What Does Your Assurance Report Actually Prove?
A HITRUST analysis of 103 SOC 2 Type 2 reports shows why TPRM teams must evaluate the evidence behind the label before they rely on it.
-
- 77% of the sampled SOC 2 reports included controls requiring MFA for remote access.
- 30% of the sampled SOC 2 reports included controls requiring MFA for privileged access.
- 7% of the sampled SOC 2 reports included dedicated phishing training or simulations, while 5% included a prescriptive email-filtering control.
- 0% of the sampled SOC 2 reports included an organizational control to maintain offline or immutable backups.
- Organizations rely on assurance artifacts to approve vendors, reduce questionnaire depth, set monitoring frequency, accept residual risk, satisfy contractual obligations, and demonstrate oversight. These findings reflect what the sampled reports specified, not whether organizations implemented controls that the reports omitted. When a report omits a material control, the recipient cannot use that report to confirm it.
- The Assurance Gap gives TPRM teams five questions to determine what an artifact supports, what it leaves open, and what supplemental work they need.
Evaluate the Evidence Before You Rely on It
Learn five questions that help you evaluate scope, threat-landscape coverage, quality, supply chain coverage, and measurable outcomes in:
The Assurance Gap
