SOC 2 · Third-party risk

SOC 2 vendor review for IT and SaaS procurement

Upload a vendor SOC 2 Type I or Type II report and Governly maps it against your requirements to produce a transparent, traceable Decision Report — covering scope, trust service criteria, exceptions and the controls you still need to operate on your side.

What Governly checks in a SOC 2 report

A SOC 2 report is only as useful as the parts that actually apply to the service you're buying. Governly extracts the structural details that matter for third-party risk decisions.

  • Report type (Type I vs Type II) and reporting period
  • Scope of systems, services and trust service criteria covered
  • CPA firm, opinion type and any qualifications
  • Exceptions, deviations and management responses
  • Complementary user entity controls (CUECs) you must implement
  • Sub-service organisations and carve-outs

Where SOC 2 review fits

SOC 2 review is one input into a complete vendor assessment. Pair it with a DPA review under GDPR and an ISO/IEC 27001 check to get a full picture before you sign.