What Does Your Assurance Report Actually Prove?

A HITRUST analysis of 103 SOC 2 Type 2 reports shows why TPRM teams must evaluate the evidence behind the label before they rely on it.
    • 77% of the sampled SOC 2 reports included controls requiring MFA for remote access.
    • 30% of the sampled SOC 2 reports included controls requiring MFA for privileged access.
    • 7% of the sampled SOC 2 reports included dedicated phishing training or simulations, while 5% included a prescriptive email-filtering control.
    • 0% of the sampled SOC 2 reports included an organizational control to maintain offline or immutable backups.
  • Organizations rely on assurance artifacts to approve vendors, reduce questionnaire depth, set monitoring frequency, accept residual risk, satisfy contractual obligations, and demonstrate oversight. These findings reflect what the sampled reports specified, not whether organizations implemented controls that the reports omitted. When a report omits a material control, the recipient cannot use that report to confirm it.
  • The Assurance Gap gives TPRM teams five questions to determine what an artifact supports, what it leaves open, and what supplemental work they need.
The Assurance Gap - Cover

Evaluate the Evidence Before You Rely on It

Learn five questions that help you evaluate scope, threat-landscape coverage, quality, supply chain coverage, and measurable outcomes in:

The Assurance Gap

The Only Certification Proven to Work

With a 99.62% breach-free rate among HITRUST-certified environments, HITRUST stands alone in cybersecurity assurance. From third-party risk to internal controls, trust the solution that reduces risk — and proves it.

Engage with HITRUST

Chat Now

This is where you can start a live chat with a member of our team