Scattered test failures don’t qualify an opinion; materiality does. When deviations pile up on a control until an entire criterion goes unmet — quarterly access reviews that simply stopped, change management with no approvals for months — or when the system description misdescribes reality, the auditor carves the failure out of the clean language: “except for the matter described below…”. Everything else in the report may be spotless; that paragraph still defines it. The difference from routine audit exceptions is the difference between a scratch and a failed inspection.
A qualified report is a yellow flag with a dossier attached, not an automatic disqualification. Experienced reviewers do three things: locate exactly which criterion failed, map it against what they actually buy from you — a Processing Integrity failure matters less to a customer using you for storage — and demand a dated remediation plan plus a clean follow-up report. Expect the deal to slow, procurement to escalate, and some security teams to ask for compensating assurances in the contract. That playbook, from both sides of the table, is laid out in SOC 2 in due diligence.
Move before the questions arrive: fix the failed control, restart clean operation, and consider a shorter follow-up period so the next unqualified opinion lands sooner. Sending the report with a candid cover note beats letting a reviewer discover the qualification on their own.