Vendor security assurance

What is a SOC 2 report and does a dealership software vendor need one?

A SOC 2 is an independent auditor's report on how a service organisation controls security and related criteria. No rule requires a dealership vendor to hold one, but for any vendor touching customer or financial data it is the most common way to evidence controls without running your own audit. A Type II report, which covers a period of operation rather than a point in time, is the one worth asking for.

Direct answerSeptember 1, 2026 reviewedNeutral evaluation
01

Type I and Type II are not interchangeable

Type I says controls were designed appropriately on a date. Type II says they operated effectively across a period, usually six to twelve months. Ask which one you are being shown and what period it covers.

02

Read the exceptions and the scope

The value is in the detail, not the logo. Check which systems are in scope, which trust criteria are included, and what exceptions the auditor recorded. A report scoped to a product you are not buying tells you nothing.

03

Absence is not disqualifying

Smaller and newer providers often have real controls and no report, because an audit is expensive. Where there is no SOC 2, ask for a completed security questionnaire, penetration-test summary, subprocessor list and incident-response commitment, and put the answers in the contract.

04

Re-check it

A report expires. Make annual re-provision a contractual obligation rather than something you have to chase.

Decision checklist

What to verify

Open procurement templates →

Ask whether the report is Type I or Type II and what period it covers

Read the scope and the auditor's exceptions, not the logo

Where there is no report, require a completed security questionnaire

Make annual re-provision a contractual obligation

Related market maps

Continue the research

People also research

Related dealership technology questions