Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Mergers & acquisitions

Is a SOC 2 report enough to prove an acquisition target is secure?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

No. A SOC 2 report is useful evidence but does not prove an acquisition target is secure. It reflects a target-selected scope, a closed audit window, and only the controls the target chose to include — not your risk appetite. It says nothing definitive about privacy compliance, undisclosed breaches, data residency, AI use, or post-close integration risk. Treat SOC 2 as one input and verify the rest through independent due diligence.

On this page

Why isn't a SOC 2 report enough on its own?

A SOC 2 report is meaningful evidence, but it is not a clean bill of health for an acquisition. It is an attestation by an independent CPA firm that, for a defined scope and over a defined period, the target's controls were suitably designed (Type 1) or also operated effectively (Type 2) against the Trust Services Criteria the target selected. Every one of those qualifiers limits what the report actually proves.

The scope is chosen by the target, not by you. A company can carve a single product line into scope and leave the rest of the business out. It can include only Security and omit Confidentiality, Privacy, Availability, and Processing Integrity. The audit covers a window that has already closed, so it tells you little about what changed after the period ended. And an unqualified opinion confirms the controls met the chosen criteria — not that those criteria match the risk you are taking on.

  • Scope is self-selected: the target defines which systems, products, and entities are in or out.
  • Criteria are optional: only the Security category is mandatory; Confidentiality, Privacy, Availability, and Processing Integrity may be excluded.
  • It is point-in-time (Type 1) or period-based (Type 2): even a Type 2 covers a closed past window, not today.
  • It is not a privacy or legal opinion: SOC 2 does not certify PIPEDA, Quebec's Law 25, PHIPA, GDPR, or HIPAA compliance.
  • Exceptions matter: many reports contain noted exceptions or a qualified opinion in the testing detail.

What does a SOC 2 report actually prove — and what does it miss?

A SOC 2 report proves that an independent CPA firm examined a specific set of controls and formed an opinion on them. Read properly, it tells you which Trust Services Criteria were assessed, the period covered, the systems in scope, the subservice organizations relied on, the auditor's opinion, and — critically — any exceptions found during testing. That is genuinely valuable information.

What it does not tell you matters just as much in an acquisition. The report will not reveal whether the target has had unreported security incidents, where regulated data physically resides, whether consent and data-sharing practices are lawful, how AI or third-party models touch personal information, or whether the team can sustain those controls after key people leave at close. None of that is in scope for a SOC 2, yet all of it can become your liability the day the deal closes.

  • Not covered: undisclosed or under-reported breaches and any related notification obligations.
  • Not covered: privacy-law compliance (consent, retention, cross-border transfer, data-subject rights).
  • Not covered: data residency — where regulated data is actually stored and processed.
  • Not covered: AI and machine-learning systems, training data, and vendor model exposure.
  • Not covered: technical depth — a SOC 2 is a controls audit, not a penetration test or code review.
  • Not covered: integration and key-person risk once the target merges into your environment.

How should you read a SOC 2 report during diligence?

Read past the opinion paragraph and into the detail. The cover opinion is where most buyers stop, but the evidence that affects valuation and risk sits in the body of the report. A careful reviewer reconstructs what was actually tested, how recently, and what failed.

Work through the report deliberately and compare what it claims against what the target told you elsewhere in diligence.

  • Confirm it is a Type 2, not a Type 1 — operating effectiveness over time is far stronger than design at a point in time.
  • Check the period covered and the gap to today; request a bridge (gap) letter for any months since the period ended.
  • List the Trust Services Criteria in scope and note which were excluded, especially Privacy and Confidentiality.
  • Map the in-scope systems and entities to the actual business you are buying — watch for carve-outs.
  • Read every noted exception and the auditor's response; a qualified opinion is a red flag, not a footnote.
  • Review complementary user-entity controls and any carve-out subservice reliance — gaps there transfer to you.
  • Verify the report was issued by a licensed CPA firm and is current, not expired.

What else belongs in M&A security and privacy due diligence?

Treat the SOC 2 as one input and build the rest of the picture around it. Comprehensive M&A privacy and security due diligence independently verifies what a SOC 2 cannot, so you price the risk correctly and avoid inheriting undisclosed liabilities. The goal is to confirm the target is secure and compliant in reality — not just in the documents it chose to share.

A thorough review typically combines independent technical testing, a privacy and data-handling assessment, and a review of past incidents and contractual obligations. Where the target operates across multiple jurisdictions, the privacy picture has to be assessed jurisdiction by jurisdiction rather than assumed from one report.

  • An independent threat and risk assessment (TRA) of the target's architecture and controls.
  • Penetration testing to validate real-world exploitability, which a controls audit cannot show.
  • A privacy assessment covering consent, retention, cross-border data flows, and data-subject rights under applicable laws.
  • An AI Privacy Impact Assessment where the target uses AI or processes data through third-party models.
  • A breach and incident history review, including notification obligations and any unremediated findings.
  • A vendor and subprocessor review to understand downstream data exposure.
  • A post-close integration plan so the target's controls survive the merger and key-person departures.

When can a SOC 2 carry more weight in a deal?

A SOC 2 carries more weight when it is broad, recent, and clean — and when it lines up with everything else you have verified. A current Type 2 report that includes Security, Confidentiality, and Privacy, covers the full business in scope, has no exceptions, and is corroborated by independent testing is strong supporting evidence. The same report with a narrow scope, an expired period, or buried exceptions tells you to dig deeper, not to relax.

Even at its best, a SOC 2 supports your conclusion rather than replacing your own diligence. A SOC 2 opinion offers reasonable assurance — assurance, not a guarantee — so the buyer who treats it as one corroborated input, weighted against independent findings, is the buyer who avoids surprises after close.

Frequently asked questions

No. SOC 2 is a security and controls attestation, not a legal compliance opinion. Even a report that includes the Privacy Trust Services category does not certify compliance with PIPEDA, Quebec's Law 25, PHIPA, GDPR, or HIPAA. Privacy compliance must be assessed separately, jurisdiction by jurisdiction.

Generally no. A Type 1 only confirms that controls were suitably designed at a single point in time, not that they actually operated effectively. For acquisition diligence you want a Type 2, which tests operating effectiveness over a period — ideally several months and recent.

As recent as possible — and you should mind the gap. Reports cover a closed audit period, so if months have passed since the period ended, request a bridge (or gap) letter from the target confirming no material changes, and weight older reports accordingly. An expired report should not be relied on alone.

Watch for a narrow or carved-out scope that excludes the business you are buying, a Type 1 where you expected a Type 2, an expired audit period, excluded categories such as Privacy or Confidentiality, noted testing exceptions, a qualified opinion, and heavy reliance on carve-out subservice organizations whose own controls you cannot see.

No. A SOC 2 is a controls audit, not a technical security test. It confirms that policies and processes exist and were followed, but it does not attempt to exploit the systems. A penetration test validates real-world exploitability that a SOC 2 cannot demonstrate.

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.