Skip to content
Ridgeline Compliance
Read this first. We are not a CPA firm, so we provide SOC 2 readiness, gap analysis and preparation consulting only. The formal SOC 2 examination and report are performed by a separate, licensed, independent CPA firm.

Service

SOC 2 vendor management that keeps evidence each year

SOC 2 vendor management shows that you know which third parties touch your data and that you check them. So the examination looks for a list, a risk tier and a review record for each important vendor.

  • Readiness, not the audit
  • An independent CPA firm signs
  • Written estimate, no call
Soc 2 vendor management: list vendors, tier by risk and review and record

What auditors expect from SOC 2 vendor management

Criterion CC9.2 covers risks from vendors and business partners. Therefore auditors look for a current vendor list, a way of rating risk and evidence that key vendors were reviewed. The criterion text is in the AICPA Trust Services Criteria.

Building the vendor list

Start with anything that stores, processes or can reach customer data. Also include tools with admin access to your systems.

  • Cloud hosting and databases
  • Email, support and CRM tools holding customer data
  • Payment processors
  • Contractors with system access

SOC 2 vendor management check

Tick what you have today.

Your result appears here as you tick, so you can see what is still open.

Tiering vendors for SOC 2 vendor management

Not every vendor needs the same review. So tier them, then review proportionately.

TierExampleReview
HighHosting provider.Read their SOC 2 report annually.
MediumSupport desk with customer data.Security questionnaire or report.
LowDesign tool with no data.Listed, but no formal review.

Reading reports in SOC 2 vendor management

When a vendor shares its report, check the period, the opinion and any exceptions. Also read the complementary user entity controls, because those are duties the vendor expects you to perform. Missing them is a common finding.

SOC 2 vendor management as part of readiness

We build the list, the tiers and the review records with you, as part of our fixed readiness fee. However, the CPA firm examines the result, since we are not a CPA firm.

Keep the process light enough to repeat. For example, a short intake form for new tools, plus an annual review of the high tier, is usually enough for a small company. Also record any decision to accept a risky vendor, because a documented decision is evidence too. That way the examination finds a process, not a scramble.

SOC 2 vendor management questions

Do all vendors need a SOC 2 report?

No. High-risk vendors usually should have one, while low-risk ones can be listed only.

What if a vendor has no report?

Use a questionnaire or other evidence, and record the decision.

How often is SOC 2 vendor management reviewed?

Annually for key vendors, and before onboarding new ones.

What are complementary user entity controls?

Duties a vendor expects you to perform, so you must show you do them.

Related guides

Set up SOC 2 vendor management

Send a rough vendor list. We reply with a written scope and a fixed fee.

See if we can help