Resources

Articles

Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Filters
Show all
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Sep 24, 2022

Your Pre-Audit Checklist for SOC 2 Compliance

Your Pre-Audit Checklist for SOC 2 Compliance

SOC 2

If you want to assess SOC 2 compliance for your business, it helps to do a pre-audit. This checklist will help you organize the tasks and details required to assess and address any issues before your first SOC 2 compliance audit.

But first, let’s cover a few of the basics.

What does SOC 2 compliance mean?

SOC 2 (pronounced "sock") compliance is an industry-standard focusing on a company's information security and privacy practices. The goal is to protect your users' private information and ensure that it is managed securely.

Why is SOC 2 compliance important?

Security is a top concern for all organizations, especially SaaS and cloud-computing providers. When privacy data is mishandled, it leaves the organization's and its customer's data at risk of theft, extortion, malware installation, and other cyber attacks.

Are you ready for your SOC 2 audit?

To achieve SOC 2 compliance, companies must adhere to specific procedures and policies set by the American Institute of Certified Public Accountants (AICPA).

Before an experienced SOC 2 CPA completes your audit, you can ensure you’re meeting expectations by performing a self-audit. How?

We’ve created a quick and easy checklist for you to prepare for your SOC 2 audit:

Please note, that while there are five categories within the Trust Services Categories listed below, only the ‘Security’ category is required for a SOC 2. However, when trusted with private data and security, the rest of the Trust Service Categories are recommended but not required.

  • Do your controls meet the relevant Trust Services Categories?

Privacy

Do you manage private data with any of the following?

  • Access control
  • Two-factor authentication
  • Encryption

Security

Do you manage customer and/or employee data with any of the following?

  • Logical and Physical Access control
  • Network firewalls
  • Intrusion detection
  • Two-factor authentication

Availability

Do you have availability controls and processes in place, such as:

  • Handling of security incidents
  • Disaster recovery
  • Performance monitoring
  • System and Data Backups

Processing Integrity

Can you provide proof of:

  • Data integrity; ensuring accuracy and completeness of data
  • Processing monitoring; error detection and correction, job reporting, and audit trails

Confidentiality

Can you provide proof of:

  • Data encryption
  • Access controls
  • Data Retention and Destruction Procedures

My organization completed a SOC 2 compliance self-audit. Now what?

After going through the above checklist, make sure that you are:

  • Remediating any areas where your organization is not meeting the AICPA’s defined SOC 2 criteria, based on your chosen criteria within the Trust Services Categories.Meet and communicate with stakeholders and employees the results of the self-audit, and remediation plans to create a culture of security and compliance throughout the organization.

SOC 2 Compliance Audit Readiness

You’re dealing with private data and information, so suffice it to say, yes, a self-audit is a great way to ensure your organization takes its responsibilities for security seriously.

After a SOC 2 compliance self-audit and remediation, your organization is ready for its SOC 2 compliance audit from an experienced and specialized CPA like Johanson Group.

ABOUT JOHANSON GROUP:

Johanson Group, based in Colorado Springs, CO, provides audits and professional services to public and private companies in a variety of industries world wide.

We serve:

  • SaaS Start-ups
  • SaaS Healthcare Organizations
  • Established SaaS Companies
  • Government SaaS Organizations

We provide:

  • SOC 2 assessments
  • HIPPA assessments
  • ISO/IEC 27001 reports
Sep 16, 2022

What is a SOC 2 Attestation?

What is a SOC 2 Attestation?

SOC 2

The SOC 2 report, or attestation, is the output of the audit. It contains the opinion of the auditor, a description of the platform being audited and the results of the audit.

Section 1 -Independent Service Auditor’s report

The opinion section of the audit report lays out the scope of the audit, the company’s responsibilities, the CPA (auditors) firm’s responsibilities, any imitations of the audit and the opinion.

The audit firm expresses an opinion on three distinct but complementary subject matters.

  1. Whether the description of the system is presented in accordance with the description criteria.
  2. Whether controls were suitably designed to provide reasonable assurance that the company’s services commitments and system requirements were achieved based on the applicable trust services criteria.
  3. Whether controls operated effectively to provide reasonable assurance that the company's service commitments and system requirements were achieved based on the applicable trust service criteria.

Below is what the opinion of a “clean” audit should look like.

In our opinion, in all material respects,

a. The description presents XYZ, Inc.’s Really Cool (system) that was designed and implemented throughout the period of Month 01, 202X to Month 31, 202X in accordance with the description criteria.

b. The controls stated in the description were suitably designed throughout the period Month 01, 202X to Month 31, 202X, to provide reasonable assurance that XYZ, Inc.’s service commitments and system requirements would be achieved based on the applicable trust services criteria if its controls operated effectively throughout the period and if the sub-service organization and user entities applied the complementary controls assumed in the design of XYZ, Inc.’s controls throughout the period.

c. The controls stated in the description operated effectively throughout the period Month 01, 202X to Month 31, 202X, to provide reasonable assurance that XYZ, Inc.’s service commitments and system requirements were achieved based on the applicable trust services criteria if complementary sub-service organization controls and complementary user entity controls assumed in the design of XYZ, Inc.’s controls operated effectively throughout the period.

Section 2 - Assertion of XYZ Management

In this section the organization’s management basically says that the company has done everything according to the guidelines the AICPA has laid out, they haven’t lied or hid anything from the auditors. Below is a sample of what the company’s management is asserting.

We confirm, to the best of our knowledge and belief, that:

a. The description presents XYZ, Inc.’s Really Cool (system) that was designed and implemented throughout the period of Month 01, 202X to Month 31, 202X, in accordance with the description criteria.

b. The controls stated in the description were suitably designed throughout the period Month 01, 202X to Month 31, 202X, to provide reasonable assurance that XYZ, Inc.’s service commitments and system requirements would be achieved based on the applicable trust services criteria if its controls operated effectively throughout that period, and if the sub-service organization and user entities applied the complementary controls assumed in the design of XYZ, Inc.’s controls throughout that period.

c. The controls stated in the description operated effectively throughout the period Month 01, 202X to Month 31, 202X, to provide reasonable assurance that XYZ, Inc.’s service commitments and system requirements were achieved based on the applicable trust services criteria if complementary subservice organization controls and complementary user entity controls assumed in the design of XYZ, Inc.’s controls operated effectively throughout that period.

CTA: READ More:

Section 3 - System Description

In this section, the organization lays out the platform or system that is being audited. They are “drawing a box” around what was in the scope of the audit. The system is defined as the “infrastructure, software, procedures and data that are designed, implemented and operated by people to achieve one or more of the organization's specific business objectives (for example, delivery of services or production of goods) in accordance with management-specified requirements.”

DC Section 200 says, “Though the description is generally narrative in nature, there is no prescribed format for the description. Flowcharts, matrixes, tables, graphics, context diagrams, or a combination thereof may be used to supplement the narratives contained within the description.” This means that there is no one way that the system description needs to be laid out. As long as it covers the required information and is able to be understood by the reader it is acceptable.

Most auditors will have a template for you to use. Some SOC 2 readiness platforms also have a template generator.

You can contact us for our template.

You can also read the specific guidelines from the AICPA here .

Description of Test of Controls and Results Thereof

This is where the auditor lays out the controls that were tested and the results of the tests. You hope to see “No exceptions noted” in the Results of Service Auditor’s Test of Controls column. This means that the auditor found that the organization was following the control based on the evidence.

If you see “No events to test” it means that the event did not occur during the audit period. For example, a smaller start-up company may not have any employees that terminated during the audit period. The auditor would not have any evidence to show that the company did or did not follow the applicable procedures and policies.

If you see “Exceptions noted”, it means that the auditor found in some situations that the organization did not follow the control. If you see this you will also see a Section V of the report, where management responds to why the control experienced exceptions during the examination period.

Sample SOC 2 report

The AICPA has created a sample report

Your report’s format will look slightly different based on the CPA firm performing the audit but all of the critical information will be there.

The SOC 2 report, or attestation, is what your customer will request to make sure that your security posture is up to industry standards and that you are a safe company to work with. We advise those with a SOC 2 report to have those you are sharing it with sign an NDA (non disclosure agreement) due to the sensitive nature of the contents of the report.

ABOUT JOHANSON GROUP:

Johanson Group, based in Colorado Springs, CO, provides audits and professional services to public and private companies in a variety of industries world wide.

We serve:

  • SaaS Start-ups
  • SaaS Healthcare Organizations
  • Established SaaS Companies
  • Government SaaS Organizations

We provide:

  • SOC 2 assessments
  • HIPPA assessments
  • ISO/IEC 27001 reports
Aug 31, 2022

Essential Knowledge: SOC 2 Compliance Requirements

Essential Knowledge: SOC 2 Compliance Requirements

SOC 2

In its simplest form it is: did you do what you said you were going to do when you said you were going to do it?

Each company will need to identify the risks associated with their business, create controls to mitigate those risks, and then follow through with them. The AICPA has used the COSO framework to create the high-level criteria that need to be addressed as well as points of focus to consider. Each company can and should have controls that are relevant to its organization.

Learn more here and review the complete list of the criteria and points of focus.

SOC 2 Compliance list

There is not a minimum set of controls or a standardized template of controls that organizations can implement to help ensure that controls are suitably designed based on the applicable trust services criteria in a SOC 2 examination. A company should implement specific controls designed to mitigate risks identified by management, which could prevent the company from achieving its service commitments and system requirements. For that reason, SOC 2 does not prescribe specific controls for any organization. Instead, the trust services criteria establish the outcomes that those controls should meet to achieve a service organization’s service commitments and system requirements.

The AICPA has said: “Because each system and the environment in which it operates are unique, the combination of risks that would prevent a service organization from achieving its service commitments and system requirements, and the controls necessary to address those risks, will be unique in each SOC 2 examination. Management needs to identify the specific risks that threaten the achievement of the service organization's service commitments and system requirements and the controls necessary to provide a reasonable assurance that the applicable trust services criteria are met, which would mitigate those risks.”

Many organizations find this a little frustrating. There are a number of sample controls out there. Many compliance platforms have a basic list that you can use to get started. You will find that some of the controls don’t apply to your organization and that you will want to add other controls. That is exactly what you should do.

Compliance platforms

Compliance platforms such as Vanta, Secureframe, Drata, and Trustero make SOC 2 much easier. Without a platform, you will probably need to hire a CPA firm or a consultant to work with you to develop your controls. Then you will need to monitor all those controls manually. That is a significant cost in terms of money and time. It also leads to the possibility of exceptions on your SOC 2 report. You will also need someone to monitor those controls manually and collect the evidence. This usually ends up being a full-time position.

We see clients that use a compliance platform get ready to start their SOC 2 audit MUCH sooner than those without one. We also see that those that use a platform are less likely to have an exception. The audit process is much smoother as all the evidence is located in one place and appropriate evidence is collected. The time needed to monitor the controls and collect the evidence is greatly reduced to a few minutes each day.

What is the minimum time period for a SOC 2 Type II?

We get this question a lot. Often clients are under pressure to get their SOC 2 Type II quickly so that they can close a deal or they waited too long to get started.

The AICPA does not specify a minimum period for SOC 2 type II. What they do give is some things to consider to determine the audit period. The main point is, will the auditor be able to obtain sufficient evidence to support an opinion of the operating effectiveness of the controls? With the creation of compliance platforms, a three-month audit period is usually sufficient.

We do advise clients to talk to their auditors. We also suggest that if you are thinking about using a shortened period for your first SOC 2 Type II that you try to include as many annual, and semi-annual items as possible.  We also suggest that you talk with your potential clients, to see if a shortened audit period will be sufficient for their needs.

Do we need to have a Board of Directors?

No. The AICPA recognizes that smaller organizations don’t need to have a board of directors. They do give some guidance about things to consider. Here is what the AICPA has said:

Trust services criterion CC1.2 discusses the need for a board of directors that is independent of service organization management and exercises oversight of the development and performance of internal control. If a smaller, less complex service organization does not have an independent board of directors, how would the service auditor’s opinion on the suitability of the design of controls be affected?

TSP section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, defines a board of directors as follows:

Individuals with responsibility for overseeing the strategic direction of the entity and the obligations related to the accountability of the entity. Depending on the nature of the entity, such responsibilities may be held by a board of directors or supervisory board for a corporation, a board of trustees for a not-for-profit entity, a board of governors or commissioners for a government entity, general partners for a partnership, or an owner for a small business.

This definition recognizes that smaller, less complex businesses may find it costly and unnecessary to attract independent board members. These entities generally have different control environments, which may be as effective as those in larger, more complex organizations. In the context of a smaller, less complex service organization, an owner-manager may have far greater personal oversight over organizational structure operations; the ability to affect ethical values; and the ability to attract, retain, and hold accountable service organization personnel.

In addition, an owner-manager is likely to actively participate in the operation of key controls (by exercising a high level of supervision and review) to provide adequate oversight of internal control and to mitigate risks arising from the lack of segregation of duties that often exists in such organizations. When that is the case, a service auditor may conclude that the lack of a board of directors at a smaller, less complex service organization is unlikely to affect the achievement of the service organization’s service commitments and system requirements.

In some situations, however, an owner-manager may not have the knowledge or competence to perform the oversight role without placing excessive reliance on company service organization management. In this situation, the lack of independent oversight may result in a breakdown in internal controls and increase the risk of fraud. In such cases, the service auditor evaluates the effect of the design deficiency on the service organization’s achievement of its service commitments and system requirements; based on that evaluation, the service auditor may decide to modify the opinion on the suitability of the design in the SOC 2 report.

Our auditors found an exception: are we going to fail?

No. There isn’t a pass/fail grade for SOC 2 reports.

In general, an exception will not create the need for the auditor to change their opinion. It all depends on the type of exception, how long it took to remediate and if there were other compensating controls in place. You will have the opportunity to have a management response to the exception and explain what happened and what you have put in place to make sure it doesn’t happen again.

There isn’t a hard and fast rule as to the number of exceptions you can have before the auditor changes the opinion. The auditor will look at the deficiencies individually and in the aggregate. This means that professional judgment will be used in creating the opinion of the report.

Your organization will need to look at all aspects of the business to create sufficient controls and ensure that those controls are followed. Using a readiness platform will help you do all of this and decrease the potential of any exceptions. We see organizations of all sizes be able to successfully complete a SOC 2 Type I and Type II report with a “clean” audit opinion. We are sure that you can do it as well!

ABOUT JOHANSON GROUP:

Johanson Group, based in Colorado Springs, CO, provides audits and professional services to public and private companies in a variety of industries world wide.

We serve:

  • SaaS Start-ups
  • SaaS Healthcare Organizations
  • Established SaaS Companies
  • Government SaaS Organizations

We provide:

  • SOC 2 assessments
  • HIPPA assessments
  • ISO/IEC 27001 reports
No results found.
No results found for your search query
The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe
Essential Knowledge: SOC 2 Compliance Requirements
What is a SOC 2 Attestation?
Your Pre-Audit Checklist for SOC 2 Compliance
The Benefits of SOC 2 Compliance
SOC 2 Controls: What they are and how they help you stay compliant
The History of SOC 2 Compliance
IT Audit Checks: What You Need To Know
An Overview of a HIPAA Attestation of Compliance
SOC 2 vs. ISO 27001: Which to Choose
7 Things To Look For In A SOC 2 Auditor
SOC 2 Frequency: What You Should Know
Why SOC 2 Auditing Is Essential for SaaS Businesses
Why You Need a Cybersecurity Risk Management Policy, How to Write One—and Who Can Help
Choosing the Right Compliance Framework for Your Business: NIST vs ISO
Exploring the Five Trust Service Principles of SOC 2 Compliance
3 Essential Steps for Choosing the Right SOC 2 Risk Advisory Professional for Your Compliance Needs
How to Choose the Right ISO 27001 Penetration Testing Company
ISO Asset Management and Cybersecurity: Protecting Your Assets in the Digital Age
Understanding SOC 1 vs. SOC 2 Reports: Choosing the Right Compliance Framework for Your Organization
A Comprehensive Guide to ISO 27001 Annex A Controls for Information Security Management
HIPAA vs. HITRUST: What You Need to Know
Safeguarding Customer Trust: The Value of SOC 2 Audits
Streamlining The SOC 2 Audit Process in 10 Steps
How To Read A SOC 2 Report
HIPAA Compliance Made Simple: Your HIPAA Security Rule Checklist
Understanding HIPAA Compliance Reports: A Comprehensive Guide
The Importance of ISO 27001 Certification for SaaS Providers
What is a ISO 27001 Surveillance Audit?
SOC 2 and HIPAA Compliance: Similarities and Differences
Information Security Audits: An Overview of Different Types
Developing a Robust Patch Management Policy for SOC 2 Audits
The Role of a CPA Firm in ISO 27001 Compliance Audits
SaaS Infrastructure: Best Practices for ISO 27001 Compliance
What is ISO 27001? A Comprehensive Guide to Compliance
Unlocking Growth: The Value of SOC 2 Compliance for Startups
ISO 27001 Audits: Understanding Stage 1 vs. Stage 2
The 5 Benefits of SOC 2 Reporting for Your Organization
HIPAA Compliance in 7 Steps: Your Ultimate Guide
ISO 27001 for Small Businesses
SOC for Cybersecurity vs. SOC 2: What’s the Difference?
Who Needs ISO 27001 Certification?
SOC 2 Compliance: 5 Common Questions
ISO 27001 vs ISO 27002: What’s the Difference?
The Ultimate Guide to GDPR
What is NIST 800-53?
CCPA vs GDPR: Navigating Privacy Regulations
ISO 27017 vs ISO 27018: Which Is Right for Your Business?
Understanding SOC 2 Trust Service Criteria
7 Common Myths About SOC 2: Debunking Misconceptions
Understanding CCPA Compliance
The Importance of Regular Security Audits for Your Organization
Common Misconceptions About Security Audits
ISO 27001 vs ISO 42001: A Comprehensive Comparison
Self-Attestation or Use an Auditor: What’s Best for Compliance?
Choosing the Right QSA for Your Business: A Practical Guide
Understanding Compliance vs. Security
What Is Required for a Successful SOC 2 Risk Assessment?
Common Cybersecurity Audit Pitfalls and How to Avoid Them
Unpacking Your SOC Audit Opinion: What Your Report Truly Means
What is NIST 800-171?
What is SOC 3? Everything You Need to Know
The Cost of PCI Non-Compliance: Fines, Breaches, and Reputational Damage
Compliance for Seed-Stage Startups: When Should You Start Thinking About SOC 2?
Understanding the Differences: SOC 1 Type 1 vs. Type 2
Why We Partnered with Rippling - and What It Means for Your SOC 2 Audit
PCI Compliance Guide
Determining the Scope Statement
SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
What is a SOC 2 Bridge Letter?
Your Guide to SOC 2 Attestation Reports
What is SOC 2 Penetration Testing and Why You Need One
Key Differences Between ISO 27001 and 27002
How Your Customer Success Manager fits into your journey to SOC 2 compliance
What is the difference between SOC 2 Type 1 and SOC 2 Type 2