DisclosureIndependent directory. Not a CPA firm. Nothing here is legal, audit, or tax advice. Methodology.

Can my customers see my SOC 2 report?

By Editorial team · Published · Last updated

Yes, under NDA. SOC 2 reports are not public — they are shared one-to-one with customers and prospects after a signed mutual NDA.

Short answer: yes, but only under NDA. SOC 2 reports are confidential by industry convention. They contain detailed control descriptions, vendor names, and sometimes specific findings — information that would be sensitive in competitor or attacker hands. The standard distribution model is one-to-one sharing under a signed mutual NDA.

Who can see the full report

What you can publish without an NDA

How the standard distribution flow works

  1. Prospect requests SOC 2 report during procurement.
  2. You send a mutual NDA template (or use the prospect's).
  3. Both parties sign — typically through DocuSign or similar in 1 to 5 business days.
  4. You share the PDF report through a secure delivery method: trust center download, encrypted email, or your data room.
  5. The prospect's security team reviews and either signs off on procurement or sends follow-up questions.

Trust center platforms that streamline this

Most GRC platforms ship a trust center feature that automates NDA-gated report distribution. Vanta Trust, Drata Trust Center, and SafeBase are the most common. They handle the NDA acceptance, log who downloaded the report, and notify you on access. For startups, a free trust center page (Vanta or Drata) plus a manual NDA process is usually sufficient.

What happens if a SOC 2 report leaks

Practically, the auditor's reputation is at stake; yours is too. Most NDAs include damages clauses for unauthorized disclosure. The bigger downside is that detailed control descriptions become available to attackers and competitors, and your auditor may push you toward stricter distribution controls in subsequent cycles. Use a trust center with download tracking — manual emailing of the PDF is less defensible if a leak happens.