SOC 2 Quality Guild

February 17, 2026 ยท View on GitHub

Practitioner-driven standards for SOC 2 report reliability

A community creating standardized evaluation criteria to help GRC and TPRM practitioners assess how much weight to give a SOC 2 report when making vendor trust decisions.

๐ŸŒ Website: s2guild.org
๐Ÿ’ฌ Community: Join Slack


What We Do

SOC 2 has become the most widely adopted security assurance framework for SaaS companies. But rapid growth in demand has created a quality gap โ€” reports vary dramatically in rigor, and the ecosystem lacks standardized ways to tell the difference.

The SOC 2 Quality Guild provides:


The Problem

TPRM teams make critical vendor trust decisions based on SOC 2 reports, but face fundamental challenges:

  • Quality varies widely - from rigorous professional audits to compliance theater
  • No shared evaluation criteria - practitioners rely on vibes, anecdotes, or brand recognition
  • Information asymmetry - hard to distinguish high-quality audits from low-effort check-the-box exercises
  • Inconsistent decisions - different teams assess the same report differently

This creates uncertainty for practitioners, inconsistent feedback for vendors, and an ecosystem that struggles to differentiate quality work.


Our Approach

SOC 2 Reliability Rubric

A practical framework with 11 signals across 3 pillars to evaluate report quality:

๐ŸŸข Structure (3 signals)

Does the report include required components and maintain professional consistency?

  • S1: Required Auditor's Report Section Structure
  • S2: Management's Assertion Completeness
  • S3: Inconsistent Language Across Report Sections

๐Ÿ”ต Substance (4 signals)

Do the controls, testing, and conclusions logically align and support each other?

  • S4: System Description Specificity
  • S5: Control-to-Criteria Mapping Logic
  • S6: Vague or Conflicting Control Descriptions
  • S7: Test Procedure Detail and Specificity

๐ŸŸฃ Source (4 signals)

What credentials, independence factors, and track record may affect report credibility?

  • S8: CPA Firm Registration, Peer Review Enrollment & Results
  • S9: CPA-to-SOC Reports Issued Ratio
  • S10: CPA Firm Leadership & Report Signer Experience
  • S11: Use of a GRC Tool

โ†’ Explore the full rubric


Contributing

We welcome contributions from GRC practitioners, TPRM professionals, auditors, and anyone who cares about improving security assurance quality.

Ways to Contribute

  1. Vote on Community Projects - Visit s2guild.org/#projects and upvote initiatives that matter to you
  2. Propose New Projects - Open an issue with your idea
  3. Share Examples - Contribute real-world examples (anonymized) of quality signals
  4. Improve the Rubric - Suggest refinements to evaluation criteria
  5. Build Tools - Create automation, templates, or integrations

โ†’ View all projects and vote


Rubric Versioning

We maintain official versions in this repository while active collaboration happens in Google Docs.

Versioning Workflow

  1. Active Development - Community discusses in shared Google Doc
  2. Consensus Decision - Working group agrees changes are ready
  3. Version Lock - Export to GitHub as new versioned release
  4. Changelog - Document what changed and why
  5. Announcement - Publish to community via Slack, website
  6. Iterate - Continue refining in Google Doc for next version

This ensures practitioners have stable references to cite while enabling ongoing collaborative improvement.

โ†’ View version history


Principles

Focus on Education, Not Accusations

We evaluate the reliability of reports as evidence โ€” not the trustworthiness of individual vendors or auditors. Our frameworks provide repeatable, verifiable signals that any practitioner can apply.

Practitioner-Driven

The Guild exists to serve practitioners making real vendor trust decisions. Community members set priorities through voting, discussion, and direct contribution.

Market Pressure for Quality

By giving practitioners tools to consistently evaluate report quality, we create incentives that improve outcomes for everyone โ€” vendors, auditors, and the organizations that rely on their work.

Transparent and Open

Our work is open-source (CC BY-SA 4.0), community-governed, and built in public. Anyone can review, adapt, or build upon what we create.


Get Involved

Join the Community


License

This work is licensed under CC BY-SA 4.0.

You are free to:

  • โœ… Share - Copy and redistribute in any medium or format
  • โœ… Adapt - Remix, transform, and build upon the material

Under the following terms:

  • Attribution - Give appropriate credit, provide a link to the license
  • ShareAlike - Distribute adaptations under the same license
  • No additional restrictions - You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits

ยฉ 2026 SOC 2 Quality Guild


Acknowledgments

Built by practitioners, for practitioners. Many thanks to the community members who contribute expertise, examples, mentorshop, and feedback to this growing community.


Contact


Together, we're building a more transparent, consistent, and quality-driven trust ecosystem.