What is a carve-out vs inclusive SOC 2 report?
Carve-out and inclusive describe how a SOC 2 handles your subservice providers. A carve-out excludes their controls and just names them; an inclusive report folds their controls into your audit and tests them. Carve-out is far more common.
The full answer
Most companies rely on subservice organizations, such as AWS, Google Cloud, or a payroll processor, to run part of their service. A SOC 2 has to say how it treats those providers' controls, and there are two methods: the carve-out method and the inclusive method.
With the carve-out method, your report describes the subservice provider, names it, and states which functions it handles, but it excludes that provider's controls from your auditor's testing. Instead, the report lists complementary subservice organization controls you expect the provider to operate, and readers typically rely on that provider's own SOC 2 to cover them. This keeps your scope focused on controls you actually run.
The inclusive method pulls the subservice provider's relevant controls into your system description and your auditor tests them alongside yours. It gives a more complete picture but is much harder to arrange, because the provider must cooperate, share evidence, and sign onto the engagement. Large cloud vendors will not do this, which is why the inclusive method is rare.
For nearly every startup, carve-out is the right and expected choice, and buyers know to also collect the SOC 2 reports of your major subprocessors. Under the AICPA's SSAE No. 18 standards a licensed CPA firm can only opine on controls it actually tests, so be honest about the boundary. When you scope a SOC 2 through the AuditNex network, where audits start at $2,500 and average about $5,000, the licensed firm helps you list subservice providers correctly.
Go deeper
Short answer not enough? These pages cover the full picture:
Get matched with the right auditor
Answer a few questions about your scope and see transparent, comparable pricing from vetted audit firms — no sales calls.
Get instant pricing →Talk to auditors who handle this every week
Every firm on AuditNex is listed on identical terms — placement cannot be bought, and credentials are independently checked.
Related questions
Are SOC 2 reports public?
No. A SOC 2 report is confidential and shared only under NDA with customers, prospects, and auditors. If you want a freely shareable version, the public summary is a SOC 3 report.
Can I share my SOC 2 report with prospects?
Yes, but almost always under an NDA. SOC 2 reports are confidential, so companies share them with prospects and customers after a signed non-disclosure agreement. For a freely shareable version, use a SOC 3.
Can buyers verify my SOC 2 report is real?
Yes. Buyers verify a SOC 2 by confirming the signing CPA firm is licensed, checking the report period and opinion, and often contacting the firm directly. A real report names a licensed firm and follows AICPA formatting.
Can one SOC 2 report cover multiple products?
Yes. One SOC 2 report can cover multiple products or systems as long as they share the same control environment and you define that scope clearly in the system description. Many companies audit their whole platform in a single report.
How long is a SOC 2 report valid?
There is no formal expiry — the AICPA sets none. In practice, buyers treat a SOC 2 report as current for about twelve months from its period end date, then expect a fresh Type 2.
What are complementary user entity controls (CUECs)?
Complementary user entity controls, or CUECs, are controls the service organization assumes its customers will operate for the overall controls to work. They are listed in the SOC 2 report, and the auditor does not test them.
Sources: AICPA SSAE No. 18 attestation standards; AuditNex network rate card, 2026. Answer written and maintained by the AuditNex research team; last reviewed July 26, 2026. AuditNex is a marketplace — accredited firms price and scope engagements independently.