating effectiveness over a review period, and a modified opinion can arise on either. Only a licensed CPA firm can perform a SOC 2 examination and issue the report; compliance-automation tooling, including this product, is not the attestor. Last verified 10 September 2026. Not legal advice.
The four opinion types
Read the opinion paragraph of any report first, including your own. The distinctions below are what a careful buyer is looking at.
| Opinion | What the practitioner is saying | What it means for buyers | Kind of text |
|---|---|---|---|
| Unmodified (commonly called unqualified) | In their opinion, the description is fairly presented and the controls were suitably designed — and, for a Type II, operated effectively throughout the period — to meet the criteria in scope. | The normal outcome buyers expect. Can still contain exceptions in the test results. | Attestation-standard requirement — the default form when the practitioner concludes the criteria were met. |
| Qualified | Everything holds except for specific, identified matters, which are described. The exception language is scoped: "except for…". | Recoverable and readable. Buyers look at what was excepted and whether it touches what they rely on. | Attestation-standard requirement — used when a matter is material but not pervasive. |
| Adverse | The description is not fairly presented, or the controls were not suitably designed or did not operate effectively, in respects the practitioner considers pervasive. | Serious. Most vendor-risk reviewers will treat it as a blocker pending remediation and a new period. | Attestation-standard requirement — reserved for pervasive matters. |
| Disclaimer of opinion | The practitioner cannot obtain sufficient appropriate evidence to form an opinion, so none is expressed. A scope limitation, not a conclusion about your controls. | Often reads worse than a qualification, because it says the work could not be completed. | Attestation-standard requirement — a scope matter under AT-C sections 105 and 205. |
What actually leads to a modified opinion
Ordinary exceptions rarely do. These are the situations that commonly do, and every one of them is visible before the report if anyone is looking. Market observation.
- A control described in the system description that was not actually in place during the period. The description, not just the control, is then wrong.
- A criterion with no control at all — for example a periodic review that never happened in any quarter of the period.
- Pervasive deviations in a high-volume area, such as most production changes lacking independent approval.
- Evidence that cannot be produced for a substantial part of the period, so the practitioner cannot conclude — the disclaimer path.
- A misstatement in management's assertion or description discovered during the examination, which raises a question the practitioner must resolve.
- Optional criteria categories claimed in scope but never operationalised, usually because someone added Availability or Privacy to sound thorough.
The recovery path
A modified opinion is a setback, not an ending. The path is ordinary work in a specific order. Best practice throughout, with the one attestation-standard reality noted: a new opinion requires a new examination.
- Read the opinion and the described matters carefully and write down exactly which criteria and which controls are named. Precision here prevents remediating the wrong thing.
- Ask the firm what evidence would have supported a different conclusion. They cannot design your controls, but they can tell you what was missing.
- Fix the control, not the paperwork. A policy edit does not create an operating history.
- Decide the next period with the firm. A new opinion requires a new examination over a new period — you cannot re-open a closed one. Attestation-standard requirement.
- Consider a shorter next period so a clean report exists sooner, if your buyers will accept the window. Market observation.
- Tell affected customers before they find out from the report, with the remediation and the date of the next period. Market observation about how deals survive this.
- Track every named matter in a risk or remediation register with an owner and a date, and verify it holds for the whole of the next period. SRM recommendation.
What to tell buyers
Commercial handling matters as much as the remediation. This is market observation about what works, not a script and not legal advice — check contractual notice obligations with counsel.
- Lead with the specific matter and its scope, not with reassurance. A buyer who has read the report already knows the reassurance is thin.
- State the remediation and when it was implemented, and offer the next period's dates.
- Do not describe the report as passed, clean, or certified. A reviewer reading the opinion paragraph will find the difference, and then the credibility problem is larger than the control problem.
- Expect some buyers to ask for compensating measures — additional contractual commitments, a shorter review cycle, or a bridge letter after the next period. That is a negotiation, not an entitlement on either side.
- Ask counsel whether any contract obliges you to notify a customer about the opinion. That is a contract question, not an attestation question.
Kinds of text on this page
Different sentences here carry different weight. The table labels which is which, so nothing on this page gets promoted into a rule it is not.
| Kind of text | What it means | What it is not |
|---|---|---|
| Attestation-standard requirement | SSAE 18 — AT-C sections 105 and 205 — including the opinion forms and the requirement for sufficient appropriate evidence. | Not a statute. A modified opinion is not a regulatory finding or a fine. |
| Trust Services Criteria reference | A pointer to a criteria series (CC1–CC9 or an optional category) in TSP section 100. | Not the criterion text. The Trust Services Criteria are proprietary AICPA material; everything here is paraphrase. |
| Best practice | The remediation sequence and how to communicate it. | Not required by any attestation standard, and it does not change an issued opinion. |
| Market observation | How buyers commonly react, and which situations commonly produce a modified opinion. | Not a rule, and not a prediction about YOUR report or YOUR customers. |
| SRM recommendation | Something this product suggests doing, such as tracking each named matter in a register. | Not a legal requirement, not an attestation requirement, and not an audit opinion. |
What to do now
If you are holding a modified opinion, work this order. If you are not, the same list is the cheapest insurance against one.
- Identify every criterion and control named in the opinion, and separate those from ordinary exceptions in the test results.
- Ask the firm what was missing, and write the answer down before starting work.
- Remediate the control and prove capture works, then leave it running long enough to have an operating history.
- Agree the next period with the firm, including whether a shorter window is acceptable.
- Brief leadership and sales with the specific matter, the remediation, and the next period dates — before a buyer raises it.
- Ask counsel about any contractual notice obligation the opinion triggers.
- Reconcile the system description with reality. A description that overstates what exists is the fastest route to a repeat.
Checklist
A recovery list, labelled by kind of text. Not a determination.
- Opinion type identified precisely — unmodified, qualified, adverse, or disclaimer? Attestation-standard requirement.
- Named matters separated from ordinary exceptions? Attestation-standard requirement that the report describe both.
- Root cause fixed in the control, not in the policy text? Best practice.
- Next examination period agreed with the CPA firm? Attestation-standard requirement — a new opinion needs a new examination.
- Evidence capture verified working from day one of the next period? Best practice.
- Each named matter tracked with an owner and a date? SRM recommendation.
- Customers informed before they read it, and counsel asked about notice obligations? Market observation plus a legal question for counsel.
- Nobody describing the report as passed, clean, or certified? Best practice — the misnomer compounds the damage.
Where this shows up in ShipReady Metrics
The bundled framework key soc2 is customer-visible, labelled against the 2017 Trust Services Criteria with the 2022 revised points of focus, with a starter control-set that is an illustrative readiness mapping to be tailored by a compliance owner.
If you already have a session: readiness scoring and evidence review with the met-verdict overlay are the surfaces that make a weak control visible before an examination rather than after it — a named human recording that evidence does not yet support a control is precisely the signal a modified opinion later formalises. That verdict is an internal judgement, never an opinion. The cyber risk register under the security area tracks remediation for each named matter with an owner and a date. Evidence collection and connector-sourced evidence — dependency, code-scanning, and secret-scanning ingest — address the evidence-never-captured cause directly.
Nothing in this product changes an issued opinion or predicts one. Readiness in this product is not an attestation opinion. This product does not issue a SOC 2 report and does not replace a licensed CPA examination. There is no public SOC 2 demo URL.
Primary sources (last verified 10 September 2026)
Opinion forms come from the AICPA attestation standards. Buyer reactions and common causes are labelled market observation, because no authority publishes them.
AICPA attestation standards SSAE 18, AT-C section 105 and AT-C section 205, including the forms of opinion and the circumstances in which an opinion is qualified, adverse, or disclaimed. AICPA Trust Services Criteria, TSP section 100 — 2017 criteria with the 2022 revised points of focus, proprietary AICPA material cited by reference and paraphrased, never reproduced. AICPA SOC 2 guidance for service organisations. These are not a complete list, and none of them is legal advice.
The SOC 2 framework guide on this site is the education page under frameworks; this cluster does not reuse that slug. The SOC 2 versus ISO 27001 comparison on this site is live. A dedicated ISO 27001 docs cluster is not on this site yet — naming ISO 27001 in prose is not a link to it.