Why We Partnered with Rippling - and What It Means for Your SOC 2 Audit

We're excited to announce our partnership with Rippling as an independent audit firm for their newly launched Rippling Automated Compliance platform.

As independent auditors, we've sat across the table from thousands of companies preparing for their SOC 2. And we'll be honest: the audit itself is rarely the hardest part. The hard part is everything that comes before it — the scramble to pull evidence, the gaps in controls that only surface under scrutiny, and the months of back-and-forth that follow.

That's exactly why we're excited to announce our partnership with Rippling as an independent audit firm for their newly launched Rippling Automated Compliance platform.


What Makes Rippling Different

We’re extremely careful about which platforms we partner with. As a CPA firm, our credibility depends on maintaining independence. What impressed us about Rippling's approach is that compliance is built around what companies are already doing — not a bolted on check-the-box scramble to collect evidence.

Most compliance platforms require significant setup before they can collect a single piece of evidence. A company needs formalized processes in place related to system provisioning, device security, training, and people management all wired together first. Rippling already is that infrastructure for many companies, which means the evidence Rippling can provide is rooted in real company operations.

From where we sit, that changes the audit experience meaningfully. Rippling clients provide us with well-organized, continuously collected evidence. Which means they’re better positioned to respond promptly to evidence requests and they’re able to present complete and observable evidence from the beginning. Of course every company and audit is distinct, but RIppling provides our clients with a strong foundation for procuring and presenting the evidence we need.

Our Role in the Process

Rippling guides companies through evidence collection and control implementation. Our role, as always, is to serve as the independent third party — sampling that evidence, testing controls, and issuing a trustworthy SOC 2 report that a company’s customers and prospects actually rely on.

Independence matters more than ever before. A SOC 2 report only carries weight when it comes from an auditor with no stake in the outcome. That's us, and that's the relationship we've built with Rippling: They guide companies to collect the needed evidence, and we independently audit that evidence to write our opinion.


Who This Is For

Rippling is starting with the SOC 2 framework, and we've already worked with a cohort of their customers to complete their reports. New frameworks are coming soon, and we're excited to be part of the journey.

We're excited for what this means for the GRC industry and the companies getting compliant moving forward. Rippling helps companies collect evidence of how their company already operates. They guide early startups through setting up secure and automated processes that avoid data vulnerabilities. 

We're continuing to do what we've always done. We audit a company's data and write an independent report. Rippling reduces the back-and-forth so we can focus on our work.

Ready to Learn More?

As an independent CPA firm, we’re here to perform your next audit. Reach out to Johanson Group team to get started.

Related articles

Mar 10, 2026

What is the difference between SOC 2 Type 1 and SOC 2 Type 2

SaaS companies are popular, but not all of them are able to stay compliant. An annual SOC 2 audit is one way to ensure organizational security and compliance.

SOC 2
Compliance

The AICPA defines a SOC 2 Type 1 report as - a report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.

To translate that to layman's terms - Is the company set up for success with its current controls and does the system description accurately reflect the company’s operations?

The AICPA defines a SOC 2 Type 2 report as - a report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.

To translate that to layman's terms - Did the company do what it said it was going to do when it said they were going to do it and does the system description accurately reflect the company’s operations?

SOC 2 Type 1

The SOC 2 Type 1 audit looks at one day (point in time) and gives the opinion that everything is set up correctly. The auditor will look at the system description and the controls to make sure that they match the SOC 2 criteria. The auditor will also look at the evidence to verify that the control is in place.

A SOC 2 Type 1 report will give you the peace of mind that you have designed your controls appropriately to meet defined Trust Services Criteria.

SOC 2 Type 2

All the work that you did for SOC 2 Type 1 applies to Type 2. Now you just need to follow those policies and do what you said you were going to do and collect the evidence to prove it. You have moved from the setup mode to the maintenance mode. A Type 2 report is demonstrating that the controls you designed and implemented in Type 1 are now operating effectively over the period chosen for the Type 2 audit.

Usually, the minimum audit period for a SOC 2 Type 2 is 3 months. You should talk with your customers to see if this will meet their needs. You might find one that will only take a minimum of 6 months. If your customers just need a report, then we would suggest going with the shorter period so that you can get out in the marketplace with the report and start winning new customers.

How To Decide What You Need

At the end of the day, your customers are going to want a SOC 2 Type 2 report.

If you need something quick to keep sales conversations going or as an internal milestone then a SOC 2 Type 1 is a great starting point. We would also suggest doing a SOC 2 Type 1 first if you are not using a readiness platform and are trying to do it by yourself. This will make sure that you are set up for a successful SOC 2 Type 2. You would hate to find out after your SOC 2 Type 2 audit period ended that your controls didn’t match the SOC 2 criteria. The SOC 2 Type 1 provides that safety net for you to know you are on the right path.

Deciding to do a SOC 2 Type 1 will not slow you down in obtaining a SOC 2 Type 2. While the audit is being performed on your Type 1 you can start the audit period for Type 2. That way you will already be part way through the audit period by the time you receive the SOC 2 Type 1 report.

The additional cost for a SOC 2 Type 1 report is usually fairly small. Most CPA firms will give you a bundled cost for a Type 1 and a Type 2 that provide the two audits at a significantly lower price.

If none of those cases fit your needs, then we would suggest you go straight for Type 2.

A readiness platform will make sure that all of your controls match the SOC 2 criteria and that you are set up for success.

If your customers will only take a SOC 2 Type 2 and you need something to prove you are taking it seriously and are working on your SOC 2, you can also ask your auditors for an engagement letter to share with your potential customers to show that you are working on your SOC 2 Type 2. That will have enough weight with potential clients to keep sales conversations moving forward.

SOC 2 Compliance Audit Readiness

No matter which path you take, you will end up at the SOC 2 Type 2 report. There isn’t a wrong way to approach it. As you are making your choice, talk to your customers (if you can) and talk to your auditor about what is going on. Your auditor can walk you through both paths and help you make the best decision for your company.

You’re dealing with private data and information, so suffice it to say, yes, a self-audit is a great way to ensure your organization takes its responsibilities for security seriously.

After a SOC 2 compliance self-audit and remediation, your organization is ready for its SOC 2 compliance audit from an experienced and specialized CPA like Johanson Group.

Aug 28, 2023

Your Guide to SOC 2 Attestation Reports

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

Reporting
SOC 2

During a SOC 2 attestation, companies need to use specific criteria to evaluate their services.

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

A Quick SOC 2 Refresh

You've landed on this article for SOC 2 attestation, so odds are you already know what a SOC 2 report is, but just in case, here's a quick refresh:

What does the S-O-C in 'SOC 2' mean?

  • The ‘S-O-C’ stands for System and Organization Controls Number Two.
  • SOC 2 is a set of standards developed by the American Institute of Certified Public Accountants (AICPA).
    • These standards help businesses evaluate their internal controls and ensure they meet industry best practices regarding information systems management and cyber security.
  • Now, onto the basics of SOC 2 attestation reports.

What is a SOC 2 attestation?

A SOC 2 attestation is a third-party assessment of a service organization’s controls relevant to

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

Why do you need a SOC 2 Attestation?

The idea behind a SOC 2 attestation is that companies can demonstrate their commitment to data protection by having their systems reviewed independently. Customers can then make informed decisions about whether it's safe to store sensitive information in the cloud and avoid legal issues down the road.

“The reason for a SOC 2 attestation is that it helps companies and clients know that information held at the service organization is being kept private and secure.”

What does a SOC 2 attestation include?

To assure customers that you're keeping their data safe and secure, you need to show that your company has thought through all aspects of data protection.

Including:

  • Who has access to customer data?
  • What measures do you take to protect information against cyberattacks?

What is required During a SOC 2 attestation?

During a SOC 2 attestation, companies are required to use a specific set of criteria to evaluate their services.

These criteria are organized into five trust services categories:

  1. Security (required)
  2. Availability (optional)
  3. Confidentiality (optional)
  4. Processing Integrity (optional)
  5. Privacy (optional)

You will also want to ensure that these controls are in place within your systems prior to your SOC 2 attestation with a CPA:

  • Network Firewalls
  • Two-factor authentication
  • Intrusion detection
  • Performance monitoring
  • Disaster recovery and Incident response procedures
  • Security breach management
  • Quality assurance
  • Process monitoring
  • Data encryption
  • Access controls (physical and logical)
  • Change Management processes

How long does a SOC 2 attestation take?

A SOC 2 Type I (point-in-time) attestation is typically completed in about 4-6 weeks. This may seem like a long time, but remember that it takes more time for complex organizations than for simple ones.

While these variables are essential in determining the duration of your audit, there are also other factors at play:

  • If you're working with a new auditor and they don't have much experience on their side yet (for example, if you're their first client), then this will slow down the process somewhat as well. That's why we recommend choosing a CPA specializing in SOC 2 attestations like Johanson Group.
  • Some companies may need additional support before providing all the necessary documentation required by SOC 2 auditors; this may add days or weeks to your timeline!

Need to add in SOC 2 Type II (period of time) details. Those audits are a minimum of 3 months the first time and 12 months for subsequent type II audits. Type I tests the design of control, whereas Type II tests both design of controls and their operating effectiveness over a period of time.

How much does a SOC 2 attestation cost?

The cost of a SOC 2 attestation depends on many factors, including:

  • Size: Smaller organizations can often complete an audit at a lower cost than larger ones.
  • Complexity: Suppose your company uses more complex controls and procedures than other companies. In that case, it will cost more to audit you than if it did not have as much complexity in its controls.
  • Type of Service: What type of service is provided by the system being audited? For example, a mobile app for a SaaS start-up may be less expensive than an internal data protection solution for a SaaS healthcare provider due to its more straightforward design and architecture requirements.
  • Type of audit (i.e., standard or enhanced): A standard assessment costs less than one that includes additional testing for application-specific vulnerabilities and threats (enhanced.)

The SOC 2 attestation process with Johanson Group

  • The first step is to determine whether or not you are eligible for SOC 2 attestation services. If so, we will conduct an initial assessment and provide an estimate based on our findings.
  • Once we have reviewed the scope of work and estimated costs, we can begin working with you to develop a detailed plan for implementing security controls into your existing environment. Our goal is always to achieve compliance as efficiently as possible while minimizing disruption to business operations.

In short, a SOC 2 report evaluates whether a service organization's systems and processes meet high standards for security and privacy.

It also assures on behalf of service providers so they can show customers how they use their information responsibly.