Resources

Articles

Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Filters
Show all
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Aug 28, 2023

Your Guide to SOC 2 Attestation Reports

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

Reporting
SOC 2

During a SOC 2 attestation, companies need to use specific criteria to evaluate their services.

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

A Quick SOC 2 Refresh

You've landed on this article for SOC 2 attestation, so odds are you already know what a SOC 2 report is, but just in case, here's a quick refresh:

What does the S-O-C in 'SOC 2' mean?

  • The ‘S-O-C’ stands for System and Organization Controls Number Two.
  • SOC 2 is a set of standards developed by the American Institute of Certified Public Accountants (AICPA).
    • These standards help businesses evaluate their internal controls and ensure they meet industry best practices regarding information systems management and cyber security.
  • Now, onto the basics of SOC 2 attestation reports.

What is a SOC 2 attestation?

A SOC 2 attestation is a third-party assessment of a service organization’s controls relevant to

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

Why do you need a SOC 2 Attestation?

The idea behind a SOC 2 attestation is that companies can demonstrate their commitment to data protection by having their systems reviewed independently. Customers can then make informed decisions about whether it's safe to store sensitive information in the cloud and avoid legal issues down the road.

“The reason for a SOC 2 attestation is that it helps companies and clients know that information held at the service organization is being kept private and secure.”

What does a SOC 2 attestation include?

To assure customers that you're keeping their data safe and secure, you need to show that your company has thought through all aspects of data protection.

Including:

  • Who has access to customer data?
  • What measures do you take to protect information against cyberattacks?

What is required During a SOC 2 attestation?

During a SOC 2 attestation, companies are required to use a specific set of criteria to evaluate their services.

These criteria are organized into five trust services categories:

  1. Security (required)
  2. Availability (optional)
  3. Confidentiality (optional)
  4. Processing Integrity (optional)
  5. Privacy (optional)

You will also want to ensure that these controls are in place within your systems prior to your SOC 2 attestation with a CPA:

  • Network Firewalls
  • Two-factor authentication
  • Intrusion detection
  • Performance monitoring
  • Disaster recovery and Incident response procedures
  • Security breach management
  • Quality assurance
  • Process monitoring
  • Data encryption
  • Access controls (physical and logical)
  • Change Management processes

How long does a SOC 2 attestation take?

A SOC 2 Type I (point-in-time) attestation is typically completed in about 4-6 weeks. This may seem like a long time, but remember that it takes more time for complex organizations than for simple ones.

While these variables are essential in determining the duration of your audit, there are also other factors at play:

  • If you're working with a new auditor and they don't have much experience on their side yet (for example, if you're their first client), then this will slow down the process somewhat as well. That's why we recommend choosing a CPA specializing in SOC 2 attestations like Johanson Group.
  • Some companies may need additional support before providing all the necessary documentation required by SOC 2 auditors; this may add days or weeks to your timeline!

Need to add in SOC 2 Type II (period of time) details. Those audits are a minimum of 3 months the first time and 12 months for subsequent type II audits. Type I tests the design of control, whereas Type II tests both design of controls and their operating effectiveness over a period of time.

How much does a SOC 2 attestation cost?

The cost of a SOC 2 attestation depends on many factors, including:

  • Size: Smaller organizations can often complete an audit at a lower cost than larger ones.
  • Complexity: Suppose your company uses more complex controls and procedures than other companies. In that case, it will cost more to audit you than if it did not have as much complexity in its controls.
  • Type of Service: What type of service is provided by the system being audited? For example, a mobile app for a SaaS start-up may be less expensive than an internal data protection solution for a SaaS healthcare provider due to its more straightforward design and architecture requirements.
  • Type of audit (i.e., standard or enhanced): A standard assessment costs less than one that includes additional testing for application-specific vulnerabilities and threats (enhanced.)

The SOC 2 attestation process with Johanson Group

  • The first step is to determine whether or not you are eligible for SOC 2 attestation services. If so, we will conduct an initial assessment and provide an estimate based on our findings.
  • Once we have reviewed the scope of work and estimated costs, we can begin working with you to develop a detailed plan for implementing security controls into your existing environment. Our goal is always to achieve compliance as efficiently as possible while minimizing disruption to business operations.

In short, a SOC 2 report evaluates whether a service organization's systems and processes meet high standards for security and privacy.

It also assures on behalf of service providers so they can show customers how they use their information responsibly.

‍

Aug 25, 2023

HIPAA Compliance Made Simple: Your HIPAA Security Rule Checklist

HIPAA Compliance Made Simple: Your HIPAA Security Rule Checklist

HIPAA
Checklist

Are you prepared for a HIPAA compliance audit? If not, you’re in the right place.

In this article we'll assist your organization in following the HIPAA Security Rule for your HIPAA compliance audit. This will ensure the safety of your ePHI and provide peace of mind to your patients, clients, employees, and stakeholders.

First, let's focus on protecting personal information, which is crucial and influenced by various factors.

Defining ePHI: Securing Electronic Health Information and Enhancing Patient Care


Unlike its non-digitized counterpart, ePHI exists electronically, including data created, stored, transmitted, or received digitally.

To protect against cyberattacks, organizations need strong security, while digital healthcare data enhances access and decision-making.

Why Protect ePHI: A Vital Patient-Centric Approach

Cybercriminals continually refine their tactics to exploit vulnerabilities, posing a significant risk to patient data security. Balancing ePHI security and efficient data sharing for patient care decisions is a difficult challenge.

Beyond the immediate imperative of regulatory compliance, protecting ePHI is a fundamental commitment to your patients and clients. By ensuring the confidentiality, integrity, and availability of ePHI, healthcare organizations actively safeguard patient trust and sensitive information.


Not protecting ePHI can lead to legal trouble, harm patient privacy, damage trust, and affect the quality of care.


ePHI includes digitally stored data points that identify individuals, including but not limited to:

  • Name
  • Phone number
  • Social Security number (SSN)
  • Email address
  • Date of birth
  • Medical records
  • Financial information
  • Address
  • Photos

A Real-World Lesson: Florida Health Plan's Alarming Data Breach

Florida Healthy Kids Corporation (FHKC), a large health plan, experienced a significant data breach. This breach affected 3.5 million individuals and found its place in the HIPAA Journal's list of the largest healthcare data breaches in 2021. The breach traced back to a hacking event that exposed sensitive health information like names, birth dates, diagnoses, and treatments.

This breach shows the importance of strong safeguards and strategies to protect health information and follow the HIPAA Security Rule.

Now that we understand the importance of safeguarding ePHI, let's explore how the HIPAA Security Rule actively ensures its protection.

Understanding How HIPAA Security Rule Safeguards ePHI

To follow HIPAA Security Rule, organizations must create a complete set of safeguards, both administrative and technical. These safeguards collectively form a robust shield that safeguards the integrity, confidentiality, and security of electronic protected health information (ePHI). By implementing these safeguards, organizations can demonstrate their unwavering commitment to upholding patient privacy, data security, and regulatory compliance.

READ MORE: An Overview of a HIPAA Attestation of Compliance

HIPAA Security Rule mandates strong safeguards and security measures for healthcare providers, insurers, and their partners to combat cyber threats.

We categorize these safeguards into three distinct pillars:

‍

HIPAA

1. Administrative Safeguards:

Administrative safeguards include appointing a security officer, controlling access based on roles, and regularly monitoring ePHI usage to ensure rule compliance and data protection.

2. Physical safeguards

Physical safeguards involve creating secure buildings, using access controls to stop unauthorized entry, and protecting the physical infrastructure that holds ePHI. These safeguards ensure the tangible security of electronic health information, contributing to a comprehensive defense against breaches and unauthorized access.

3. Technical Safeguards:

Technical safeguards include controlling ePHI access, recording ePHI activities, using anomaly detection for monitoring, and requiring encrypted ePHI sharing.

READ MORE: HIPAA vs. HITRUST: What’s the difference?


Your HIPAA Security Rule Checklist: A Path to Compliance3\

HIPAA

Ready for HIPAA Compliance?

Protecting electronic health information in line with HIPAA is a collaborative effort. This effort focuses on patient privacy and the preservation of healthcare data integrity. Your dedication to adhering to this comprehensive checklist signifies a proactive stance toward bolstering data security. It's important to bear in mind that the duty to safeguard patient information is a shared commitment.

We understand the importance of this effort and thank you for your strong dedication to keeping healthcare data private and secure. Your proactive engagement contributes to a safer and more secure healthcare environment for all.


Get expert help from the Johanson Group for HIPAA compliance, risk management, and data protection. Together, we'll ensure the highest standards of security for your organization and the patients you serve.


Contact us today to embark on this journey towards a more secure healthcare environment.

Aug 21, 2023

How To Read A SOC 2 Report

How To Read A SOC 2 Report

SOC 2

Reading a SOC 2 report can seem complex at first, but it's essential for assessing the security, availability, processing integrity, confidentiality, and privacy of a service provider's systems.

SOC 2 reports are often used to evaluate the controls and processes of technology service providers, like data centers, cloud providers, and software as a service (SaaS) companies. Here's a step-by-step guide on how to read a SOC 2 report:

Understand the Purpose of the Report:

SOC 2 reports are generated by a third-party auditor who evaluates the service provider's controls and processes in relation to the five trust principles mentioned above. These reports provide valuable information to clients and stakeholders about the security and reliability of the service provider's systems.

Determine the Type of SOC 2 Report:

There are two main types of SOC 2 reports: Type I and Type II. Type I reports focus on the design of controls at a specific point in time, while Type II reports cover the design and effectiveness of controls over a period of time (usually six months or more). Determine which type of report you're reviewing.

Review the Scope of the SOC 2 Report:

Understand the scope of the SOC 2 report. It should define the systems and processes that are being evaluated, as well as any limitations of the assessment.

Read the SOC 2 Auditor's Opinion:

Start by reading the auditor's opinion. This section will provide an overall assessment of the service provider's controls and processes. It will state whether the controls are suitably designed (for Type I) or designed and operating effectively (for Type II).

Review the Management's Assertion:

The management of the service provider will provide a statement asserting the accuracy and completeness of the information presented in the report. This is a critical section to understand the provider's commitment to their controls.

Examine the Description of Systems:

This section provides an overview of the service provider's systems and processes that were assessed. It includes details about the architecture, components, and technologies used.

Evaluate the Control Objectives and Activities:

This is the heart of the report. It describes the specific control objectives related to each of the trust principles and the corresponding control activities implemented by the service provider. It explains how the provider is meeting these objectives and securing its systems.

Review the Test Procedures:

In a Type II report, you'll find information about the tests performed by the auditor to evaluate the effectiveness of the controls. This might include details about sampling methods and evidence collected.

Analyze the Results and Findings:

If you're looking at a Type II report, you'll find the auditor's assessment of whether the controls were operating effectively. Any findings, exceptions, or deficiencies will be documented here. Understand the nature and severity of these findings.

Examine Additional Information:

Depending on the specific report, there might be additional sections providing context, background information, and details about the audit process.

Consider the Impact:

Interpret the findings in the context of your organization's needs. Consider whether any findings are significant enough to affect your decision to engage with the service provider. Keep in mind that some findings might be common or minor, while others could indicate larger security or reliability issues.

Consult with Experts (If Needed):

If you're not well-versed in understanding SOC 2 reports, consider consulting with experts who specialize in cybersecurity, compliance, or auditing. They can help you interpret the findings and their implications accurately.

Remember that SOC 2 reports can be complex, and understanding them thoroughly is crucial for making informed decisions about engaging with a service provider.

Contact Johanson Group today to learn more.

Aug 21, 2023

What is a SOC 2 Bridge Letter?

How do you provide assurance to your employees, stakeholders and potential customers and partners in between compliance audit review periods?

Reporting
SOC 2

What is a SOC 2 Bridge Letter?

How do you assure your employees, stakeholders, and customers of your SaaS company that their information is private and secure between compliance audit review periods?

Provide them a SOC 2 Bridge Letter.

A SOC 2 bridge letter is issued after your company or organization's SOC 2 report audit period has ended. It bridges the gap between the end of your last SOC 2 report audit and when you're ready to conduct your next audit, which is why it's also referred to as a 'gap letter.'

Usually, SOC 2 reports cover a user entity for 6 months to a year, but if your company follows a calendar year, then your report’s validity may leave you uncovered.

Does a SOC 2 bridge letter provide any coverage? In its most simple form, the answer would be:  No.

Bridge letters aren’t meant to take the place of another SOC 2 report, but to provide coverage of your company and trustworthiness to your customers and clients.

What Does a SOC 2 Bridge Letter Look Like & What is Included?

What a SOC 2 bridge letter should include:

  • Significant changes to any systems or controls since the audit

OR

  • A statement that the organization or company is unaware of any material changes from the latest SOC 2 report to its expiration.


What a SOC 2 bridge letter should NOT Include:

Remember, a bridge letter is sent to cover the gap between SOC 2 audit reports. It isn’t meant to take the place of the actual audit, therefore it shouldn’t include specific details like

  • Test procedures
  • Test results
  • System descriptions

Here's an example of a SOC 2 Bridge letter template Johanson Group provides to our clients:

Who Writes and Issues a SOC 2 Bridge Letter?

Management of the company that received the previous SOC 2 report completes and sends the SOC 2 Bridge Letter to its stakeholders (not the auditor).

The letter intends to assure all intended recipients that there have been no significant changes to your SaaS company's controls between audit renewal periods. If there have been material changes, the SOC 2 bridge letter is where you would explain changes to your controls — if any— and assure your customers or clients how they wouldn't affect the results of your SOC 2 report.

The CPA firm conducting the SOC 2 audit is not involved in the writing or disbursement of a SOC 2 bridge letter. Why?

The entire purpose of the SOC 2 bridge letter is to attest that client, stakeholder, and employee privacy and security are still in compliance. If something were to change with the company's security services after a SOC 2 is complete, the CPA firm that conducted the audit could not speak to the passing of any new changes after the audit expires.

Why are Bridge Letters Important?

As you can see, bridge letters are an essential part of your SOC 2 compliance program. The written assurance to your customers and stakeholders that you are still in compliance after your SOC 2 report helps bring confidence and peace of mind that their information is secure and private and trust service commitments and requirements are being met.

LEARN MORE: Why Saas Start-Ups Should Prioritize SOC 2 Compliance

As we have seen, SOC 2 bridge letters are critical to your SOC 2 compliance. They help you to demonstrate that your controls are appropriately designed and operating effectively and can be relied upon by all stakeholders.

We encourage all organizations who use IT services to consider applying for a SOC 2 report and getting the letter as soon as possible, if they haven’t already done so.Remember, a bridge letter is a temporary coverage for your trust services compliance. Schedule your subsequent SOC 2 audit examination today with Johanson Group, your trusted CPA for SaaS organizations.

‍

Jul 28, 2023

Safeguarding Customer Trust: The Value of SOC 2 Audits

Safeguarding Customer Trust: The Value of SOC 2 Audits

SOC 2

Nearly every business relies heavily on technology to store important customer information, conduct transactions, and deliver essential services.

Organizations that handle customer data, like healthcare providers and IT vendors, must establish firm control over their systems and processes to comply with industry rules and safeguard customer information.

This is where a SOC 2 audit comes in.

SOC 2 compliance audits comprehensively assess service organizations' data management and protection practices, verifying adherence to stringent security and privacy industry benchmarks. These evaluations scrutinize how sensitive information is safeguarded, providing confidence to clients and stakeholders that the organization maintains the highest levels of data integrity and protection.

Critical Components of SOC 2 Compliance Audits

Before diving into the details of SOC 2 audits, it's essential to understand the five trust services criteria evaluated during the audit process. Each of the five criteria relate to different aspects of an organization's control environment and are vital in maintaining customer trust.

Security: This criterion assesses the controls in place to protect the system from unauthorized access and protect the information stored within the system.

Availability: This criterion assesses the controls in place to ensure the system is available for operation, such as controls for incident management, disaster recovery, and business continuity.

Processing integrity: This criterion assesses the controls to ensure the system processing is complete, accurate, timely, and authorized.

Confidentiality: This criterion assesses the controls to protect confidential information from being disclosed or distributed to unauthorized parties.

Privacy: This criterion assesses the controls in place to collect, use, retain, disclose, and dispose of personal information in accordance with the organization's privacy notice.

Meeting these control standards is crucial for organizations that handle sensitive customer data. Failure to meet any of these criteria can result in a loss of customer trust, financial penalties, or even legal action. For example, in 2020 Capital One was fined $80 million for a data breach that left 106 million customers vulnerable due to inadequate security controls. This case highlights the importance of meeting the security criterion and the severe consequences of failing.

Organizations must take every necessary step to meet these criteria or risk significant consequences.

4 Critical Steps Involved in Conducting a Successful SOC 2 Audit

A SOC 2 compliance audit thoroughly examines a service provider's controls related to security, availability, processing integrity, confidentiality, and privacy.

The process consists of four steps, adhering to the auditing standards set by the American Institute of Certified Public Accountants (AICPA).

Step One: Scoping

Scoping is the initial step where the auditors identify the systems, processes, and data within the audit scope. It involves understanding the organization's business objectives, identifying critical assets, and evaluating the supporting data and systems.

Step Two: Risk Assessment

The risk assessment involves identifying and evaluating the risks associated with the audited systems and processes. The auditors assess the likelihood and impact of various threats, including cyberattacks, data breaches, and natural disasters.

Step Three: Control Testing

Control testing focuses on evaluating the design and effectiveness of the controls in place to mitigate identified risks. Auditors examine the organization's policies, procedures, and technical rules to ensure proper functioning.

Step Four: Reporting

The final step is reporting, where the auditors summarize the audit results and communicate them to stakeholders. The report includes details about the audit scope, identified risks, and the effectiveness of tested controls.

READ MORE:  Streamlining The SOC 2 Audit Process in 10 Steps

Advantages of Undergoing a SOC 2 Audit for Service Organizations

Service organizations can reap numerous benefits by undergoing a SOC 2 audit.

Here are some of the key advantages:

Demonstrating Commitment to Security, Privacy, and Compliance

A SOC 2 audit demonstrates an organization's commitment to protecting its clients' data and maintaining the highest security, privacy, and compliance standards. By aligning with the AICPA Trust Services Criteria, SOC 2 audits provide third-party validation that an organization's controls and processes meet industry best practices.

Enhancing Trust and Credibility

A SOC 2 audit helps build trust and credibility with existing and potential clients. By independently assessing their controls, service organizations showcase their dedication to protecting sensitive information and ensuring that client data is handled securely.

This can be a significant differentiator in highly competitive industries.

Strengthening Internal Controls and Risk Management

SOC 2 audits require organizations to continually assess and improve their internal controls and risk management practices. This process allows organizations to identify weaknesses, address vulnerabilities, and implement robust controls, ultimately enhancing their overall security posture and enabling better risk management.

Meeting Regulatory Requirements and Industry Standards

Many industries have specific regulatory requirements and standards for data security and privacy. SOC 2 audits help organizations demonstrate compliance with these regulations, providing a baseline of security controls that align with industry-specific needs.

For example, Healthcare technology companies, like EHR software providers, undergo SOC 2 audits to adhere to HIPAA requirements and assure stakeholders of their commitment to data privacy and security.

Gaining a Competitive Edge

SOC 2 reports can be powerful marketing tools. They illustrate an organization's specialized expertise, commitment to safeguarding data, and adherence to industry best practices. Sharing a SOC 2 report with potential clients during sales can set an organization apart from competitors and instill confidence in clients prioritizing data security and compliance.

Common Misconceptions about SOC 2 Compliance

Over the years, we've gained extensive experience helping clients achieve and maintain compliance with SOC 2 audits.

Along the way, we've encountered numerous misconceptions and myths we'd like to address.

Myth #1: SOC 2 Compliance is Too Complex to Undertake

One common misconception is that SOC 2 audits are overly complex and burdensome, making it difficult for many organizations to achieve compliance.

Fact:

While SOC 2 audits require a comprehensive evaluation of an organization's controls, they are designed to be flexible and scalable based on the organization's size, industry, and specific circumstances.

Myth #2: SOC 2 Compliance is Expensive and Cost-Prohibitive

Another myth surrounding SOC 2 audits is that they are prohibitively expensive.

Fact:

While it is true that SOC 2 compliance audits require investment, organizations should consider the long-term benefits and value derived from achieving compliance.

SOC 2 compliance can enhance an organization's reputation, attract new customers, and improve security and risk management practices.

Myth #3: SOC 2 Compliance is Only Relevant for Large Organizations

Some believe that SOC 2 compliance only applies to large organizations with extensive IT infrastructure and complex operations.

Fact:

SOC 2 compliance is relevant for organizations of all sizes. Regardless of scale, any service organization that handles client data should prioritize data security, privacy, and compliance.

The Benefits of Partnering with an Experienced Third-Party Auditor for SOC 2 Compliance

Alt Text: Image of wooden blocks to represent people. The blue person is connected with employees by a wide network of lines. At the center of a complex extensive system. Communication is social. Cooperation, collaboration. Project leadership personnel management. | Johanson Group, LLP.

Partnering with an experienced third-party auditor simplifies SOC 2 compliance. Their expert guidance ensures alignment with industry standards and increases the chances of a successful audit.

An independent assessment adds credibility, building trust with stakeholders. Additionally, they offer cost-effective solutions and proactive risk mitigation, protecting your organization's reputation and data integrity.

Check out these resources to help you get started on your SOC 2 audit:

In Summary

In this blog post, we have debunked common misconceptions about SOC 2 audits and provided accurate information to help businesses make informed decisions regarding risk management and compliance strategies.

Let's recap the key points covered:

  1. SOC 2 audits are not too complex to undertake. With the proper guidance and support from expert risk advisory experts, organizations of all sizes can successfully navigate the audit process.
  2. While SOC 2 audits require investment, they are not prohibitively expensive. The long-term benefits of achieving compliance, such as enhancing reputation, attracting new customers, and improving security practices, outweigh the associated costs.
  3. SOC 2 audits are not only relevant for large organizations. Any service organization that handles client data should prioritize SOC 2 compliance, regardless of its size. Demonstrating a commitment to protect client information can help organizations gain a competitive edge in their industry.

It is vital to emphasize the importance of SOC 2 audits in building trust and safeguarding sensitive data. By undergoing a SOC 2 audit, businesses showcase their dedication to security, privacy, and compliance, instilling confidence in clients and fostering trust.

Partner with the Johanson Group for Expert Guidance and Support:

At Johanson Group, we understand the significance of compliance, risk management, and data protection.

Our team of experts can provide the guidance and support needed to navigate the complexities of SOC 2 compliance audits.

Book a meeting with our sales team to discuss how a SOC 2 audit can help your organization

Jul 28, 2023

Streamlining The SOC 2 Audit Process in 10 Steps

Streamlining The SOC 2 Audit Process in 10 Steps

SOC 2
Checklist

When clients approach audit firms regarding the SOC 2 Attestation process, they often find it daunting and overwhelming. SOC 2 audit firms should strive to simplify the process and instill confidence in their clients. Unfortunately, clients are often uninformed about the complexities of the SOC 2 auditing process.

At Johanson Group, LLC, we do things differently.

We believe in collaborating with our clients rather than excluding them. We ensure that our clients comprehend every step of the procedure, know their current position, and know the subsequent step to guarantee an effortless process and audit.

To provide clarity and simplicity, we have outlined the step-by-step process that our clients follow with Johanson Group.

Step 1: Sales Call

Meet with a sales team member to see if Johanson Group's services, approach, and price fit your needs. You can book a meeting with them here.

Step 2: Partner with Johanson Group by signing a Statement of Work

Once your organization has decided to move forward with Johanson Group, the next step in the SOC 2 audit process is the Statement of Work (SOW). We will send the SOW. Once signed, we are ready to start the process of your SOC 2 compliance audit. If your organization would like a letter of engagement to share with your customers, we would happily provide one.

Step 3: Kick-off call  

The next step in your SOC 2 audit process is the kick-off call. A member of our customer success team will reach out to you to arrange a kick-off meeting where we can delve into the audit process in greater depth.

During this meeting, they will be more than happy to address any questions or concerns you might have and establish a cadence for follow-up communications.

Step 4: Prepare your organization for the SOC 2 compliance audit internally

In this phase of the SOC 2 audit process, you will be working on configuring the platforms you use for data security or other information systems software.

Your main tasks in this step involve:

  • Integrating these systems
  • Creating policies
  • Identifying and implementing controls to ensure data security

If you have any questions or need assistance during this process, don't hesitate to contact your Customer Success Manager (CSM).

After setting everything up, your primary focus should be ensuring that your organization adheres to the established policies and controls to achieve compliance. Please let your CSM know when you want to start the audit. Setting up your controls can take anywhere from 14 days to 3-4 months; ultimately, it's at your own pace, but our team is always on hand to support you in your SOC 2 goals and journey.

Step 5: The SOC 2 Audit Process Begins

After finishing all the setup and putting the controls in place, your organization will start the audit period. During this time, you must monitor the controls to ensure they are within the time limits your organization has set (called SLAs). f you are using a readiness platform, we recommend logging in to your platform every day to check for any new issues that might arise.

The shortest audit period for a SOC 2 Type II is three (3) months, while the subsequent audit periods afterwards usually last twelve (12) months.

READ MORE: SOC 2 Frequency: What You Should Know

Step 6: Audit period ends/ audit work begins

Once the audit period is over, Johanson Group will begin our audit procedures. Our team will access the platform or provide evidence and promptly download all policies and evidence required. We will check if controls are working well and then review them to ensure they worked well throughout the audit.

Step 6 is mandatory and typically takes approximately 2-3 weeks.

Step 7: Follow-up

After our review process, we may contact you with follow-up questions or requests for additional evidence.

Receiving a notification like this doesn't necessarily indicate failure on your part; perhaps certain items need to be correctly uploaded onto the platform or provided to the audit team.

You can upload the evidence again on the platform or send it directly to us if necessary.

Usually, this process takes less than a week, but the exact timeframe may be affected by how quickly you respond.

Step 8: Our team will draft your SOC 2 audit report

Once you have answered all questions and Johanson Group has reviewed the additional evidence, we will send you a draft report for your review. You must thoroughly read the report to verify that all dates and trust service categories are accurate and there are no surprises.

Drafting the report usually takes 1-2 days. Your review of the draft report occurs at your own pace.

Step 9: Sign the Management Assertion and Representation Letters

In this step of the SOC 2 audit process, once you have approved the draft, we will send over the Management Assertion and Representation letters for signature via DocuSign. These documents confirm that the management effectively designed and implemented controls that continued to operate efficiently during the audit period.

Step 10: You will receive the Final SOC 2 Audit report

Once the management assertion and representation letters are signed, Johanson Group will do one final review before sending over the report. This process usually takes 3-5 days.

Johanson Group’s Transparent SOC 2 Audit Process

Navigating the SOC 2 audit process can be daunting for many organizations, often needing more communication from audit firms to make sure they are going in the right direction.  At Johanson Group, we are committed to changing this narrative and empowering our clients to understand each step along their SOC 2 journey clearly.

From the initial sales call to the final report, we prioritize transparency and seamless communication to ensure a smooth and successful audit. Our dedicated customer success team will guide you through the setup phase, ensuring your policies and controls are in place and making sure you are in a good position prior to starting the audit period.

Throughout the audit period, we will support you, ensuring timely resolution of any questions that may arise. From start to finish, our process is designed to help produce a report that aligns with your expectations and validates all your hard work and security posture.

With Johanson Group, you can confidently provide Management Assertion and Representation letters, affirming the suitability and effectiveness of your controls throughout the audit period. Finally, you can confidently share your SOC 2 report with current and prospective clients to let them know of your dedication to keeping you and their data secure.

Make your SOC 2 journey a seamless one with Johanson Group by your side. Let's get started on securing your business today!

No results found.
No results found for your search query
The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe
Essential Knowledge: SOC 2 Compliance Requirements
What is a SOC 2 Attestation?
Your Pre-Audit Checklist for SOC 2 Compliance
The Benefits of SOC 2 Compliance
SOC 2 Controls: What they are and how they help you stay compliant
The History of SOC 2 Compliance
IT Audit Checks: What You Need To Know
An Overview of a HIPAA Attestation of Compliance
SOC 2 vs. ISO 27001: Which to Choose
7 Things To Look For In A SOC 2 Auditor
SOC 2 Frequency: What You Should Know
Why SOC 2 Auditing Is Essential for SaaS Businesses
Why You Need a Cybersecurity Risk Management Policy, How to Write One—and Who Can Help
Choosing the Right Compliance Framework for Your Business: NIST vs ISO
Exploring the Five Trust Service Principles of SOC 2 Compliance
3 Essential Steps for Choosing the Right SOC 2 Risk Advisory Professional for Your Compliance Needs
How to Choose the Right ISO 27001 Penetration Testing Company
ISO Asset Management and Cybersecurity: Protecting Your Assets in the Digital Age
Understanding SOC 1 vs. SOC 2 Reports: Choosing the Right Compliance Framework for Your Organization
A Comprehensive Guide to ISO 27001 Annex A Controls for Information Security Management
HIPAA vs. HITRUST: What You Need to Know
Safeguarding Customer Trust: The Value of SOC 2 Audits
Streamlining The SOC 2 Audit Process in 10 Steps
How To Read A SOC 2 Report
HIPAA Compliance Made Simple: Your HIPAA Security Rule Checklist
Understanding HIPAA Compliance Reports: A Comprehensive Guide
The Importance of ISO 27001 Certification for SaaS Providers
What is a ISO 27001 Surveillance Audit?
SOC 2 and HIPAA Compliance: Similarities and Differences
Information Security Audits: An Overview of Different Types
Developing a Robust Patch Management Policy for SOC 2 Audits
The Role of a CPA Firm in ISO 27001 Compliance Audits
SaaS Infrastructure: Best Practices for ISO 27001 Compliance
What is ISO 27001? A Comprehensive Guide to Compliance
Unlocking Growth: The Value of SOC 2 Compliance for Startups
ISO 27001 Audits: Understanding Stage 1 vs. Stage 2
The 5 Benefits of SOC 2 Reporting for Your Organization
HIPAA Compliance in 7 Steps: Your Ultimate Guide
ISO 27001 for Small Businesses
SOC for Cybersecurity vs. SOC 2: What’s the Difference?
Who Needs ISO 27001 Certification?
SOC 2 Compliance: 5 Common Questions
ISO 27001 vs ISO 27002: What’s the Difference?
The Ultimate Guide to GDPR
What is NIST 800-53?
CCPA vs GDPR: Navigating Privacy Regulations
ISO 27017 vs ISO 27018: Which Is Right for Your Business?
Understanding SOC 2 Trust Service Criteria
7 Common Myths About SOC 2: Debunking Misconceptions
Understanding CCPA Compliance
The Importance of Regular Security Audits for Your Organization
Common Misconceptions About Security Audits
ISO 27001 vs ISO 42001: A Comprehensive Comparison
Self-Attestation or Use an Auditor: What’s Best for Compliance?
Choosing the Right QSA for Your Business: A Practical Guide
Understanding Compliance vs. Security
What Is Required for a Successful SOC 2 Risk Assessment?
Common Cybersecurity Audit Pitfalls and How to Avoid Them
Unpacking Your SOC Audit Opinion: What Your Report Truly Means
What is NIST 800-171?
What is SOC 3? Everything You Need to Know
The Cost of PCI Non-Compliance: Fines, Breaches, and Reputational Damage
Compliance for Seed-Stage Startups: When Should You Start Thinking About SOC 2?
Understanding the Differences: SOC 1 Type 1 vs. Type 2
Why We Partnered with Rippling - and What It Means for Your SOC 2 Audit
PCI Compliance Guide
Determining the Scope Statement
SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
What is a SOC 2 Bridge Letter?
Your Guide to SOC 2 Attestation Reports
What is SOC 2 Penetration Testing and Why You Need One
Key Differences Between ISO 27001 and 27002
How Your Customer Success Manager fits into your journey to SOC 2 compliance
What is the difference between SOC 2 Type 1 and SOC 2 Type 2