Last updated: July 26, 2026
Reports & Opinions · Compliance Q&A

What is a carve-out vs inclusive SOC 2 report?

Carve-out and inclusive describe how a SOC 2 handles your subservice providers. A carve-out excludes their controls and just names them; an inclusive report folds their controls into your audit and tests them. Carve-out is far more common.

The full answer

Most companies rely on subservice organizations, such as AWS, Google Cloud, or a payroll processor, to run part of their service. A SOC 2 has to say how it treats those providers' controls, and there are two methods: the carve-out method and the inclusive method.

With the carve-out method, your report describes the subservice provider, names it, and states which functions it handles, but it excludes that provider's controls from your auditor's testing. Instead, the report lists complementary subservice organization controls you expect the provider to operate, and readers typically rely on that provider's own SOC 2 to cover them. This keeps your scope focused on controls you actually run.

The inclusive method pulls the subservice provider's relevant controls into your system description and your auditor tests them alongside yours. It gives a more complete picture but is much harder to arrange, because the provider must cooperate, share evidence, and sign onto the engagement. Large cloud vendors will not do this, which is why the inclusive method is rare.

For nearly every startup, carve-out is the right and expected choice, and buyers know to also collect the SOC 2 reports of your major subprocessors. Under the AICPA's SSAE No. 18 standards a licensed CPA firm can only opine on controls it actually tests, so be honest about the boundary. When you scope a SOC 2 through the AuditNex network, where audits start at $2,500 and average about $5,000, the licensed firm helps you list subservice providers correctly.

Go deeper

Short answer not enough? These pages cover the full picture:

SOC 2 Type 1 vs Type 2 ›  ·  Complete SOC 2 guide ›

Get matched with the right auditor

Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.

Get instant pricing →

Talk to auditors who handle this every week

Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.

All auditor profiles ›

Related questions

All compliance questions ›

Sources: AICPA SSAE No. 18 attestation standards; AuditNex network rate card, 2026. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.