This website is currently in development and testing. Some content on here is still dummy and features may change or be unstable.

SOC 2 Quality Rubric

v1.0.0

Community-developed criteria for evaluating SOC 2 report quality

Last updated: January 19, 2026

View Source Doc

Three-Pillar Framework

Reports are evaluated across three fundamental dimensions that assess different aspects of quality and credibility.

27%
Structure
Does the report include required components and maintain professional consistency? Structure failures indicate the report may not meet professional standards.
36%
Substance
Do the controls, testing, and conclusions logically align and support each other? Substance failures mean the documented work doesn't support the conclusions.
37%
Source
What credentials, independence factors, and track record may affect report credibility? Source failures suggest factors that undermine independence or credibility.

Want to suggest changes to the rubric?

The rubric is community-maintained. Join the SOC 2 Quality Guild to contribute.

Join the Guild