State of M&A Data Rooms — Q2 2026 Read the report →

How to Share Your SOC 2 Report and ISO 27001 Certificate with Customers (2026)

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

How to Share Your SOC 2 Report and ISO 27001 Certificate with Customers (2026)

I'm Deqian Jia, co-founder of Peony, a data room company, and this post is about the unglamorous job that lands on the security or compliance owner at a B2B vendor: your customers and prospects keep asking for your SOC 2 report and your ISO 27001 certificate, and you have to get the right document to the right person without leaking control detail, sending a stale version, or losing track of who has what.

The friction is real. A buyer's security team, per Vanta's State of Trust Report 2025, spends "9 working weeks per year on vendor security reviews and risk assessments" — so every hoop you make them jump through to get your evidence is time taken directly out of your own sales cycle. The fix is not another PDF attachment. It is a standing, permissioned trust pack that stays current on its own.

Quick answer. Your ISO 27001 certificate is typically shareable openly (it is proof, not blueprint); your SOC 2 Type II report goes out under NDA because it contains control detail and the auditor's exceptions. The manual status quo — an "available on request" page plus account managers emailing PDFs — has no version control, no revocation when a report is superseded, and no record of who holds what. The fix is a standing trust pack in a data room: an open layer, an NDA-gated layer, and a deep-dive layer, behind one link on your security page. When a report renews, you replace the file once and every viewer sees the current version. Peony runs this from free ($0), with the Simple NDA on the Business plan ($30/admin/month) and the Advanced NDA — signed PDF plus audit trail — on the Data Room plan ($52/admin/month). Viewers are always free.

Where this post sits. This is the seller-side how-to for distributing your own audit evidence. It is not the buyer-side guide to evaluating someone else's certs (that is the data room security questionnaire and SOC 2 and ISO 27001 compliant data rooms), not the full portal architecture (customer document portal), and not the trust-center category comparison (trust center vs data room). It is the narrow, high-frequency question: how do I share these specific documents, and keep them current?

Which security documents can you share openly, and which need an NDA?

The short version: the certificate is open, the audit report is gated, and everything in between is a case-by-case call you should make deliberately rather than by default. The instinct to lock everything down is as wrong as the instinct to post everything — the first adds friction that slows deals, the second leaks operational detail.

Here is how the common security package typically splits. Treat these as prevailing industry practice, not legal rules, and confirm each against your own counsel and the specific document's contents before you rely on it.

DocumentTypical treatmentWhy
ISO 27001 certificateOpenly shareableIt names the accredited body, scope, and expiry — it is proof of certification, not a control blueprint
SOC 2 Type II reportUnder NDAContains the system description, control tests, and the exceptions section — restricted-use by design
SOC 3 reportOpenly shareableThe general-use version of a SOC 2 examination, stripped of control listings and test results — built to post publicly
Security whitepaperOpenly shareableA curated summary you wrote for exactly this purpose
Completed questionnaires (CAIQ, SIG, VSA)Case-by-caseA blank CAIQ is public; your completed answers reveal your control posture, so many teams gate them
ISO 27001 Statement of Applicability (SoA)Case-by-case / under NDALists every Annex A control and how you scoped it — closer to a blueprint than a certificate
DPA and sub-processor listOpenly shareableUsually published for transparency; buyers expect to see them before they ask
Detailed penetration-test findingsTightly gatedThe full report contains exploitable detail; share a short attestation letter openly instead

The two anchors to remember: the ISO 27001 certificate is the shareable artifact, the SOC 2 Type II report is the gated one. A useful tell for anything else — does the document prove a state (share it) or describe how it is built (gate it)? The certificate proves; the report and the SoA describe.

One naming precision, because customers will use the words loosely: SOC 2 is an AICPA attestation, so strictly a vendor "has a SOC 2 report" rather than being "SOC 2 certified," whereas ISO 27001 genuinely produces a certificate from an accredited body. It rarely matters in a sales email, but it matters in how you describe your own posture on a public page.

Why does emailing PDFs on request break down?

Because an email attachment is frozen the instant you hit send, and the compliance evidence it carries is not. Three specific failures follow, and every security owner who has run the "available on request" model has hit all three.

Renewal turns into a redistribution project. Your SOC 2 report covers a look-back window and gets reissued annually; your ISO 27001 certificate renews on its three-year cycle with surveillance audits in between. The day the new report lands, every copy you emailed over the past year is stale — and there is no reaching into a customer's inbox to swap it. So either your customers are qualifying you on a superseded report, or you spend a day re-emailing the new one to everyone who ever asked, then repeat that at the next renewal.

Superseded reports live forever. A prospect who evaluated you eighteen months ago still has that old PDF. If they forward it internally, or an auditor pulls it during their review, the document circulating is one you can no longer correct or withdraw. An emailed file has no expiry and no off switch.

You have zero access record. You cannot prove a customer received the current report, you do not know who is still opening the old one, and when your own team asks "which prospects have our SOC 2?" the honest answer is a search through the account managers' sent folders. That matters both ways: it is a gap in your delivery evidence, and it is a governance blind spot.

And remember what this friction costs the other side. With the buyer's team already spending nine working weeks a year on vendor reviews, a slow "email us and we'll dig out the PDF" loop is a direct tax on the deal — which is why fixing distribution is one of the few security investments that speeds revenue up rather than just reducing risk.

How do you set up a standing trust pack in a data room?

You build three access layers behind one link, gate the middle layer with an NDA, and put that link on your website's security page so it is always reachable. This is the core move, and it takes an afternoon, not a project.

Think of the pack in three folders, each with a different door:

  • Open layer — no gate. Your ISO 27001 certificate, SOC 3 report, security whitepaper, DPA, sub-processor list, and pen-test attestation letter. Anyone with the link opens these immediately — the "prove it fast" tier that unblocks most early-stage questions without a human in the loop.
  • NDA layer — gated. Your SOC 2 Type II report, and completed questionnaires if you gate them. The viewer signs before the file unlocks. For the strong version, use the Advanced NDA on the Data Room plan ($52/admin/month): it produces a signed PDF from both parties and records the acceptance in the audit trail, so you hold a countersigned artifact for every recipient. For lighter gating, the Simple NDA (acknowledge-only) on the Business plan ($30/admin/month) does the job.
  • Deep-dive layer — tightly permissioned. Detailed pentest findings, architecture documents, anything you release only to a serious prospect late in the cycle. Here you use granular per-file permissions — view-only, no download, per named viewer — so this material never sits in the same bucket as the certificate.

Two controls make the pack safe to leave standing on a public page. Email authentication ties each visit to a verified address, so "download the report" is never anonymous, and allow and block by domain restricts the gated layer to real corporate addresses. Both are on the Business plan and up.

Then the standing link. Put one link to the pack on your /security or /trust page — a "Request our security documentation" or "Trust pack" button. That single URL becomes the front door your sales team forwards and your renewal updates flow through. You have built the control layer of a trust center without running a trust-center project — and unlike a one-way trust center, the same room can also collect documents back (a signed order form, a customer's own DPA) when you need it to. For the full multi-audience version — prospects, customers, and third parties from one place — the customer document portal guide walks the architecture end to end.

How do you handle report renewals and superseded versions?

You upload the new report once, and everyone sees the current version — that is the entire payoff of a link over an attachment. The renewal stops being a mailing campaign and becomes a single file swap.

Concretely, when your auditor issues the new SOC 2 report or your certification body reissues the ISO 27001 certificate:

  1. Replace the file behind the link. Using update-links, you swap the PDF in place. The URL does not change, so every customer, prospect, and partner holding that link now opens the current report on their next visit. No redistribution round, no "please discard the previous version" email.
  2. Expire the stragglers. For any one-off shares of the old report, link expiration — available on every plan, including Free — time-boxes them so they stop resolving after a set date. The superseded report cannot circulate indefinitely.
  3. Revoke on demand. If a specific relationship ends or a report must come down immediately, remote access revocation (Business plan and up) pulls that viewer's access the moment you click, even after they have opened it.
  4. See who is behind. The audit trail (Data Room plan) shows exactly who is still opening the previous version, so if a prospect is mid-review on last year's report, you nudge that one account rather than blasting everyone.

This is the same "always-current pack" discipline a GDP-licensed pharma wholesaler uses to keep its licence and inspection certificate live for every trading partner — the GDP compliance pack is the pharma-wholesale version of the same idea, applied under a hard regulatory retention duty. Yours is the horizontal version: any vendor, any framework, one link that is current by default rather than by chasing.

How do you answer security questionnaires from the same pack?

The corpus you assembled for distribution doubles as your questionnaire evidence base. Every completed CAIQ, every SIG Lite response, your whitepaper, and your policies live in one place, so when a customer sends a questionnaire you answer from a maintained library rather than reconstructing answers from memory or old email threads. Keeping the completed questionnaires beside the reports also means the next reviewer who asks a near-identical question gets a consistent answer.

There is an honest limit here, and it is worth stating plainly. A data room stores and serves that evidence and logs who pulled it, but it does not auto-answer an inbound questionnaire for you. Dedicated trust-center platforms add AI questionnaire automation on top of the hosted corpus — they draft answers to an incoming SIG or CAIQ from your existing documents — which is a genuine capability a data room does not have. If your inbound volume is high enough that questionnaire drafting is the bottleneck, that automation earns its keep; the trust center vs data room comparison lays out exactly where that line sits and what the trust-center platforms cost.

What does it cost to run this, and does anyone else need to pay?

Peony is free to start at $0, the Business plan is $30 per admin per month, and the Data Room plan — the one most trust packs settle on — is $52 per admin per month on annual billing. The detail that changes the math for a vendor with a growing customer base: viewers are always unlimited and free. You pay for your internal admin seats, and every customer security team, every prospect's reviewer, and every auditor who pulls your report reads it without a seat, an account charge, or a per-download fee.

That pricing model is the reason a standing trust pack is cheap to leave open even when thousands of customers reference it. The tiers map cleanly to how much gating you need:

  • Free ($0) — the open layer (certificate, whitepaper, SOC 3), with page-level analytics and link expiry, to test the workflow before you gate anything.
  • Business ($30/admin/month) — email authentication, allow and block by domain, remote access revocation, and the Simple NDA acknowledge-only gate: enough for lighter gating of the SOC 2 report.
  • Data Room ($52/admin/month) — the Advanced NDA (signed PDF plus audit trail and countersigning), dynamic watermarking so each copy of the report carries the viewer's identity, granular per-file permissions for the deep-dive layer, and the full audit trail. This is the tier a serious trust pack wants, because a leaked report should trace back to whoever pulled it.

For context on the alternative: among dedicated trust-center platforms, Conveyor is the notable exception that publishes a floor price (from $9,600/year), while SafeBase, Drata, and Vanta trust centers are quote-only. Those platforms buy you questionnaire automation and GRC sync on top; if you just need compliant distribution of your report under NDA with a real access record, a data room does that from free — one reason 6,800+ customers run controlled sharing on Peony rather than standing up a separate platform for it.

A word on our own posture, since it is fair to ask. Peony is SOC 2 Type II-ready — controls aligned to SOC 2, with the Type II audit underway — and I would rather say that plainly than call us "certified," because we are not yet. We do not hold ISO 27001 today either. Available for reviews right now: our security whitepaper, our completed questionnaires, and our standard DPA with SCCs. Our standard plans process in the United States (AWS) under Standard Contractual Clauses, with EU-region data residency available on the Enterprise plan — I will not imply EU hosting is the default, because it is not. That is exactly the honest, boundary-included answer this post argues you should give your own customers.

Frequently asked questions

Can you share a SOC 2 Type II report publicly, or does it need an NDA?

A SOC 2 Type II report is a restricted-use document: it contains the auditor's detailed system description, the control tests, and the exceptions section, which is exactly the operational detail you do not want indexed on the open web. So the near-universal industry practice is to share the full Type II report under an NDA, not to post it publicly. If you want a public trust signal, the SOC 3 report is built for that purpose because it is stripped of the control listings and test results, so you can post it openly and keep the Type II report behind the NDA gate. The practical setup is a two-layer trust pack: an open layer that anyone can pull, and an NDA-gated layer that unlocks the Type II report after the viewer signs.

Should you share your ISO 27001 certificate openly or gate it?

The ISO 27001 certificate itself is typically shared openly. It is a short document naming the accredited certification body, the certificate number, the scope statement, and the expiry date, and it is designed to be shown as proof, which is why many vendors link it straight from a public security page. The document you gate is the audit report behind it and the Statement of Applicability (SoA), because the SoA lists every Annex A control and how you scoped it, and that is closer to a control blueprint than a proof of certification. So the typical split is certificate open, SoA and any detailed audit output case-by-case or under NDA. Treat this as common practice rather than a legal rule, and confirm nothing in your certificate scope statement is itself sensitive before you post it.

How do you stop a superseded SOC 2 report from living in customer inboxes forever?

You stop emailing the file and start sharing a link to it instead. When your auditor issues the new report, you replace the file behind the standing link once, and every customer who holds that link opens the current report the next time they visit, with no redistribution round. For the copies already circulating, link expiration lets you time-box the old share so it stops resolving, and remote access revocation lets you pull a specific viewer's access immediately, with expiry available on every Peony plan including Free, and revocation from the Business plan. Page analytics then show who is still opening the superseded version so you can nudge exactly those accounts. An emailed PDF gives you none of this: once it is sent, it is frozen and unrecallable.

What does it cost to share a SOC 2 report with customers, and do they need a paid seat?

Peony starts free at $0, the Business plan is $30 per admin per month, and the Data Room plan is $52 per admin per month on annual billing, and viewers are always unlimited and free, so every customer security team reads your report without ever needing a paid seat. You pay for your internal admin seats and nothing per recipient, which is what makes a standing trust pack cheap to run even when thousands of customers pull it. For gating, the Business plan carries email authentication, allow and block lists, remote revocation, and the Simple NDA acknowledge-only gate; the Data Room plan adds the Advanced NDA that produces a signed PDF from both parties plus a full audit trail and dynamic watermarking. That is why 6,800+ customers run controlled document sharing on Peony without the bill scaling with the audience.

Do you need a trust-center platform to share your SOC 2 report, or is a data room enough?

For the core job of distributing your report under NDA and keeping it current, a data room is enough, and it is usually the cheaper and faster path because you already need one for other confidential sharing. A data room gives you the NDA gate, per-viewer watermarks, expiry, revocation, and the access log, which is the whole distribution mechanic. Where dedicated trust-center platforms genuinely add value is at high inbound volume: they layer AI questionnaire automation on top of the hosted document corpus and sync with your GRC tool if you already run Vanta or Drata, which a data room does not do. So the honest split is that a data room handles distribution and evidence of distribution, while a trust center adds questionnaire automation and GRC sync for teams drowning in inbound reviews.