Collecting vendor security reports (SOC 2, SOC 3, ISO, pentest, service agreement)
To clear the vendor tests, collect two documents and upload them inside a review you then complete: the vendor's SOC 2 report (a SOC 3 report counts the same) and your Service Agreement with them. An ISO Report or a penetration test is useful evidence to keep on file, but on its own it satisfies none of the vendor tests. You get these reports from the vendor — their trust center, a signed NDA, or their sales or security contact — not from inside UprootSecurity.
What each report proves
- SOC 2 report — an independent auditor's examination of the vendor's security controls, with detailed testing of how each control actually operated. This is the strongest routine assurance most vendors can give you.
- SOC 3 report — a public summary of that same SOC 2 assurance, without the detailed control testing. Vendors hand it out freely because it carries no confidential detail. For the platform's purposes it counts the same as a SOC 2 report.
- Service Agreement — the contract that governs your connection to the vendor: the master service agreement (MSA), the data processing agreement (DPA), or the subscription terms. It proves the third-party relationship is on paper, with security and confidentiality terms in it.
- ISO Report — an ISO 27001 or ISO 27701 certification, showing the vendor runs a certified security or privacy management system.
- Pentest / VAPT Report — a penetration test or vulnerability assessment, showing someone actively tried to break the vendor's systems and what they found.
Which report satisfies which test
- The Vendor SOC 2 reports test passes for a vendor once a completed review contains a SOC 2 report or a SOC 3 report. Either one does it.
- The Third-party system connections test passes for a vendor once a completed review contains a Service Agreement.
- An ISO Report and a Pentest / VAPT Report satisfy neither test. Upload them anyway — they're real assurance, they stay on your record, and they feed the findings the platform generates for the vendor. They just don't turn a test green on their own.
So the two documents that carry your compliance are the SOC 2 (or SOC 3) report and the Service Agreement. The ISO cert and the pentest are supporting evidence, not test-passers. The other two vendor tests — Vendor security reviews and Vendor risk level assessments — don't depend on any report at all; you cover those by completing the review on time and setting the vendor's risk level.
How to get a report from a vendor
You collect these outside UprootSecurity, then upload them. Three reliable ways, roughly easiest first:
- Their trust center. Many vendors publish a security or trust page where the SOC 3, the ISO certificate, and sometimes a gated SOC 2 live. Start here — it's the fastest.
- A signed NDA. Bigger vendors gate the full SOC 2 report behind a non-disclosure agreement, often through a "request access" step on the trust center. Sign it and you'll get the report. This is normal — a SOC 2 contains detail they can't publish openly.
- Their sales or security contact. If there's no trust center, email your account rep or their security team and ask for the latest SOC 2 (or SOC 3), ISO certificate, and pentest summary. The Service Agreement you already have — it's your signed contract, MSA, or DPA with them.
When a vendor won't share a report
Some vendors — often the largest — won't release a SOC 2 even under NDA, or they route you through a portal that stalls. Don't let that block the review. Fall back to answering the security questionnaire yourself, from what you already know and whatever public assurance they do publish (a SOC 3, a trust-center summary, their public security page)

A completed review needs either an upload or a completed questionnaire, so answering the questionnaire yourself keeps the review moving even with no reports in hand. Be clear on what that buys you, though: completing the questionnaire lets you finish the review, but the Vendor SOC 2 reports test still needs an actual SOC 2 or SOC 3 report, and the Third-party system connections test still needs a Service Agreement. The questionnaire keeps the review current; it doesn't turn those two tests green. See Answer the questionnaire yourself, or send it to the vendor.
Uploading — you don't tag the reports
- You don't choose the report type. Upload the file and the platform reads it and classifies it as a SOC 2 report, SOC 3 report, Service Agreement, ISO Report, or Pentest / VAPT Report. You never tag it yourself.
- Upload a fresh report for each review. Each review expects its own current documents; a report from two cycles ago doesn't carry forward. Re-pull the vendor's latest and upload it each time.
- Uploads live inside a review, and the review has to be completed. An uploaded report only counts once its review is marked Completed with Complete review. A report sitting in a review you never finish satisfies nothing. The vendor's assigned owner is who uploads and completes the review.
Why it matters / what your auditor expects
An auditor wants to see that you collect and review each key vendor's security assurance — and that you keep the documents on file. A SOC 2 report is the gold standard because it's an independent audit with real control testing; a SOC 3 is the shareable version of the same thing. The Service Agreement proves the relationship is governed by a contract with security terms, not a handshake. ISO certificates and pentests round out the picture for higher-risk vendors. Collecting these each year, inside a completed review, is exactly the evidence the vendor controls behind SOC 2 and ISO 27001 expect you to retain.
Common mistakes
- Uploading an ISO cert or a pentest and expecting the SOC 2 test to pass. It won't. Only a SOC 2 report or a SOC 3 report satisfies the Vendor SOC 2 reports test. Keep the ISO cert and pentest — they're good evidence — but chase the SOC 2 or SOC 3 too.
- Forgetting the Service Agreement. The Third-party system connections test needs it, and it's the one document you already have — your own contract with the vendor.
- Uploading to a review you never complete. A report only counts once the review is Completed. Finish the review.
- Reusing last cycle's report. Each review expects a fresh, current upload. Re-pull the latest every time.
- Letting a hard-to-reach vendor stall the whole review. If they won't share, answer the questionnaire yourself and complete the review — then keep chasing the documents the two report tests still need.
