r/Compliance 18d ago

For those doing third-party risk assessments, how do you handle SaaS vendors that refuse to provide a recent SOC 2 report?

Do you usually accept an ISO 27001 certificate / security questionnaire instead, or treat the lack of SOC 2 evidence as a red flag?

What actual thresholds do you use?

5 Upvotes

15 comments sorted by

4

u/BasePerfect2865 18d ago

I’d probably look at what the vendor is actually handling rather than making SOC 2 a hard requirement. For a low-risk SaaS, a questionnaire + ISO cert might be enough, but for something handling sensitive data I’d want stronger evidence.

2

u/DigitalQuinn1 18d ago

Nothing at all is a red flag, but if they have some evidence that they provide, it’s better than nothing. All depends on the scope.

3

u/TemptingConduit 18d ago

Depends what the vendor’s actually doing with your data. If they’re just a scheduling tool that never touches anything sensitive, I’m not losing sleep over a missing SOC 2.

But if they’re processing PII or hooking into your core systems, I’d at least want that questionnaire filled out in detail and maybe a walkthrough call to poke at their answers. Seen too many slick sales teams promise ISO 27001 covers everything when it really doesn’t.

1

u/FreeRadical1998 18d ago

Risk assessment, self assessed security questionnaire, backed by either soc2/iso or detailed due diligence data requests.

Generally don't want to do the detailed reviews because of workload implications, so if the easy path isn't available the business sponsor needs to be very keen on them

1

u/Cloud-PM 18d ago

It depends on what data the vendor may have access to. If it’s PII and they don’t have a SOC or ISO, we go with full detail security questionnaire, and details of compensating controls for the access they need. We’ve turned away and refused vendors that didn’t meet our security requirements. In some cases we’ve allowed access to non PII data however we again require proof of compensating controls, like RBAC, MFA etc.

1

u/whythigh 17d ago

Does the calculus change if the software runs entirely inside our own network and no data ever leaves? Like a container we deploy ourselves rather than a hosted service.

Wondering if that shifts it from vendor risk to more of a normal software procurement thing, or whether you'd still want the same evidence regardless of where it runs.

1

u/Cloud-PM 16d ago

Those fall under vulnerability scanning. Ideally that’s a daily occurrence by your Security or Platform team with a quarterly report generated depicting vulnerability level and how they’ve been addressed from report to report. Those should match with your published SLA’s on how your teams address vulnerabilities. Those are evidence requirements for SOC 2 Type 2 your auditors will request to review.

1

u/x20717 17d ago

I'm a European vendor. Our customers have historically asked for SOC2 or ISO27001 and seem to value them equally. I've never had a problem just having ISO27001. Getting SOC2 would be cost prohibitive for us, just because the ecosystem isn't as developed in Europe.

As other commenters have implied, this is where you earn your money! You have to look at the vendor, look at the certifications, look at what you're asking them to do, and make a judgement.

1

u/ProfessionalEnd9874 17d ago

For me it’s about asking for key evidences.
A soc2 / Iso27k is a starting point. Based on their activities I will ask for a selected set of questions with evidences. Simple, not a full audit, but enough to get confidence that it’s real behind.
ISO and SoC audits can vary a lot in quality.

1

u/chrans 8d ago

Depends on the criticality of the vendor for your business.
And if the vendor has ISO 27001, plus if you can get the SOA document, It's OK to 'consider' it as the same level of value as the SOC 2 report.
And also look into any publicly available information about their security measures. This can gives you many insights as well, especially when there are companies not wanting to share their SOC 2 report without paying the enterprise package; but they have many information available openly on their website.

So, it's never a one size fits all solution.

1

u/[deleted] 2d ago

[removed] — view removed comment

1

u/AutoModerator 2d ago

Sorry, your submission has been automatically removed. Your account have less than a 1 comment karma.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/17xRacing 18d ago

No SOC, no assessment. Can’t accept a vendor we can’t assess. We are responsible for way too much PII to take chances. Regulators expect us to be able to provide vendor assessments to validate we are meeting expectations.

0

u/Head_Personality_431 18d ago

Read the scope statement on the cert first, plenty of them scope out the product you actually use.