Sharing your SOC 2 report with customers
You paid for the report — now make it sell. How to distribute your SOC 2 report securely, what customers actually ask for, and the mistakes that leak it.
The report is confidential — treat it that way
A SOC 2 Type 2 report contains detailed descriptions of your systems and controls. It is not a marketing document: share it under NDA, never post it publicly. (If you want something public, that's what SOC 3 is for — a general-use summary report without the control details.)
What customers actually ask for
- The full Type 2 report (most common) — shared under NDA during security review.
- A bridge letter — if your last report period ended months ago, auditors can issue a "bridge letter" stating nothing material changed since. Ask your auditor; it's routine.
- The auditor's attestation letter — a short letter confirming the report exists, for buyers who just need a checkbox.
- Your security questionnaire answers — the report supplements these, it doesn't replace them.
Set up a trust center
Once you're sharing the report more than a few times a quarter, stop emailing PDFs. A trust center (dedicated page or a tool like SafeBase, Conveyor, or Drata's trust center) lets prospects request access, sign an NDA, and download the current report — without your sales team playing document courier. Keep exactly one current report published and archive the rest.
Distribution hygiene
- NDA first, report second. Mutual NDAs are standard; most buyers expect the dance.
- Track who has it. Log every disclosure — customer, date, report period. You'll thank yourself at renewal.
- Never email it unencrypted to a personal address. Use your trust center or secure share.
- Renew before it expires. A report covering a period that ended 9+ months ago starts raising eyebrows. Time your re-audit so a fresh report is always within reach — see our timeline guide.
- Don't cherry-pick. Sharing only clean pages while hiding exceptions destroys trust faster than the exceptions themselves.
Questions
Can I share my SOC 2 report publicly?
No — a SOC 2 Type 2 report contains detailed system and control descriptions and must be shared under NDA. If you want a public-facing document, ask your auditor about a SOC 3 report, which is designed for general distribution.
What is a SOC 2 bridge letter?
A bridge letter is a short letter from your auditor stating that nothing material changed between the end of your last report period and today. Customers often request one when your most recent report is several months old.
Need next year's report lined up?
Get quotes for your renewal audit before the current report goes stale.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.