An alternative for that vendor is to request their policies - their information security policy, their Incident Response, etc. I realize these are not reviewed and tested by an audit firm, but it at least provides a record of what the vendor claims is going on. Is it best case? No. Is it better than nothing? Yes.
Not all companies are of a size that they can or will commit to paying for a SOC review. It is expensive, as has been noted.
I admit I prefer to see a SOC2 Type 2, but even that is not always possible.
The third party SOC is not completely useless, as it helps meet the requirements for looking at the vendor's third party vendors who have control over the information assets.
At the end of the day, there are actually things that the vendor can refuse - things like financials if they are a private company. If you have doubts about the company already, and this is just adding to them, then looking for a new vendor seems like the best course. If this is the only issue, then perhaps looking at increasing mitigating controls makes sense.
------------------------------
Dave Howe CCUFC
Chief Information Officer
Franklin First Federal Credit Union
------------------------------
Original Message:
Sent: 10-17-2025 09:19 PM
From: Cathy Ryan
Subject: Vendor Provided AWS SOC 2 Report and ISO Certificates
I agree this is frustrating. We often see this from start-ups and smaller (perhaps local) companies. A SOC audit can be fairly expensive and very time-consuming, and a small company may not have those resources. Partnering with a cloud provider like AWS does ensure a certain level of security, but you should also request documentation of completed AWS CUECs from your vendor. An ISO security (27001) certification audit performed by an independent third-party is a comprehensive audit. Request the entire audit - not just the certification. Clearly communicate your expectations to your vendor. Successful completion of a SOC audit can be written into your contract. However, understand that a SOC 2 audit requires a year of detailed record-keeping, BEFORE the audit is performed. Many companies start with a Type 1 audit because of that, and a Type 1 audit is also less expensive.
Original Message:
Sent: 10-17-2025 06:46 AM
From: Anonymous Member
Subject: Vendor Provided AWS SOC 2 Report and ISO Certificates
This message was posted by a user wishing to remain anonymous
I don't know if it is a red flag or not but it is concerning. The purpose of a SOC 2 is for a vendor to show how they manage security and related controls and unless they are Amazon, what they provided has minimal value.
I am going through a similar issue with a vendor that our external auditor flagged for providing a third-party SOC 2 report and a letter saying they have to follow the same controls. The auditor and myself are in agreement that we need to have a report for that vendor. If they won't provide one, the auditor and I will recommend that a replacement vendor be found.
If your vendor is providing a service that may impact upon financial reporting, the business function needs to go back to them and tell them they need to do their own SOC report.
There are no real substitutes for a SOC report. However, you can ask if they have had a security assessment based on NIST, ISO or other recognised security standard performed by a third-party. If so, ask for a copy of the report.
Hope this helps.
Original Message:
Sent: 10-15-2025 01:41 PM
From: Anonymous Member
Subject: Vendor Provided AWS SOC 2 Report and ISO Certificates
This message was posted by a user wishing to remain anonymous
Hello,
I have a new vendor that has only provided AWS SOC 2 report and certifications for security. On their company website the page for their privacy and security reports link directly to AWS. They have not provided any internal information security procedures, standards or reports. This is a red flag for me for a cloud-based platform usually used by Marketing departments or small businesses. How do other companies handle vendors like this? What questions should I ask? Are there any substitutes for information security reports you have requested? Thank in advance.
-------------------------------------------