Last updated: July 26, 2026
Reports & Opinions · Compliance Q&A

Can I share my SOC 2 report with prospects?

Yes, but almost always under an NDA. SOC 2 reports are confidential, so companies share them with prospects and customers after a signed non-disclosure agreement. For a freely shareable version, use a SOC 3.

The full answer

Yes — sharing your SOC 2 report with serious prospects is a normal part of enterprise sales, and a Type 2 report is exactly what enterprise security questionnaires commonly ask for. The catch is that the report is confidential, so you almost always release it only after the prospect signs a non-disclosure agreement.

The reason is the content. A SOC 2 report describes your systems, your controls, and, in a Type 2, the auditor's specific tests and any exceptions. You do not want that circulating freely, so an NDA lets you share the full report while keeping control over who reads it. Most buyers expect this and have their own mutual NDA ready.

Timing matters too. Buyers generally treat a SOC 2 report as current for about twelve months from its period end date, so a prospect deep in due diligence will want your most recent report, not one nearing that mark. If there is a gap between your report's period end and their review, a management bridge letter can cover roughly three months.

If you would rather not gate every request behind an NDA, publish a SOC 3 — the public summary version — and reserve the full SOC 2 for qualified prospects. And if you do not have a current report yet, AuditNex network audits start at $2,500 promotionally and average about $5,000, so you can get a shareable Type 2 in hand before the deal stalls.

Go deeper

Short answer not enough? These pages cover the full picture:

SOC 2 Type 1 vs Type 2 ›  ·  Complete SOC 2 guide ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

All compliance questions ›

Sources: AICPA SOC 2 attestation guidance (SSAE No. 18); Enterprise security review market practice, 2026. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.