How do I review and edit my Section III (System Description) for my SOC 2 report?

Last updated: June 23, 2026

Context

Section III is the System Description — the customer-facing part of your SOC 2 report. It provides a descriptive overview of your company and security program to anyone reading the report (such as auditors, enterprise clients, or prospects).

Oneleet can generate a draft of Section III , based on information already provided in your Oneleet platform. Because it is generated, it is important that you review it carefully for accuracy before it is submitted to the auditor. Your vCISO reviews it prior to sharing, but you should also review this document. You know your system best!

Answer

Follow these steps to review and finalize your Section III:

  1. Access the draft. Once your Oneleet team has generated the Section III draft, you will receive a link to the Oneleet platform to review the document.

  2. Review for AI hallucinations and inaccuracies. The AI generates content based on your platform data and publicly available information, but it can make mistakes. Pay close attention to:

    • Headcount / staff size — This is a common area where the AI may generate an incorrect number. Make sure the employee and contractor count reflects your current team size. If your headcount is about to change (e.g., new hires joining soon), you can use the number that will be accurate at the time of writing.

    • Technologies and vendors — Confirm that the listed infrastructure, tools, and vendors accurately reflect what your company uses. Remove anything you no longer use and add anything that is missing.

    • Organizational structure and descriptions — Verify that role descriptions, team structure, and company background are accurate and reflect how you would describe your organization.

    • Cloud infrastructure scope — If you use cloud providers such as AWS, make sure they are correctly represented. Omitting or incorrectly excluding a core infrastructure provider can raise concerns with auditors.

  3. Make edits directly in the document. You can edit the draft directly. Feel free to rewrite any section to better reflect your organization's language and structure.

  4. Section III is a system description, not a controls document. It is meant to be a general overview of your company and security program, not a detailed, control-by-control breakdown. Specific details about vulnerability scans, penetration tests, access reviews, etc., are covered in other sections of the SOC 2 report. The system description does not need to include that level of specificity.

  5. Notify your Oneleet team when your review is complete. Once you are satisfied with the content, let your Oneleet team know. They will forward the finalized Section III to the auditor. Do not delay this step, as it may hold up the progression of your audit.

Tip: Your section III will be a component of your final report. Make sure it's perfect, so you don't have to make changes after the report is issued.