SOC 2 exceptions and qualified opinions
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 2 min read · SOC 2
Buyers read the opinion and the exceptions, not just the logo. Knowing the difference between a noted exception and a qualified opinion is how you read — and pass — a report.
Exception vs qualified opinion
These are different severities. An exception is the auditor noting that, in their testing, a control did not operate as described in one or more instances — for example, two of forty access reviews were late. A qualified opinion is the auditor stating that one or more controls were not operating effectively enough for them to give a clean opinion. The first is common and survivable; the second is what a careful buyer scrutinises.
How exceptions happen
Most exceptions are operational drift: an access review that slipped, a change merged without the recorded approval, an offboarding that lagged. They are the gap between the control as designed and the control as run during the period — which is exactly what a Type II tests.
Reading a report like a buyer
When you receive a vendor's SOC 2, read the opinion letter first (is it unqualified?), then the exceptions in the testing section and management's responses. A report with no context-free exceptions and a clean opinion is strong; one with a qualification needs a conversation. This is also how your customers will read yours.
Minimising your own
Exceptions come from controls that run unreliably. The fix is operational consistency — recurring reviews that actually happen, change approvals that are enforced, offboarding that is prompt — and evidence captured as the work happens. SentinelPanda's job is to make those controls run on schedule so the period has no gaps to find.