By HarmanJyot Kaur · August 20, 2026 · 7 min read
TL;DR
- SOC 2 doesn’t really have a pass/fail outcome — the auditor issues an opinion (unqualified, qualified, adverse, or disclaimer), and most “failed audit” situations are actually a qualified opinion with specific noted exceptions.
- A qualified report with a small number of well-explained exceptions is often still usable with prospects — what matters more is whether you’re proactively explaining it, not hiding it.
- If the audit was paused before a report was finalized, that’s usually recoverable: a focused gap assessment tells you exactly what’s a documentation fix (days) versus a real technical gap (weeks) versus something that needs a full re-observation period (months).
- A bridge letter can buy time with a prospect while remediation is underway — it’s not a replacement for the report, but it keeps a stalled deal from dying entirely.
First, figure out what actually happened
“The audit failed” gets used for at least three genuinely different situations, and the right next step is different for each one.
You received a qualified opinion. The auditor finished the engagement and issued a report — it’s just not the clean, no-exceptions report you were hoping for. The report lists specific exceptions: a control that didn’t operate consistently across the whole observation period, evidence that was incomplete for part of the window, something like that. This is the most common outcome people call a “failure,” and it’s usually the most recoverable one, because you have a real report in hand with a specific, bounded list of problems.
The audit was paused or withdrawn before completion. Somewhere during fieldwork, it became clear the report was going to be bad enough that finishing it wasn’t worth it, and you (or the auditor) stopped. This is more serious in the short term — you don’t have a report to show anyone — but it also means you get to fix things before anything is written down permanently.
You received an adverse opinion or a disclaimer. Rarer, and more serious: the auditor concluded your controls genuinely did not operate effectively, or couldn’t reach a conclusion at all because of missing evidence or scope problems. This needs the most work to recover from, but it’s not a life sentence — it’s a data point about how far off the control environment actually was.
Whichever one you’re in, the first move is the same: get the specific list of findings from your auditor in writing, if you don’t already have it. “The audit failed” as a feeling is much scarier than the actual bounded list of exceptions usually is.
If it’s a qualified opinion: assess what’s actually in it
Not all exceptions are equal, and this is where a lot of unnecessary panic happens. Ask three questions about each exception:
- How many controls does it touch? One exception on one control is a very different conversation than exceptions across a third of your control set.
- Is it a documentation gap or a real operational gap? “We do this but didn’t write it down consistently” is a fast fix. “We don’t actually do this” is a real fix.
- Is it in a Trust Services Criteria area your prospect actually cares about? An exception in Availability controls matters less to a prospect who only asked about Security and Confidentiality.
Once you know what you’re actually dealing with, you have a real choice: send the qualified report with your own explanation and remediation timeline attached, or hold it and fix the exceptions first, then re-engage the auditor for a corrected report or a bridge letter covering the gap.
If the audit was paused: this is a gap assessment, not a crisis
A paused audit means you found out the hard way what a gap assessment would have told you cheaper and earlier. The move now is the same one a pre-audit gap assessment does — triage every open finding into three buckets:
- Documentation gaps — the control genuinely operates, it just isn’t written down or evidenced consistently. Usually closeable in days.
- Procedural gaps — access reviews that happen inconsistently, an incident runbook that’s never been tested, onboarding/offboarding that isn’t tied to HR events. Usually closeable in one to two weeks with the right templates.
- Real technical gaps — MFA not enforced everywhere, no centralized logging, no tested backup restore process. These take real engineering time, typically weeks, sometimes longer depending on what’s missing.
Most paused audits turn out to be mostly the first two buckets and a smaller number of genuine technical gaps than it felt like in the moment. Triage first, panic never — the size of the fix is almost always smaller than the size of the fear.
Talk to the prospect before they ask
The instinct when an audit doesn’t go well is to go quiet until it’s fixed. That’s usually the wrong move if there’s a live deal waiting on the report. Security teams evaluating vendors have seen qualified opinions and remediation plans before — what damages trust is silence, not an honest “here’s what happened and here’s our timeline,” delivered before they have to chase you for it.
A short, factual update — what the exception was, what’s being done about it, and a realistic date — usually keeps a deal alive. Disappearing until everything is perfect usually doesn’t.
Trade-offs and what we’d avoid
- Don’t hide a qualified report and hope nobody asks for detail. Security reviewers read the actual exceptions, not just the opinion type on the cover. Get ahead of it with your own explanation.
- Don’t treat every exception as equally urgent. A handful of low-severity, well-documented exceptions is a very different remediation project than a systemic gap across multiple controls — prioritize accordingly.
- Don’t skip the root-cause fix and just re-book the audit. An auditor re-testing the same unfixed gap produces the same result. Fix first, then re-engage.
- Don’t assume a paused or qualified audit means starting over from zero. Most of the work that got you this far — scoping, technical controls, existing documentation — still holds. You’re closing a specific, bounded list, not restarting the whole program.
What to do next
What to do next
Get the specific findings in writing from your auditor if you don’t already have them, and triage each one: documentation gap, procedural gap, or real technical gap. The bounded list is almost always less scary than the general feeling of “we failed.”
See Compliance Audit for how we run this exact triage and remediation process — prioritized by what’s actually blocking your report, not a generic checklist.
Talk to whoever’s waiting on the report before they ask. If there’s a deal on the line, book a 30-minute call — we’ll help you figure out what’s realistic to tell them and by when.
Related reading: SOC 2 readiness for cloud-native startups — the engineering checklist that prevents most of this in the first place, and How much does SOC 2 compliance actually cost? if remediation work has you re-budgeting.
Tags