After your first SOC 2 report: sharing, renewing and the next framework
Once the report arrives, share it under NDA, keep controls running for the next period, and plan the renewal. Most customers expect a current report every year. This is also the moment to decide whether ISO 27001 or another framework comes next.
How do you share a SOC 2 report?
Usually under a nondisclosure agreement, on request. A trust center page lets prospects see your security posture and request the report without an email chain. Vanta and Secureframe list a Trust Center in their published plans, and Scytale offers it as a separate Trust Center product; Scytale says its Trust Center launches in under 10 minutes and is pre-filled from compliance data (Scytale's claim).
What is a bridge letter?
A bridge letter, sometimes called a gap letter, is a statement from your management covering the time between the end of your last report period and today. Customers ask for it when your report is a few months old. It is written by you, not the auditor.
How often do you renew SOC 2?
A Type II report covers a past period, so it ages. Most companies run a new examination every year so there is always a recent report. Keep controls running continuously; a gap between periods shows up in the next report.
What about security questionnaires?
The report reduces questionnaires but does not end them. Some tools include questionnaire automation: Vanta lists 25 per year on Plus and 144 on Professional; Secureframe lists questionnaire automation in Complete; Scytale pairs AI auto-fill with human expert review.
When should you add a second framework?
When customers or markets ask for it. ISO 27001 is the usual next step for companies selling internationally; the current edition, ISO/IEC 27001:2022, was published in October 2022. HIPAA, GDPR and ISO 42001 follow for health data, EU personal data and AI governance. Tools that cross-map controls let one piece of evidence count toward several frameworks. Scytale states 80+ frameworks with control cross-mapping and Vanta states 35+.
Further reading
- ISO/IEC 27001:2022 at iso.orgSource: iso.org · Read 2026-09-29
What should you read next?
NextBack to the tool ranking
Questions founders ask
Do we need a new SOC 2 report every year?
Not by rule, but most customers ask for a report covering a recent period, so annual renewal is the norm.
What is the difference between SOC 2 and ISO 27001?
SOC 2 is a CPA firm's attestation report on your controls; ISO 27001 is a certification of your information security management system by an accredited certification body. Many companies end up with both.