Resources

Articles

Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Filters
Show all
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Apr 29, 2026

SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?

SOC 1, SOC 2, SOC 3 — same family, very different reports. Here's how to know which one your customers are actually asking for.

SOC 1
SOC 2
SOC 3
Reporting

The short version

All three reports are issued under the AICPA's System and Organization Controls framework. Where they differ is what they evaluate and who they're written for.

  • SOC 1 — Controls relevant to your customers' financial reporting. Restricted-use report.
  • SOC 2 — Controls relevant to security, availability, processing integrity, confidentiality, and privacy. Restricted-use report.
  • SOC 3 — A public-facing summary of your SOC 2. General-use report.

If your customers care about how you handle their data, you're looking at SOC 2 (and possibly SOC 3). If they care about how you affect their financial statements, you're looking at SOC 1.

SOC 1: built for financial reporting

A SOC 1 report exists for one reason: to give your customer's auditors the comfort they need when your services impact your customer's financial statements.

Classic examples of who needs SOC 1:

  • Payroll processors
  • Loan servicing platforms
  • Medical claims processing
  • Fund administrators
  • SaaS platforms that handle billing, revenue recognition, or accounting workflows on behalf of customers

The controls in scope are the ones that, if they failed, could cause a misstatement in your customer's books. Think: change management for billing logic, access controls around financial data, completeness and accuracy of transaction processing.

SOC 1 reports come in two flavors:

  • Type 1 — Design of controls at a point in time.
  • Type 2 — Design and operating effectiveness over a period (usually 6–12 months).

SOC 1 is a restricted-use report. It's written for your customers and their auditors — not for marketing.

SOC 2: the one most SaaS companies need

SOC 2 is the report procurement teams ask for when they're evaluating a vendor that touches their data. It evaluates your controls against the AICPA's Trust Services Criteria:

  • Security (required in every SOC 2)
  • Availability (optional)
  • Processing Integrity (optional)
  • Confidentiality (optional)
  • Privacy (optional)

Most SaaS companies start with Security only and add Availability or Confidentiality based on customer pressure or contractual commitments.

Like SOC 1, SOC 2 has a Type 1 and a Type 2 version. Type 1 covers a point in time; Type 2 covers a period — typically a minimum of three months for a first audit, then twelve months going forward. Most enterprise customers will eventually want a Type 2.

SOC 2 is also a restricted-use report. You can share it with prospects under NDA — and you absolutely should — but you can't post it on your website.

Which is exactly the gap SOC 3 fills.

SOC 3: the public version of SOC 2

SOC 3 is essentially a marketing-friendly version of your SOC 2. It uses the same Trust Services Criteria and is based on the same audit work, but it strips out the detailed control descriptions and test results. What's left is a high-level attestation you can publish on your website, hand out at trade shows, or include in sales decks without an NDA.

A few things worth knowing:

  • You can only get a SOC 3 if a SOC 2 Type 2 has been (or is being) performed. SOC 3 isn't a standalone audit — it's a derivative report.
  • SOC 3 is general-use. Anyone can read it.
  • SOC 3 doesn't replace SOC 2. Enterprise procurement teams still want the full SOC 2 Type 2.

Think of SOC 3 as the trust badge on the homepage and SOC 2 as the document you send when a security questionnaire lands in your inbox.

Side-by-side comparison

SOC 1 SOC 2 SOC 3
Focus Internal controls over financial reporting Security, Availability, Processing Integrity, Confidentiality, Privacy Same as SOC 2, summarized
Audience Customer auditors and management Customers and prospects (under NDA) General public
Distribution Restricted Restricted Public
Detail level Full controls and test results Full controls and test results High-level only
Type 1 / Type 2 Both available Both available Type 2 only
Standard SSAE 18 (AT‑C 320) SSAE 18 (AT‑C 105 & 205) SSAE 18 (AT‑C 105 & 205)

How to choose

The decision usually comes down to three questions:

1. What do your customers' contracts and security questionnaires actually ask for?

Ninety percent of the time, this answers it for you. Read the requests instead of guessing.

2. Does your service affect your customers' financial statements?

If yes — payroll, billing, accounting, claims, fund services — you likely need SOC 1. If your customers' auditors are calling you, that's a strong signal.

3. Do your customers care about how you handle their data?

If yes, you need SOC 2. This covers most SaaS, hosting, managed services, and infrastructure providers.

Some companies need both SOC 1 and SOC 2 — for example, a billing SaaS that processes financial transactions and stores sensitive customer data. That's not unusual, just more work.

SOC 3 is rarely a starting point. It's something you add once your SOC 2 Type 2 is in place and marketing wants something they can publish.

What about ISO 27001, HIPAA, or PCI?

These often come up in the same conversation, but they're separate frameworks with their own audits and certifications. SOC reports don't replace them and they don't replace SOC reports. If you're juggling multiple frameworks, a good auditor can help you map overlapping controls so you're not doing the same work three times.

Bottom line

SOC 1 is for financial reporting. SOC 2 is for everything else customers worry about — security, uptime, data handling. SOC 3 is the public-facing version of SOC 2 you can share without an NDA.

The cleanest path for most SaaS companies: start with SOC 2 Type 1 to validate your control design, move into a SOC 2 Type 2 audit period, and add SOC 3 once you want a public-facing trust signal. If you process financial transactions on behalf of customers, layer in SOC 1.

Not sure which path fits your business? That's the kind of conversation a 30-minute call with a specialized auditor can resolve faster than another week of internal debate.

Mar 10, 2026

What is the difference between SOC 2 Type 1 and SOC 2 Type 2

SaaS companies are popular, but not all of them are able to stay compliant. An annual SOC 2 audit is one way to ensure organizational security and compliance.

SOC 2
Compliance

The AICPA defines a SOC 2 Type 1 report as - a report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.

To translate that to layman's terms - Is the company set up for success with its current controls and does the system description accurately reflect the company’s operations?

The AICPA defines a SOC 2 Type 2 report as - a report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.

To translate that to layman's terms - Did the company do what it said it was going to do when it said they were going to do it and does the system description accurately reflect the company’s operations?

SOC 2 Type 1

The SOC 2 Type 1 audit looks at one day (point in time) and gives the opinion that everything is set up correctly. The auditor will look at the system description and the controls to make sure that they match the SOC 2 criteria. The auditor will also look at the evidence to verify that the control is in place.

A SOC 2 Type 1 report will give you the peace of mind that you have designed your controls appropriately to meet defined Trust Services Criteria.

SOC 2 Type 2

All the work that you did for SOC 2 Type 1 applies to Type 2. Now you just need to follow those policies and do what you said you were going to do and collect the evidence to prove it. You have moved from the setup mode to the maintenance mode. A Type 2 report is demonstrating that the controls you designed and implemented in Type 1 are now operating effectively over the period chosen for the Type 2 audit.

Usually, the minimum audit period for a SOC 2 Type 2 is 3 months. You should talk with your customers to see if this will meet their needs. You might find one that will only take a minimum of 6 months. If your customers just need a report, then we would suggest going with the shorter period so that you can get out in the marketplace with the report and start winning new customers.

How To Decide What You Need

At the end of the day, your customers are going to want a SOC 2 Type 2 report.

If you need something quick to keep sales conversations going or as an internal milestone then a SOC 2 Type 1 is a great starting point. We would also suggest doing a SOC 2 Type 1 first if you are not using a readiness platform and are trying to do it by yourself. This will make sure that you are set up for a successful SOC 2 Type 2. You would hate to find out after your SOC 2 Type 2 audit period ended that your controls didn’t match the SOC 2 criteria. The SOC 2 Type 1 provides that safety net for you to know you are on the right path.

Deciding to do a SOC 2 Type 1 will not slow you down in obtaining a SOC 2 Type 2. While the audit is being performed on your Type 1 you can start the audit period for Type 2. That way you will already be part way through the audit period by the time you receive the SOC 2 Type 1 report.

The additional cost for a SOC 2 Type 1 report is usually fairly small. Most CPA firms will give you a bundled cost for a Type 1 and a Type 2 that provide the two audits at a significantly lower price.

If none of those cases fit your needs, then we would suggest you go straight for Type 2.

A readiness platform will make sure that all of your controls match the SOC 2 criteria and that you are set up for success.

If your customers will only take a SOC 2 Type 2 and you need something to prove you are taking it seriously and are working on your SOC 2, you can also ask your auditors for an engagement letter to share with your potential customers to show that you are working on your SOC 2 Type 2. That will have enough weight with potential clients to keep sales conversations moving forward.

SOC 2 Compliance Audit Readiness

No matter which path you take, you will end up at the SOC 2 Type 2 report. There isn’t a wrong way to approach it. As you are making your choice, talk to your customers (if you can) and talk to your auditor about what is going on. Your auditor can walk you through both paths and help you make the best decision for your company.

You’re dealing with private data and information, so suffice it to say, yes, a self-audit is a great way to ensure your organization takes its responsibilities for security seriously.

After a SOC 2 compliance self-audit and remediation, your organization is ready for its SOC 2 compliance audit from an experienced and specialized CPA like Johanson Group.

Oct 2, 2023

PCI Compliance Guide

Discover everything you need to know about PCI compliance, including compliance levels, benefits, a PCI 4.0 checklist, and the difference between compliance and certification. Learn why Johanson Group is your trusted partner for PCI compliance solutions.

PCI DSS

PCI Compliance Levels

PCI compliance is categorized into four levels based on the volume of credit card transactions processed annually:

  • Level 1: Over 6 million transactions per year.
  • Level 2: Between 1 million and 6 million transactions per year.
  • Level 3: Between 20,000 and 1 million e-commerce transactions per year.
  • Level 4: Fewer than 20,000 e-commerce transactions or up to 1 million total transactions annually.

Each level has its own specific requirements and validation processes, with Level 1 being the most stringent.

Who Needs PCI Compliance?

Any business that processes, stores, or transmits credit card information must comply with PCI DSS. This includes merchants, financial institutions, payment processors, and service providers. Non-compliance can result in hefty fines, increased transaction fees, and damage to reputation.

What are the Benefits of PCI Compliance?

Achieving PCI compliance offers numerous benefits, including:

  • Enhanced Security: Protects sensitive cardholder data from breaches and fraud.
  • Customer Trust: Builds confidence with customers knowing their information is secure.
  • Avoid Penalties: Prevents costly fines and penalties associated with non-compliance.
  • Operational Efficiency: Encourages the adoption of best security practices, improving overall business processes.

PCI Compliance vs. Certification

While PCI compliance means adhering to the PCI DSS requirements, PCI certification involves a formal assessment by a qualified security assessor (QSA) to validate compliance.

  • PCI Compliance: An ongoing process where businesses ensure they meet the PCI DSS standards. This includes self-assessment questionnaires and regular security checks.
  • PCI Certification: A formal certification process where a QSA conducts a thorough audit and provides a Report on Compliance (ROC) if the business meets all requirements.

Certification can provide additional assurance to stakeholders, but the primary goal is always to maintain compliance to protect cardholder data effectively.

PCI 4.0 Compliance Checklist

Before engaging with a PCI Qualified Security Assessor (QSA), you will want to make sure you have as many items on the following PCI DSS compliance checklist complete as possible. PCI DSS version 4.0 introduces several updates to enhance payment data security.

PCI

Choose Johanson Group for PCI Compliance

When it comes to PCI compliance, the Johanson Group stands out as a trusted partner. With a dedicated team of experts, including our new Director of PCI services, Anthony Fulda, we offer comprehensive compliance solutions tailored to your business needs. Our services include:

  • Detailed risk assessments and gap analyses
  • Implementation of robust security measures
  • Ongoing monitoring and support
  • Assistance with PCI DSS validation and certification

Partnering with Johanson Group ensures that your business meets the highest standards of payment data security, giving you peace of mind and a competitive edge in the market. Contact us today to learn more about our PCI compliance services and how we can help secure your payment processes.

Sep 25, 2023

Determining the Scope Statement

Don't leave information security to chance - determine the ISO 27001 scope statement that works best for you. Read our expert analysis now.

Audits
Compliance
ISO 27001

The ISO 27001 scope statement is one of the first steps for building your ISMS. Although it is just a short separate document or small paragraph in your security policy, it is one of the most important aspects of the certification. The scope statement is defined in the ISO/IEC 27001:2013 under section 4. It shortly describes the purpose or context of your organization and what processes are relevant to run your business. In other words, it defines the boundaries, subject, and objectives of your ISMS.

Some examples of scope statements include:

Long example –  

Design, Development, Manufacturing, Operations, Sales, Customer Experience,

Services and Support for Networking, Data Center, Communications, Video, Collaboration, and Security Products, Solutions, and Services related to the Wizbang Solution.

Specific processes around a solution –  

Development, provisioning, and customer support of software for designing, automating, and analyzing business processes (for on-premise and cloud product offerings).

Associated physical security –  

The physical and logical protection of customer and company data and associated information assets in use, stored, and accessed in the company office or remotely for the provision of professional services that include service management, cyber security operations, and associated consulting services.  

Key aspects to consider when developing the scope are:

  • business processes that are important to operate your organization
  • mandatory laws and regulations
  • all interested and relevant parties (internal and external) for your ISMS or information security
  • norms and dependencies

When determining the scope, consider what your customers are concerned about and capture the processes that are used to define your scope. The ISO certificate can be a marketing tool and a market differentiator for your organization.  

Think about the business model of your organization and what processes are critical to the business. What business locations should be included, what type of information is stored, and what services and processes do the organization offer? Identify relevant and important stakeholders and key players (external and internal) and gather feedback for expectations about information security, IT security, or other areas that need to be protected.

The scope statement doesn’t need to be long or detailed, it simply needs to convey the processes that are going to be included in the certification. Just remember this statement will be displayed on the certificate and should accurately reflect the areas of certification.

Sep 18, 2023

How Your Customer Success Manager fits into your journey to SOC 2 compliance

Stay ahead of the compliance curve with the help of your Customer Success Manager. Read on to learn how they fit into your SOC 2 journey.

Customer Success
SOC 2

For many companies trying to achieve SOC 2 compliance, keeping up with both the work necessary to get their controls in place along with actually running their business can be quite the juggling act. Luckily, you have a Customer Success Manager (CSM) to help!


So, what exactly does your CSM do? Simply put, your CSM will be your primary point of contact and the main person managing your account throughout the audit process. They are there to help make the roadmap ahead clear,  answer questions as you begin your journey, and are then there to keep the audit engagements on track for the years ahead. In order to better understand, let’s touch on the core aspects of a CSM’s role when helping you:

Onboarding

First and foremost, from the moment you sign on to have your audit performed, your CSM is the person who will be scheduling and then holding a kickoff meeting to help set expectations and answer any initial questions you might have as you’re getting started. This meeting walks through the process from start to finish, as well as establishes what the regular communications between you and them will look like moving forward. After the kickoff meeting, they will provide any necessary documents/links to help make sure you have everything to coordinate the audit.

Answering Questions and Scheduling the Audit

Once you’ve gotten your feet wet and have an understanding of what the next steps are, your CSM will be regularly checking in with you to see how things are going as well as provide support for any questions you might have. As you’re going through setting things up, they’ll also be on hand to schedule your audit and coordinate with any readiness platforms you are utilizing to support your SOC 2 compliance.

Supporting the Audit Itself

Once you have the date(s) you want to use for your SOC 2 audit, your CSM will then hand you off to our Audit Associates so that the controls testing can begin. While the CSM will not be performing the audit themselves, they work closely with the Audit team and communicate closely so that the project continues moving forward and you get your report as quickly as possible. If there are any additional evidence pieces needed or clarifications necessary, your CSM will coordinate with the Audit team to make sure these outstanding items are settled.

Continuing and Building Our Partnership

You’ve done it!

You finally have your SOC 2 report in hand! With the audit now complete, your CSM will be one of the first people out the gate to congratulate you; not only that, but they’ll also set expectations as to when we’ll reach out regarding the next report to ensure you won’t have any gaps in your compliance. After a few months, your CSM will reach out to see what your plans for your next SOC 2 report are; in that, they’ll provide a quote as well as coordinate having the Statement of Work (SOW) signed to formalize the engagement. Once you’re signed on, they’re once again there to support you for the various SOC 2 reports to come!

Whether you’re going for your first SOC 2 report ever or you’re a seasoned compliance veteran, it’s important to us that you have every possible tool and aid at your disposal so that you can walk through each step of the audit process with complete confidence that you will succeed.

In all, your CSM is the person to help make this happen; there to help make sure you will come out the other side of this journey with a report that leaves you and your customers satisfied. Whenever you feel stuck, you need only shoot an email over or make a phone call, and your CSM will be there!

Sep 11, 2023

Key Differences Between ISO 27001 and 27002

Streamline your payment security controls to protect transactions and maintain merchant trust.

ISO 27001
ISO 27002
ISO

Information security is a pressing concern for organizations.

Cyber threats are on the rise, and more personal information falls into the wrong hands every day.

That's why organizations with an ISMS (information security management system) rely on standards in a set of series called the ISO 27000 series published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Within the ISO 2700 series are the ISO 27001 and 27002.

This article will discuss some key differences between ISO 27001 and 27002 and how each standard helps protect an organization's data from cyber threats.

But before we go into the differences, it's important to note that the ISO 27000 series standards focus on information security. They do not include physical safety, personnel security, or software development requirements.

ISO/IEC 27001 and 27002, what's the difference?

While seemingly similar, the two are just as different. If combined into one singular standard, the compliance criteria would be too complicated to implement and use practically.

To keep it simple, ISO 27001 is a recognized standard for an organization's ISMS. Think of it as a checklist of everything you must complete to receive compliance certification.

ISO 27002 references cyber security, privacy protection, information security, and risk assessment rules.

So, the key differences between the two are:

  • Details:  ISO 27001 is broad regarding ISMS implementation controls and rules, while ISO 27002 offers detailed recommendations for compliance criteria.
  • Applicability: Every ISMS organization and business isn't the same; therefore, following ALL of the recommendations listed in ISO 27002 wouldn't be realistic or needed. ISO 27001 requires organizations must undergo a risk assessment to identify risks but doesn't specify which ones. That is where ISO 27002 comes in handy. Use it as a guide for compliance to prioritize potential risks for your organization.
  • Certification: Your organization can only be certified in compliance with ISO 27001 standards. Becoming certified means your organization is fully compliant in your efforts to manage confidential data and information–both your employees and your customers.

Looking for ISO 27001 Compliance Certification? Start now.

What is the benefit of gaining ISO 27001 compliance certification?

ISO 27001 is considered the gold standard for information security management.

It helps organizations implement a system of internal controls to control and monitor their information security risks.

The goal of ISO 27001 is to ensure that an organization maintains a high level of protection for its customers, business partners, employees, and suppliers by implementing an effective ISMS (Information Security Management System).

Organizations can meet this goal by complying with the standards outlined in ISO 27001/27002:

  • Risk assessment
  • Asset classification and identification
  • Control implementation and maintenance

While it's true that you can implement an effective information security program without certification, it's highly recommended to do so because most top-tier customers require certification before they'll consider doing business with you.

This requirement makes sense when you consider that any company possessing sensitive personal or financial data would want to know that their provider has taken all necessary precautions to safeguard this information against cyber attacks. A certificate of ISO 27001 compliance will help ensure this protection.

Examples of how ISO 27001 and ISO 2007 are different:

  • The focus of the standards:

The focus of both standards is on information security management, but they take different approaches.

ISO 27001 focuses on information security management and is a generic standard, meaning that the criteria within ISO 27001 can apply to any organization regardless of its sector or industry.

ISO 27002 focuses on data security and is specific; it provides guidance for implementing specific controls within an organization's IT infrastructure (e.g., firewalls).

An organization must determine what type of system or system components will be covered by this standard. For example, a financial institution would focus on entirely different control standards to comply with than a healthcare organization would.

  • Process vs. implementation requirements:

In addition to addressing different organizational needs based on sector and industry type, these standards also differ in process requirements versus implementation requirements—that is, how they handle each step required during your risk management program's lifecycle.

Both standards include sections dedicated solely to defining policies explicitly related to risk assessment (ISO/IEC 27000 - 4) and how to implement the suggested measures into daily operations, such as incident response plans (ISO 14701).

Why you need a CPA firm to help your organization with your ISO 27001 or ISO 27002

When managing ISO 27001 or ISO 27002, you need a CPA firm to help your organization with the following:

  • A plan:

A solid plan aligned with your business goals and objectives will be essential to ensure success. You will also want to ensure that all key stakeholders are involved in developing this plan.

  • Processes and procedures:

Once you have created your plan, it is crucial to define how you will implement it within your organization so everyone knows what's expected of them when carrying out their responsibilities as needed throughout each stage of the ISMS life cycle.

  • Knowing the right tools to use for your specific industry and organization:

For example, if your organization is sharing sensitive data across different departments, you will probably need encryption technology like passwords and biometrics authentication systems (fingerprint readers). An experienced CPA in ISO 27001/27002 compliance can suggest the right tools to help you meet compliance criteria.

Information security is laudable. It needs to be done right to make sure that it is effective.

To recap: The difference between 27001 and 27002 is that they both focus on information security but differ in how they go about it.

ISO 27001 focuses more on the processes of an organization, while ISO 27002 focuses more on the products or services that an organization provides.

The best way to protect yourself from cyberattacks is by having a team of professionals who understand both standards to help implement them correctly for your business needs.

Ready to get ISO 27001 certified? Contact Johanson Group today to get started.

No results found.
No results found for your search query
PCI Compliance Guide
Determining the Scope Statement
SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
What is a SOC 2 Bridge Letter?
Your Guide to SOC 2 Attestation Reports
What is SOC 2 Penetration Testing and Why You Need One
Key Differences Between ISO 27001 and 27002
How Your Customer Success Manager fits into your journey to SOC 2 compliance
What is the difference between SOC 2 Type 1 and SOC 2 Type 2