skip to main content

SOC Reporting Services

SOC Reporting Services

Verification and Assurance for Your Security and Controls

Does your organization process payments, host data or conduct other outsourced services for clients? Have you received questions about your security and controls? Do you need to provide verification to government regulators? A System and Organization Controls (SOC) report provides third-party peace of mind, universally satisfies compliance requirements and serves as a gold standard affirmation.

SOC reports are complex and cover a wide range of objectives and controls, so it is important to work with an assurance team well-versed in quality standards and reliable output. RKL’s assurance professionals combined have three decades of experience conducting SOC reports, and they can help you determine which type of SOC report works best for your requirements and goals.

SOC Reporting Services

SOC Report: Which Type Does Your Organization Need?

SOC 1

What is it? An assurance tool for controls related to financial reporting designed by the American Institute of Certified Public Accountants (AICPA).

Who needs one? Any organization that provides services that could have an impact on financial operations at another company.

What does it cover? At least six months of information that is material and impactful to the financial statement.

SOC 2

What is it? Also designed by AICPA, SOC 2 tests controls related to five principles of the Trust Services Criteria (security, availability, confidentiality, privacy, processing integrity).

Who needs one? Any organization that provides services to other companies that include the holding or processing of data or information on others’ behalf.

What does it cover? At least two months of technical controls for data storage and processing (not financial information).

 

 

SOC Reporting ServicesSOC Reporting Services

SOC for Cybersecurity

What is it? Using the same Trust Services Criteria as the SOC 2, a framework designed to demonstrate the detailed design and controls for their cybersecurity management program.

Who needs one? Any organization that seeks or is required to demonstrate the effectiveness of their cybersecurity risk management program.

What does it cover? At least two months of technical controls for data storage and/or processing (not financial information).

SOC for Supply Chain

What is it? A reporting framework created to convey supply chain risk management efforts to stakeholders

Who needs one? Manufacturing and distribution organizations with complex supply chains, those handling sensitive customer data, or any that wish to demonstrate to clients, suppliers, and stakeholders that they have effective controls to manage and mitigate supply chain risks.

What does it cover? At least two months of technical controls for data storage and/processing (not financial information).

SOC Reporting ServicesSOC Reporting Services

Why RKL for SOC Reporting?

Tax Services Icon

Transparency

Each engagement starts with a review of existing reports to identify any gaps in prior SOC reports and align with management around objectives and controls that need to be tested. Without a previous report, we look at other process narratives, documents and established procedures to leverage existing efforts.

Timeliness

Whether you need a report related to financial statement preparation and review with a hard deadline or have your own internal timeline that needs to be met, our team will meet it without cutting corners to produce a thorough and reliable assurance opinion.

Quality

The AICPA sets high standards for SOC Reports and RKL uses those as the floor, not the ceiling. We are committed to delivering a comprehensive report that assuages security and safety concerns and drives ongoing value for your organization and your clients.

SOC Reporting Services

Related Articles

SOC FAQs

What is a SOC report?

A SOC (System and Organization Controls) report is an independent CPA attestation that describes a service organization’s system, reports on controls relevant to user entities, and provides assurance to customers and their auditors.

What’s the difference between SOC 1, SOC 2, and SOC 3?

The report type should be picked based on the audience (user financial auditors vs. customers/parties concerned with information security) and distribution needs.

  • SOC 1 focuses on controls relevant to user entities’ financial reporting and is useful to user entity auditors.
  • SOC 2 focuses on Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and is commonly used by tech/cloud providers or by companies maintaining sensitive client information.
  • SOC 3 is a public summary of a SOC 2 with no detailed control testing.

What is Type 1 vs. Type 2?

  • Type 1 reports on the fairness of the system description and the design of controls at a point in time and is often used for an initial attestation.
  • Type 2 reports the same as the Type 1, plus the operating effectiveness of controls over a defined period that can range from 2 to 12 months, depending on whether it is a SOC 1 or SOC 2 report. It also provides stronger ongoing assurance that controls actually operate.

Who should get a SOC report?

Customer base and compliance needs determine which SOC report to pursue.

  • SOC 1 is for service organizations whose services affect their customers’ financial reporting. Common candidates include payroll processors, loan servicing, medical billing, and asset management,
  • SOC 2 is for organizations whose customers require assurance about data access, security, privacy, availability, etc. Common candidates include payroll processors, SaaS/cloud providers, managed service providers, data centers, and companies that are maintaining sensitive customer information.

What are the Trust Services Criteria (TSC)?

The TSC are the standards used in a SOC 2 examination. They include Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the required baseline, while the other criteria apply based on services, contractual commitments, regulatory needs, or customer expectations.

How do you define the scope of a SOC engagement?

The scope is defined by:

  • The relevant services, processes, systems, and locations applicable to the SOC 1 control objectives or SOC 2 criteria
  • The consideration of whether to include or exclude any subservice organizations.

It should be based on customer needs, auditability, and risk. Defining scope early reduces surprises, limits rework, and helps produce a report that meets user needs.

What are complementary user-entity controls (CUECs) and subservice organizations?

CUECs are controls that the service organization expects user entities to perform. They are documented in the SOC report.

Subservice organizations are third parties critical to supporting the in-scope SOC service. They may be addressed using the following methods:

  • Carve-out method: Their controls are excluded from evaluation but described within the report.
  • Include the subservice organization’s controls within the SOC report, in which their controls are included and tested.

Identifying CUEUs and subservice organizations early is important because these decisions affect testing, opinion, and how user entities rely on the report.

How long does a SOC engagement take, and what does it cost?

Timeline depends on readiness and type.

  • Readiness assessment: A few months
  • Type 1 report: A few months
  • SOC report: Depending on the variable of the report range.
    • Type 2 requires an operating period ranging from 2 to 12 months, depending on the SOC report type and testing and reporting time.

Cost varies widely with report type, scope, complexity, number of locations, and remediation needs. A tailored estimate can be provided after scoping.

What happens if exceptions (control failures) are found?

Exceptions are documented in the report. Depending on severity and pervasiveness, the report opinion could be adjusted to reflect heavily impacted areas. Most SOCs, with isolated exceptions, still receive an unmodified opinion with exceptions described.

How should SOC reports be distributed, and how long are they “valid”?

SOC 1 and SOC 2 are restricted-use reports and shared under a non-disclosure agreement with user entities and their auditors. SOC 3 reports, by design, are intended to be shared publicly.

There is no formal expiration. However, a Type 2 report covers only its period, and clients usually obtain annual SOC reports to provide continuous assurance.