How to Read a Custodian's SOC 2 Type II Report

Reading a custodian's SOC 2 Type II report means looking past the cover page to four things: what the report covers (scope), whether the auditor found the controls effective (the opinion), where controls failed during the period (exceptions), and what the report assumes you will do (complementary user-entity controls). A clean opinion on a narrow scope can still leave the risks you care about untested.

What a SOC 2 Type II Report Is

A SOC 2 report is an independent CPA firm's examination of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy, the AICPA's Trust Services Criteria. A Type II report tests whether those controls operated effectively over a period (often 6 or 12 months), not just whether they were designed at a point in time (which is Type I).

For the difference between report types and where SOC reports fit in custody diligence generally, see the companion explainer on crypto custody SOC 1 and SOC 2 reports. This page is the next step: how to actually read the document once you have it. For where audit reports sit in the overall safekeeping picture, see the crypto custody hub.

How to Read the Report, Section by Section

Work through the report in this order:

  1. Section 1. Auditor's opinion. Read this first. Look for whether the opinion is unqualified (controls were effective), qualified (effective except for specific issues), adverse, or a disclaimer. A qualified or adverse opinion is a flag that needs explanation. Note the auditor's name and whether they are an independent CPA firm.
  2. Section 2. Management's assertion. The custodian's own statement about its system and controls. Compare it later against what the testing actually showed.
  3. Section 3. System description and scope. This is where most diligence is won or lost. Identify exactly which systems, services, and locations are covered, and which are excluded. A report that covers the custodian's web app but excludes the key-management system, or covers one subsidiary but not the entity you contract with, may not cover your actual risk.
  4. Section 4. Trust services criteria, controls, tests, and results. The detailed table of each control, how the auditor tested it, and the result. This is where exceptions appear.
  5. Other information (if present). Management responses to exceptions and any unaudited material. Treat unaudited claims as marketing, not assurance.

Which Findings Actually Matter

Not every line item carries equal weight. Focus your attention on:

  • The reporting period and its recency. A report covering a window that ended many months ago, or a short stub period, tells you less about current controls. Confirm the period and ask for the most recent report.
  • Scope exclusions. What was carved out? For a custodian, the key-generation and key-management environment, cold-storage procedures, and transfer-authorization controls are usually the controls that matter most. If those are out of scope, the report is weaker evidence than it looks.
  • Exceptions (deviations). These are instances where a control did not operate as intended during the period. Read the description, the number of instances, and management's response. One isolated, remediated exception is different from a recurring failure in a control central to safeguarding assets.
  • The trust services categories covered. Security is the baseline; availability, confidentiality, and processing integrity are additional. Know which ones the custodian included.
  • Subservice organizations. If the custodian relies on a third party (e.g., a data center or a sub-custodian), check whether that party is included (inclusive method) or carved out (carve-out method), and whether you need that party's own SOC report.

Complementary User-Entity Controls (CUECs)

Most SOC reports list complementary user-entity controls, things the report assumes you (the customer) will do for the overall control environment to work, such as managing your own user access, safeguarding credentials, and reviewing transfer confirmations. The custodian's clean opinion is conditioned on you performing these. Read the CUEC list and confirm you can and will meet each one; gaps here are your responsibility, not the custodian's.

A Quick Evaluation Checklist

  • Is the opinion unqualified? If not, what is the qualification?
  • What reporting period does it cover, and how recent is it?
  • Are key management, cold storage, and transfer authorization in scope?
  • What exceptions were noted, and were they remediated?
  • Which trust services categories are covered?
  • Are subservice organizations included or carved out?
  • Can you meet every complementary user-entity control?

Fit this into the broader vetting process via the crypto custody due diligence checklist and how to choose a crypto custodian. A SOC 2 report is one input among several; pair it with questions from questions to ask a crypto custodian.

Related Questions

Does a clean SOC 2 report mean my assets are safe?

No. A clean (unqualified) opinion means the auditor found the in-scope controls operated effectively over the period tested. It does not guarantee future performance, cover controls that were excluded from scope, or protect against theft, insolvency, market loss, or risks outside the report's boundaries. Read it as evidence about a defined set of controls during a defined window, not as a safety guarantee.

Is SOC 2 the same as being a qualified custodian?

No. SOC 2 is an attestation about internal controls; qualified-custodian status is a regulatory and legal characterization tied to the entity type and the SEC custody rule. A custodian can have a strong SOC 2 report without being a Cryptocurrency qualified custodians have emerged to serve institutional requirements. Qualified custody may be required for register">qualified custodian, and vice versa. They answer different questions and should both be evaluated. See what is a qualified crypto custodian.

Can I get a custodian's SOC 2 report before signing up?

Often yes, usually under a non-disclosure agreement, because the report can contain sensitive control detail. If a custodian will not share even a summary or the auditor's opinion, treat that as a diligence flag. You should be able to confirm the report type, period, opinion, and scope before placing assets.

Sources

Compliance Note

This page is for educational purposes only and does not constitute legal, accounting, audit, investment, or financial advice. A SOC 2 Type II report provides limited assurance over a defined set of controls and period and is not a guarantee of asset safety, future control performance, or protection against loss. Interpreting an audit report and assessing a custodian should be done with qualified professionals. Advisory services are provided by DAG Wealth, LLC, an SEC-registered investment adviser; DAG Wealth is a brand pending a Form ADV update. Registration does not imply a certain level of skill or training.

Disclosures

DAG Holdings Co is a holding company that does not provide investment advisory, brokerage, administrative, or insurance services to clients. DAG is not a law firm, does not provide legal or tax advice, and does not provide tax preparation services. Tax matters are handled through referrals to qualified independent tax professionals.

DAG Private Client services involve estate matters that require qualified independent counsel in the applicable jurisdiction. LLC formation, trust drafting, and estate planning services are provided in coordination with or by qualified independent legal counsel licensed in the applicable jurisdiction.

Asset protection structures, including Wyoming LLCs and trusts, do not guarantee protection against all claims, creditors, or losses. Outcomes depend on specific facts, jurisdiction, and applicable law.

Insurance products and services are offered through Xure Insurance or its affiliates.

Investment advisory services are offered exclusively through DAG Wealth, an SEC-Registered Investment Adviser (CRD No. 328627). Registration with the SEC does not imply a particular level of skill or training. Form ADV and Form CRS are available upon request or at www.adviserinfo.sec.gov.

Custody arrangements with third-party independent qualified custodians reduce certain risks but do not eliminate them.

Investing in digital assets involves risk, including the possible loss of principal. Digital assets are highly volatile and may not be suitable for all investors. Past performance is not indicative of future results.

Specific fee schedules, scope of engagement, conflicts of interest, and material business practices are disclosed in writing before engagement and in Form ADV Part 2A for the investment-advisory portion.

The information on this site is for general educational purposes and is not legal or tax advice.