Resources
Articles
Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe
The FBI logged over 1 million cybercrime complaints in 2025, totaling $20 billion in losses. Most weren't sophisticated hacks. They were email scams and ransomware exploiting weak processes and access controls. SOC 2 and ISO 27001 already cover the fixes. Here's the mapping.
The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe
Each year the FBI’s Internet Crime Complaint Center (IC3) issues a report on cybercrime. According to the 2025 report (https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf), the IC3 received over 1 million complaints with over $20 billion in reported losses.
How fraudsters are stealing from companies might be the most surprising stat. Investment fraud totaled $8.6 billion, Business email compromise totaled $3.05 billion, and tech support scams came in at $2.13 billion.
Business Email Compromise
The FBI classifies Business Email Compromise as a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments. These sophisticated scams are carried out by fraudsters by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications, through social engineering or computer intrusion techniques to conduct unauthorized transfer of funds.
SOC 2 and ISO 27001 both have controls that can make employees aware of the scam and provide other ways to identify bad actors.

Ransomware - Not Just an Enterprise Problem
When we talk about security incidents we often think of bots and ransomware. Ransomware accounted for $32 million in reported losses. The FBI notes that this number is low as it does not account for losses due to downtime, remediation, third-party recovery costs and that many organizations don’t report it at all. Many small and medium sized businesses may assume that ransomware is just an enterprise problem, the top reported industries were legal services (18%), contracting (17%), engineering/architectural services (10%), consulting (7%) and non-critical manufacturing (5%).
What can organizations do to stop these threats? Here is a table of FBI (https://www.fbi.gov/investigate/cyber) recommendations for protection against Ransomware attacks mapped to SOC 2 and ISO 27001 controls:

The Takeaway
The FBI’s Internet Crime Complaint Center tells a consistent story about how attacks cost business money. Business email compromises and ransomware don’t succeed because of a lack of technology. They succeed due to gaps in processes, training or access control that gave an attacker the opening they needed.
The SOC 2 and ISO 27001 frameworks provide organizations with a structured way to build processes and habits. These frameworks do more than just unlock sales and get you out of filling out a vendor questionnaire, they help protect your customers, brand reputation and bottom line.

Understanding the Differences: SOC 1 Type 1 vs. Type 2
Let's delve into the depths of these audits to decipher their dissimilarities and understand which one suits your organization's needs best.
What is a SOC 1 Audit?
Before delving into the nuances of SOC 1 Type 1 and Type 2 audits, it's essential to grasp the fundamental concept of a SOC 1 audit. SOC, or Service Organization Control, is a set of auditing standards developed by the American Institute of Certified Public Accountants (AICPA). These standards are designed to assess the effectiveness of a service organization's internal controls over financial reporting. In essence, SOC 1 audits provide assurance to stakeholders regarding the accuracy and reliability of the financial information processed by service organizations.
What is a SOC 1 Type 1 Audit?
A SOC 1 Type 1 audit is an evaluation conducted by an independent auditor to assess the fairness of the description of a service organization's system and the suitability of the design of its controls at a specific point in time. In simpler terms, it scrutinizes the organization's control environment and evaluates whether the controls are appropriately designed to achieve specified control objectives. However, it's essential to note that SOC 1 Type 1 audits do not assess the operational effectiveness of these controls over time; instead, they provide a snapshot of controls at a particular moment.
READ MORE: SOC 1 vs SOC 2 vs SOC 3: Understanding the Differences
What is a SOC 1 Type 2 Audit?
On the contrary, a SOC 1 Type 2 audit delves deeper into the operational effectiveness of controls. In addition to evaluating the design of controls, it assesses how well these controls have been functioning over a minimum period of six months. This extended evaluation period provides stakeholders with greater assurance regarding the consistency and reliability of the service organization's control environment. SOC 1 Type 2 audits offer a comprehensive assessment of whether the controls specified in the organization's description are operating effectively throughout the specified period, providing stakeholders with valuable insights into the organization's control environment's ongoing performance.

Choose Johanson Group for Your Next SOC Audit
Navigating the complexities of SOC 1 audits requires expertise and dedication to compliance excellence. At Johanson Group, we specialize in delivering tailored SOC audit services designed to meet your organization's unique needs. Whether you're seeking a baseline assessment with a Type 1 audit or comprehensive assurance with a Type 2 audit, our team of experienced professionals is committed to guiding you through the audit process seamlessly.
Choose Johanson Group as your trusted partner for SOC compliance, and embark on a journey towards enhanced transparency, reliability, and peace of mind. Contact us today to learn more about our services and take the first step towards safeguarding your organization's financial integrity.

Why We Partnered with Rippling - and What It Means for Your SOC 2 Audit
We're excited to announce our partnership with Rippling as an independent audit firm for their newly launched Rippling Automated Compliance platform.
As independent auditors, we've sat across the table from thousands of companies preparing for their SOC 2. And we'll be honest: the audit itself is rarely the hardest part. The hard part is everything that comes before it — the scramble to pull evidence, the gaps in controls that only surface under scrutiny, and the months of back-and-forth that follow.
That's exactly why we're excited to announce our partnership with Rippling as an independent audit firm for their newly launched Rippling Automated Compliance platform.
What Makes Rippling Different
We’re extremely careful about which platforms we partner with. As a CPA firm, our credibility depends on maintaining independence. What impressed us about Rippling's approach is that compliance is built around what companies are already doing — not a bolted on check-the-box scramble to collect evidence.
Most compliance platforms require significant setup before they can collect a single piece of evidence. A company needs formalized processes in place related to system provisioning, device security, training, and people management all wired together first. Rippling already is that infrastructure for many companies, which means the evidence Rippling can provide is rooted in real company operations.
From where we sit, that changes the audit experience meaningfully. Rippling clients provide us with well-organized, continuously collected evidence. Which means they’re better positioned to respond promptly to evidence requests and they’re able to present complete and observable evidence from the beginning. Of course every company and audit is distinct, but RIppling provides our clients with a strong foundation for procuring and presenting the evidence we need.
Our Role in the Process
Rippling guides companies through evidence collection and control implementation. Our role, as always, is to serve as the independent third party — sampling that evidence, testing controls, and issuing a trustworthy SOC 2 report that a company’s customers and prospects actually rely on.
Independence matters more than ever before. A SOC 2 report only carries weight when it comes from an auditor with no stake in the outcome. That's us, and that's the relationship we've built with Rippling: They guide companies to collect the needed evidence, and we independently audit that evidence to write our opinion.
Who This Is For
Rippling is starting with the SOC 2 framework, and we've already worked with a cohort of their customers to complete their reports. New frameworks are coming soon, and we're excited to be part of the journey.
We're excited for what this means for the GRC industry and the companies getting compliant moving forward. Rippling helps companies collect evidence of how their company already operates. They guide early startups through setting up secure and automated processes that avoid data vulnerabilities.
We're continuing to do what we've always done. We audit a company's data and write an independent report. Rippling reduces the back-and-forth so we can focus on our work.
Ready to Learn More?
As an independent CPA firm, we’re here to perform your next audit. Reach out to Johanson Group team to get started.

SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
SOC 1, SOC 2, SOC 3 — same family, very different reports. Here's how to know which one your customers are actually asking for.
The short version
All three reports are issued under the AICPA's System and Organization Controls framework. Where they differ is what they evaluate and who they're written for.
- SOC 1 — Controls relevant to your customers' financial reporting. Restricted-use report.
- SOC 2 — Controls relevant to security, availability, processing integrity, confidentiality, and privacy. Restricted-use report.
- SOC 3 — A public-facing summary of your SOC 2. General-use report.
If your customers care about how you handle their data, you're looking at SOC 2 (and possibly SOC 3). If they care about how you affect their financial statements, you're looking at SOC 1.
SOC 1: built for financial reporting
A SOC 1 report exists for one reason: to give your customer's auditors the comfort they need when your services impact your customer's financial statements.
Classic examples of who needs SOC 1:
- Payroll processors
- Loan servicing platforms
- Medical claims processing
- Fund administrators
- SaaS platforms that handle billing, revenue recognition, or accounting workflows on behalf of customers
The controls in scope are the ones that, if they failed, could cause a misstatement in your customer's books. Think: change management for billing logic, access controls around financial data, completeness and accuracy of transaction processing.
SOC 1 reports come in two flavors:
- Type 1 — Design of controls at a point in time.
- Type 2 — Design and operating effectiveness over a period (usually 6–12 months).
SOC 1 is a restricted-use report. It's written for your customers and their auditors — not for marketing.
SOC 2: the one most SaaS companies need
SOC 2 is the report procurement teams ask for when they're evaluating a vendor that touches their data. It evaluates your controls against the AICPA's Trust Services Criteria:
- Security (required in every SOC 2)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
Most SaaS companies start with Security only and add Availability or Confidentiality based on customer pressure or contractual commitments.
Like SOC 1, SOC 2 has a Type 1 and a Type 2 version. Type 1 covers a point in time; Type 2 covers a period — typically a minimum of three months for a first audit, then twelve months going forward. Most enterprise customers will eventually want a Type 2.
SOC 2 is also a restricted-use report. You can share it with prospects under NDA — and you absolutely should — but you can't post it on your website.
Which is exactly the gap SOC 3 fills.
SOC 3: the public version of SOC 2
SOC 3 is essentially a marketing-friendly version of your SOC 2. It uses the same Trust Services Criteria and is based on the same audit work, but it strips out the detailed control descriptions and test results. What's left is a high-level attestation you can publish on your website, hand out at trade shows, or include in sales decks without an NDA.
A few things worth knowing:
- You can only get a SOC 3 if a SOC 2 Type 2 has been (or is being) performed. SOC 3 isn't a standalone audit — it's a derivative report.
- SOC 3 is general-use. Anyone can read it.
- SOC 3 doesn't replace SOC 2. Enterprise procurement teams still want the full SOC 2 Type 2.
Think of SOC 3 as the trust badge on the homepage and SOC 2 as the document you send when a security questionnaire lands in your inbox.
Side-by-side comparison
How to choose
The decision usually comes down to three questions:
1. What do your customers' contracts and security questionnaires actually ask for?
Ninety percent of the time, this answers it for you. Read the requests instead of guessing.
2. Does your service affect your customers' financial statements?
If yes — payroll, billing, accounting, claims, fund services — you likely need SOC 1. If your customers' auditors are calling you, that's a strong signal.
3. Do your customers care about how you handle their data?
If yes, you need SOC 2. This covers most SaaS, hosting, managed services, and infrastructure providers.
Some companies need both SOC 1 and SOC 2 — for example, a billing SaaS that processes financial transactions and stores sensitive customer data. That's not unusual, just more work.
SOC 3 is rarely a starting point. It's something you add once your SOC 2 Type 2 is in place and marketing wants something they can publish.
What about ISO 27001, HIPAA, or PCI?
These often come up in the same conversation, but they're separate frameworks with their own audits and certifications. SOC reports don't replace them and they don't replace SOC reports. If you're juggling multiple frameworks, a good auditor can help you map overlapping controls so you're not doing the same work three times.
Bottom line
SOC 1 is for financial reporting. SOC 2 is for everything else customers worry about — security, uptime, data handling. SOC 3 is the public-facing version of SOC 2 you can share without an NDA.
The cleanest path for most SaaS companies: start with SOC 2 Type 1 to validate your control design, move into a SOC 2 Type 2 audit period, and add SOC 3 once you want a public-facing trust signal. If you process financial transactions on behalf of customers, layer in SOC 1.
Not sure which path fits your business? That's the kind of conversation a 30-minute call with a specialized auditor can resolve faster than another week of internal debate.

What is the difference between SOC 2 Type 1 and SOC 2 Type 2
SaaS companies are popular, but not all of them are able to stay compliant. An annual SOC 2 audit is one way to ensure organizational security and compliance.
The AICPA defines a SOC 2 Type 1 report as - a report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.
To translate that to layman's terms - Is the company set up for success with its current controls and does the system description accurately reflect the company’s operations?
The AICPA defines a SOC 2 Type 2 report as - a report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.
To translate that to layman's terms - Did the company do what it said it was going to do when it said they were going to do it and does the system description accurately reflect the company’s operations?
SOC 2 Type 1
The SOC 2 Type 1 audit looks at one day (point in time) and gives the opinion that everything is set up correctly. The auditor will look at the system description and the controls to make sure that they match the SOC 2 criteria. The auditor will also look at the evidence to verify that the control is in place.
A SOC 2 Type 1 report will give you the peace of mind that you have designed your controls appropriately to meet defined Trust Services Criteria.
SOC 2 Type 2
All the work that you did for SOC 2 Type 1 applies to Type 2. Now you just need to follow those policies and do what you said you were going to do and collect the evidence to prove it. You have moved from the setup mode to the maintenance mode. A Type 2 report is demonstrating that the controls you designed and implemented in Type 1 are now operating effectively over the period chosen for the Type 2 audit.
Usually, the minimum audit period for a SOC 2 Type 2 is 3 months. You should talk with your customers to see if this will meet their needs. You might find one that will only take a minimum of 6 months. If your customers just need a report, then we would suggest going with the shorter period so that you can get out in the marketplace with the report and start winning new customers.
How To Decide What You Need
At the end of the day, your customers are going to want a SOC 2 Type 2 report.
If you need something quick to keep sales conversations going or as an internal milestone then a SOC 2 Type 1 is a great starting point. We would also suggest doing a SOC 2 Type 1 first if you are not using a readiness platform and are trying to do it by yourself. This will make sure that you are set up for a successful SOC 2 Type 2. You would hate to find out after your SOC 2 Type 2 audit period ended that your controls didn’t match the SOC 2 criteria. The SOC 2 Type 1 provides that safety net for you to know you are on the right path.
Deciding to do a SOC 2 Type 1 will not slow you down in obtaining a SOC 2 Type 2. While the audit is being performed on your Type 1 you can start the audit period for Type 2. That way you will already be part way through the audit period by the time you receive the SOC 2 Type 1 report.
The additional cost for a SOC 2 Type 1 report is usually fairly small. Most CPA firms will give you a bundled cost for a Type 1 and a Type 2 that provide the two audits at a significantly lower price.
If none of those cases fit your needs, then we would suggest you go straight for Type 2.
A readiness platform will make sure that all of your controls match the SOC 2 criteria and that you are set up for success.
If your customers will only take a SOC 2 Type 2 and you need something to prove you are taking it seriously and are working on your SOC 2, you can also ask your auditors for an engagement letter to share with your potential customers to show that you are working on your SOC 2 Type 2. That will have enough weight with potential clients to keep sales conversations moving forward.
SOC 2 Compliance Audit Readiness
No matter which path you take, you will end up at the SOC 2 Type 2 report. There isn’t a wrong way to approach it. As you are making your choice, talk to your customers (if you can) and talk to your auditor about what is going on. Your auditor can walk you through both paths and help you make the best decision for your company.
You’re dealing with private data and information, so suffice it to say, yes, a self-audit is a great way to ensure your organization takes its responsibilities for security seriously.
After a SOC 2 compliance self-audit and remediation, your organization is ready for its SOC 2 compliance audit from an experienced and specialized CPA like Johanson Group.

Compliance for Seed-Stage Startups: When Should You Start Thinking About SOC 2?
Compliance for Seed-Stage Startups: When Should You Start Thinking About SOC 2?
In the early days of a seed-stage startup, "speed to market" is the only metric that matters. However, many founders accidentally accrue Compliance Debt. This happens when you ignore security documentation until a prospect asks for your SOC 2 report during the final stage of a huge deal.
Suddenly, your "speed" hits a brick wall. This guide explains how to time your compliance journey so it accelerates your growth instead of stalling it.
What is SOC 2 and Why Does It Matter for Startups?
SOC 2 (System and Organization Controls 2) is an auditing procedure developed by the AICPA. It ensures that service providers manage data securely to protect the interests and privacy of their clients.
For a seed-stage startup, SOC 2 serves three primary functions:
- Sales Enablement: It bypasses lengthy security questionnaires from enterprise procurement teams.
- Investor Due Diligence: It signals to VCs that your technical foundation is mature and "due diligence-ready."
- Risk Mitigation: It forces you to implement "least privilege" access and automated backups before a breach can kill your company.
Want to learn more about Why SOC 2 Matters? Click here!
The "Perfect Timing" Framework: When to Start
Don't start on Day 1, but don't wait until Day 500. Use these three triggers to decide when to pull the trigger:
1. The "Enterprise" Trigger
If your roadmap includes selling to banks, healthcare providers, or government-regulated entities, you need to start 6 months before your first major sales push.
2. The "Funding" Trigger
If you are preparing for a Series A, expect institutional investors to ask about your security posture. Having a SOC 2 Type 1 in hand shows you are a "grown-up" company.
3. The "Team Size" Trigger
Once you hit 10–15 employees, manual security "vibes" no longer work. You need automated policies for onboarding, offboarding, and laptop encryption.

Common Pitfalls for Seed-Stage Founders
- Over-scoping: You don't need all five "Trust Principles." Start with Security (the only mandatory one) and perhaps Confidentiality.
- Manual Evidence Collection: In 2026, if you are taking manual screenshots of your AWS settings, you’re doing it wrong. Use compliance automation platforms (like Vanta, Drata, or Secureframe).
- Treating it as a "One-Time" Event: SOC 2 is a "film," not a "photo." If you stop following your policies the day after the audit, your next report will fail.
Compliance as a Competitive Edge
In a crowded SaaS market, security is a feature. By starting your SOC 2 journey early, you aren't just "checking a box"—you’re building a moat that makes it easier for big companies to say "yes" to you. Get started today!



.avif)

