TPR-210Third-Party & Supply Chain Risk

Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations

A SOC 2 report can look clean while missing exactly what you rely on. Read the opinion, scope, exceptions, CUECs and carve-outs like an auditor.

6 lessons About 3 hours 3 ALCs Certificate on completion

Prepares you for: CCSP · AWS Certified Cloud Practitioner

What you'll be able to do

  • Read the auditor's opinion and understand what it really covers
  • Spot carve-outs and subservice organizations that leave gaps
  • Decide which exceptions matter to you
  • Write a review memo in under an hour
You finish with

A completed SOC report review

What's in it. What the opinion covers, what it carves out, which exceptions matter to you.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Vendor risk analysts, security reviewers and procurement staff who read SOC reports.

What's inside

  1. Part 1Where the requirement comes from 16 min
  2. Part 2How small teams and enterprises meet it 14 min
  3. Part 3The method, step by step 20 min
  4. Part 4Hands-on lab: small team choose one 90 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 20 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageYou have ten minutes per report; know where to look.
EnterpriseA review standard applied by a team, with bridge letters and period gaps tracked.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a completed SOC report review?6 lessons, about 3 hours. Start whenever you're ready.
Join and enroll