SOC 2 Quality Rubric
v1.0.0Community-developed criteria for evaluating SOC 2 report quality
Last updated: January 19, 2026
Three-Pillar Framework
Reports are evaluated across three fundamental dimensions that assess different aspects of quality and credibility.
27%
Structure
Does the report include required components and maintain professional consistency? Structure failures indicate the report may not meet professional standards.
36%
Substance
Do the controls, testing, and conclusions logically align and support each other? Substance failures mean the documented work doesn't support the conclusions.
37%
Source
What credentials, independence factors, and track record may affect report credibility? Source failures suggest factors that undermine independence or credibility.
Want to suggest changes to the rubric?
The rubric is community-maintained. Join the SOC 2 Quality Guild to contribute.