Streamlining The SOC 2 Audit Process in 10 Steps

We believe in collaborating with our clients rather than excluding them. We ensure that our clients comprehend every step of the procedure, know their current position, and know the subsequent step to guarantee an effortless process and audit.
When clients approach audit firms regarding the SOC 2 Attestation process, they often find it daunting and overwhelming. SOC 2 audit firms should strive to simplify the process and instill confidence in their clients. Unfortunately, clients are often uninformed about the complexities of the SOC 2 auditing process.
At Johanson Group, LLC, we do things differently.
We believe in collaborating with our clients rather than excluding them. We ensure that our clients comprehend every step of the procedure, know their current position, and know the subsequent step to guarantee an effortless process and audit.
To provide clarity and simplicity, we have outlined the step-by-step process that our clients follow with Johanson Group.
Step 1: Sales Call

Meet with a sales team member to see if Johanson Group's services, approach, and price fit your needs. You can book a meeting with them here.
Step 2: Partner with Johanson Group by signing a Statement of Work

Once your organization has decided to move forward with Johanson Group, the next step in the SOC 2 audit process is the Statement of Work (SOW). We will send the SOW. Once signed, we are ready to start the process of your SOC 2 compliance audit. If your organization would like a letter of engagement to share with your customers, we would happily provide one.
Step 3: Kick-off call

The next step in your SOC 2 audit process is the kick-off call. A member of our customer success team will reach out to you to arrange a kick-off meeting where we can delve into the audit process in greater depth.
During this meeting, they will be more than happy to address any questions or concerns you might have and establish a cadence for follow-up communications.
Step 4: Prepare your organization for the SOC 2 compliance audit internally

In this phase of the SOC 2 audit process, you will be working on configuring the platforms you use for data security or other information systems software.
Your main tasks in this step involve:
- Integrating these systems
- Creating policies
- Identifying and implementing controls to ensure data security
If you have any questions or need assistance during this process, don't hesitate to contact your Customer Success Manager (CSM).
After setting everything up, your primary focus should be ensuring that your organization adheres to the established policies and controls to achieve compliance. Please let your CSM know when you want to start the audit. Setting up your controls can take anywhere from 14 days to 3-4 months; ultimately, it's at your own pace, but our team is always on hand to support you in your SOC 2 goals and journey.
Step 5: The SOC 2 Audit Process Begins

After finishing all the setup and putting the controls in place, your organization will start the audit period. During this time, you must monitor the controls to ensure they are within the time limits your organization has set (called SLAs). f you are using a readiness platform, we recommend logging in to your platform every day to check for any new issues that might arise.
The shortest audit period for a SOC 2 Type II is three (3) months, while the subsequent audit periods afterwards usually last twelve (12) months.
READ MORE: SOC 2 Frequency: What You Should Know
Step 6: Audit period ends/ audit work begins

Once the audit period is over, Johanson Group will begin our audit procedures. Our team will access the platform or provide evidence and promptly download all policies and evidence required. We will check if controls are working well and then review them to ensure they worked well throughout the audit.
Step 6 is mandatory and typically takes approximately 2-3 weeks.
Step 7: Follow-up

After our review process, we may contact you with follow-up questions or requests for additional evidence.
Receiving a notification like this doesn't necessarily indicate failure on your part; perhaps certain items need to be correctly uploaded onto the platform or provided to the audit team.
You can upload the evidence again on the platform or send it directly to us if necessary.
Usually, this process takes less than a week, but the exact timeframe may be affected by how quickly you respond.
Step 8: Our team will draft your SOC 2 audit report

Once you have answered all questions and Johanson Group has reviewed the additional evidence, we will send you a draft report for your review. You must thoroughly read the report to verify that all dates and trust service categories are accurate and there are no surprises.
Drafting the report usually takes 1-2 days. Your review of the draft report occurs at your own pace.
Step 9: Sign the Management Assertion and Representation Letters

In this step of the SOC 2 audit process, once you have approved the draft, we will send over the Management Assertion and Representation letters for signature via DocuSign. These documents confirm that the management effectively designed and implemented controls that continued to operate efficiently during the audit period.
Step 10: You will receive the Final SOC 2 Audit report

Once the management assertion and representation letters are signed, Johanson Group will do one final review before sending over the report. This process usually takes 3-5 days.
Johanson Group’s Transparent SOC 2 Audit Process
Navigating the SOC 2 audit process can be daunting for many organizations, often needing more communication from audit firms to make sure they are going in the right direction. At Johanson Group, we are committed to changing this narrative and empowering our clients to understand each step along their SOC 2 journey clearly.
From the initial sales call to the final report, we prioritize transparency and seamless communication to ensure a smooth and successful audit. Our dedicated customer success team will guide you through the setup phase, ensuring your policies and controls are in place and making sure you are in a good position prior to starting the audit period.
Throughout the audit period, we will support you, ensuring timely resolution of any questions that may arise. From start to finish, our process is designed to help produce a report that aligns with your expectations and validates all your hard work and security posture.
With Johanson Group, you can confidently provide Management Assertion and Representation letters, affirming the suitability and effectiveness of your controls throughout the audit period. Finally, you can confidently share your SOC 2 report with current and prospective clients to let them know of your dedication to keeping you and their data secure.
Make your SOC 2 journey a seamless one with Johanson Group by your side. Let's get started on securing your business today!
Related articles

SOC for Cybersecurity vs. SOC 2: What’s the Difference?
SOC for Cybersecurity vs. SOC 2: What’s the Difference?
Cybersecurity breaches are an ever-present threat to organizations of all sizes. A Clark School study at the University of Maryland is one of the first to quantify the near-constant rate of hacker attacks of computers with Internet access— every 39 seconds on average, affecting one in three Americans every year.
In response to this growing concern, the American Institute of Certified Public Accountants (AICPA) has developed SOC (Service Organization Control) reports to assist organizations in achieving compliance and securing sensitive data. Two common types of SOC reports are SOC 1 and SOC 2, each serving distinct purposes within the realm of cybersecurity and compliance.
The Relationship Between SOC for Cybersecurity and SOC 2
While both SOC for Cybersecurity and SOC 2 are geared towards enhancing cybersecurity practices within organizations, they serve different purposes and cater to different audiences. SOC for Cybersecurity focuses specifically on an organization's cybersecurity risk management program, providing stakeholders with assurance regarding the effectiveness of these measures.
On the other hand, SOC 2 evaluates the design and effectiveness of controls relevant to security, availability, processing integrity, confidentiality, and privacy, with a broader scope encompassing overall service delivery.
READ MORE: The 5 Benefits of SOC 2 Reporting for Your Organization
Differences Between SOC for Cybersecurity and SOC 2
Scope: SOC for Cybersecurity assesses an organization's cybersecurity risk management program, including policies, procedures, and controls related to cybersecurity. SOC 2, however, evaluates controls relevant to security, availability, processing integrity, confidentiality, and privacy, with a focus on service delivery.
Control Criteria: SOC for Cybersecurity primarily follows the AICPA's cybersecurity risk management reporting framework, while SOC 2 adheres to predefined criteria based on the Trust Services Criteria (TSC) established by the AICPA.
Audience: SOC for Cybersecurity reports are intended for a broader range of stakeholders, including boards of directors, investors, and business partners, seeking assurance on an organization's cybersecurity posture. SOC 2 reports, on the other hand, are typically requested by customers and stakeholders concerned with data security and privacy in outsourced services.
Third-Party Risks: SOC for Cybersecurity evaluates an organization's ability to manage cybersecurity risks internally, whereas SOC 2 assesses the controls implemented by service organizations to mitigate risks associated with outsourced services.
Sensitive Information: SOC for Cybersecurity focuses on protecting sensitive information related to cybersecurity risks and threats, while SOC 2 evaluates controls related to the security, availability, processing integrity, confidentiality, and privacy of data processed by service organizations.
Check out these resources to help you get started on your SOC 2 audit:
- How to choose your risk advisory specialist for SOC 2 audits
- Your pre-audit checklist for SOC 2 audits and compliance
- SOC 2 compliance with your Customer Success Manager (CSM)
Improve Your Controls with Johanson Group
As organizations strive to enhance their cybersecurity posture and achieve compliance with industry standards, partnering with a trusted advisor like Johanson Group can provide invaluable support. With expertise in SOC attestation and cybersecurity risk management, Johanson Group offers comprehensive solutions tailored to your organization's specific needs. From conducting readiness assessments to implementing robust controls, Johanson Group is committed to helping you achieve SOC 2 attestation and bolster your cybersecurity defenses.
While SOC for Cybersecurity and SOC 2 both aim to strengthen cybersecurity practices within organizations, they serve distinct purposes and cater to different stakeholders. Understanding the differences between these two frameworks is essential for organizations seeking to enhance their cybersecurity posture and achieve compliance with industry standards. Partnering with a reputable firm like Johanson Group can streamline the attestation process and provide assurance to stakeholders regarding the effectiveness of your cybersecurity controls.

SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
SOC 1, SOC 2, SOC 3 — same family, very different reports. Here's how to know which one your customers are actually asking for.
The short version
All three reports are issued under the AICPA's System and Organization Controls framework. Where they differ is what they evaluate and who they're written for.
- SOC 1 — Controls relevant to your customers' financial reporting. Restricted-use report.
- SOC 2 — Controls relevant to security, availability, processing integrity, confidentiality, and privacy. Restricted-use report.
- SOC 3 — A public-facing summary of your SOC 2. General-use report.
If your customers care about how you handle their data, you're looking at SOC 2 (and possibly SOC 3). If they care about how you affect their financial statements, you're looking at SOC 1.
SOC 1: built for financial reporting
A SOC 1 report exists for one reason: to give your customer's auditors the comfort they need when your services impact your customer's financial statements.
Classic examples of who needs SOC 1:
- Payroll processors
- Loan servicing platforms
- Medical claims processing
- Fund administrators
- SaaS platforms that handle billing, revenue recognition, or accounting workflows on behalf of customers
The controls in scope are the ones that, if they failed, could cause a misstatement in your customer's books. Think: change management for billing logic, access controls around financial data, completeness and accuracy of transaction processing.
SOC 1 reports come in two flavors:
- Type 1 — Design of controls at a point in time.
- Type 2 — Design and operating effectiveness over a period (usually 6–12 months).
SOC 1 is a restricted-use report. It's written for your customers and their auditors — not for marketing.
SOC 2: the one most SaaS companies need
SOC 2 is the report procurement teams ask for when they're evaluating a vendor that touches their data. It evaluates your controls against the AICPA's Trust Services Criteria:
- Security (required in every SOC 2)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
Most SaaS companies start with Security only and add Availability or Confidentiality based on customer pressure or contractual commitments.
Like SOC 1, SOC 2 has a Type 1 and a Type 2 version. Type 1 covers a point in time; Type 2 covers a period — typically a minimum of three months for a first audit, then twelve months going forward. Most enterprise customers will eventually want a Type 2.
SOC 2 is also a restricted-use report. You can share it with prospects under NDA — and you absolutely should — but you can't post it on your website.
Which is exactly the gap SOC 3 fills.
SOC 3: the public version of SOC 2
SOC 3 is essentially a marketing-friendly version of your SOC 2. It uses the same Trust Services Criteria and is based on the same audit work, but it strips out the detailed control descriptions and test results. What's left is a high-level attestation you can publish on your website, hand out at trade shows, or include in sales decks without an NDA.
A few things worth knowing:
- You can only get a SOC 3 if a SOC 2 Type 2 has been (or is being) performed. SOC 3 isn't a standalone audit — it's a derivative report.
- SOC 3 is general-use. Anyone can read it.
- SOC 3 doesn't replace SOC 2. Enterprise procurement teams still want the full SOC 2 Type 2.
Think of SOC 3 as the trust badge on the homepage and SOC 2 as the document you send when a security questionnaire lands in your inbox.
Side-by-side comparison
How to choose
The decision usually comes down to three questions:
1. What do your customers' contracts and security questionnaires actually ask for?
Ninety percent of the time, this answers it for you. Read the requests instead of guessing.
2. Does your service affect your customers' financial statements?
If yes — payroll, billing, accounting, claims, fund services — you likely need SOC 1. If your customers' auditors are calling you, that's a strong signal.
3. Do your customers care about how you handle their data?
If yes, you need SOC 2. This covers most SaaS, hosting, managed services, and infrastructure providers.
Some companies need both SOC 1 and SOC 2 — for example, a billing SaaS that processes financial transactions and stores sensitive customer data. That's not unusual, just more work.
SOC 3 is rarely a starting point. It's something you add once your SOC 2 Type 2 is in place and marketing wants something they can publish.
What about ISO 27001, HIPAA, or PCI?
These often come up in the same conversation, but they're separate frameworks with their own audits and certifications. SOC reports don't replace them and they don't replace SOC reports. If you're juggling multiple frameworks, a good auditor can help you map overlapping controls so you're not doing the same work three times.
Bottom line
SOC 1 is for financial reporting. SOC 2 is for everything else customers worry about — security, uptime, data handling. SOC 3 is the public-facing version of SOC 2 you can share without an NDA.
The cleanest path for most SaaS companies: start with SOC 2 Type 1 to validate your control design, move into a SOC 2 Type 2 audit period, and add SOC 3 once you want a public-facing trust signal. If you process financial transactions on behalf of customers, layer in SOC 1.
Not sure which path fits your business? That's the kind of conversation a 30-minute call with a specialized auditor can resolve faster than another week of internal debate.

Understanding SOC 1 vs. SOC 2 Reports: Choosing the Right Compliance Framework for Your Organization
Understanding SOC 1 vs. SOC 2 Reports: Choosing the Right Compliance Framework for Your Organization
In today's interconnected business landscape, organizations must demonstrate their ability to safeguard sensitive information and ensure the reliability of their internal systems.
Two prominent compliance frameworks, SOC 1 and SOC 2, are vital in validating control effectiveness and providing assurance to stakeholders.
This article will clarify the differences between SOC 1 and SOC 2 reports and guide organizations in determining which report best aligns with their needs.

SOC 1: An Overview
A SOC 1 (System and Organization Controls 1) report is a type of audit report that evaluates the internal controls of a service organization. These reports are conducted in accordance with the Statement on Standards for Attestation Engagements (SSAE) No. 18, which is issued by the American Institute of Certified Public Accountants (AICPA).
The purpose of a SOC 1 report is to offer confidence to users that the service organization has effective internal controls to ensure the accuracy and completeness of their financial reporting. The service organization’s clients typically request SOC 1 reports, as they want to ensure that their financial information is accurate and secure.
Who Does a SOC 1 Report Serve?
The primary audience for a SOC 1 report is the service organization’s clients. These clients may include financial institutions, insurance companies, or any other organization that relies on the service organization for financial reporting.
In addition to clients, other stakeholders may also be interested in a service organization’s SOC 1 report. These stakeholders may include regulators, auditors, or potential investors.
Types of SOC 1 Reports
While there are many differences between SOC 1 and SOC 2, both have two types of audit: Type I and Type II.
A SOC 1 Type I report evaluates the design of the service organization’s internal controls as of a specific date. This report validates that the controls are suitably designed to achieve the intended control objectives.
A SOC 1 Type II report evaluates the design and operating effectiveness of the service organization’s internal controls over a period of time (usually six months to a year). This report assures that the controls are designed and operate effectively to achieve the intended control objectives.
SOC 2 Reports: An Overview
A SOC 2 (System and Organization Controls 2) report is a type of audit report that evaluates the internal controls of a service organization related to security, availability, processing integrity, confidentiality, and privacy. These reports are conducted in accordance with the Trust Services Criteria (TSC), which is issued by the American Institute of Certified Public Accountants (AICPA).
The purpose of a SOC 2 report is to assure users that the service organization has adequate internal controls in place to ensure the security, availability, processing integrity, confidentiality, and privacy of their data. The service organization’s clients typically request SOC 2 reports, as they want to ensure that their data is secure and protected.
READ MORE: The History of SOC 2 Compliance
Who Does a SOC 2 Report Serve?
One of the main differences between SOC 1 and SOC 2 is the primary audience. SOC 2 reports are for the service organization’s clients. These clients may include technology companies, healthcare organizations, or any other organization that relies on the service organization for data processing or storage.
In addition to clients, other stakeholders may also be interested in a service organization’s SOC 2 report.
Types of SOC 2 Reports
Two types of SOC 2 reports are Type I and Type II.
- SOC 2 Type I
This report evaluates the design of the service organization’s internal controls at a point in time. It assures that those controls are suitably designed to achieve TSC.
- SOC 2, Type II
This report evaluates the design and operating effectiveness of the service organization’s internal controls over a period of time (usually six months to a year). It assures that the controls are suitably designed and operating effectively to achieve the intended control objectives related to TSC.
READ MORE: SOC 2 Frequency: What You Should Know
3 Main Differences Between SOC 1 and SOC 2 Reports
When evaluating a service organization's internal controls, SOC 1 and SOC 2 are two of the most common audit reports.
While both reports serve the purpose of assuring clients and stakeholders, SOC 1 and SOC 2 reports have several key differences.
- Reporting standards
- Scope of the audit
- The nature of the controls being evaluated
By understanding these differences, organizations can choose the appropriate report based on their specific needs and ensure that their clients and stakeholders have the necessary level of assurance.
1. Reporting Standards for SOC 1 and SOC 2
- SOC 1 reports adhere to the rigorous SSAE 18 standards to maintain consistency and quality. These standards provide a framework for evaluating internal controls over financial reporting and require an auditor's attestation.
- SOC 2 reports, however, follow the Trust Services Criteria, consisting of five categories encompassing a broader range of control objectives. These criteria address risks and guide for assessing controls relevant to non-financial reporting areas.
2. Scopes of SOC 1 and SOC 2 Audits
- The scope of SOC 1 audits centers around the controls related to financial reporting processes. This includes evaluating controls such as revenue recognition, financial statement preparation, and billing.
- SOC 2 audits have a broader scope covering data protection controls, system availability, logical access, change management, etc. SOC 2 reports provide valuable insights into an organization's ability to secure its systems and protect customer data.
3. The nature of the controls being evaluated
One of the biggest differences between SOC 1 and SOC 2 is the controls necessary for a successful audit. Both are essential for clients and stakeholders of service organizations.
In a SOC 1 report, the controls being evaluated are related to the financial reporting of the service organization. The report assesses the effectiveness of the controls in place to ensure the accuracy and reliability of the financial statements of the service organization. This is important for clients of the service organization that rely on their financial statements for their financial reporting and decision-making.
On the other hand, a SOC 2 report evaluates the controls related to TSC criteria to ensure that the service organization's systems are secure, available, and processing data with integrity and confidentiality.
Determining Your Requirements: SOC 1, SOC 2, or Both?
Determining which report you need, SOC 1 or SOC 2, depends on the nature of your business and the services you provide.

If your organization offers services directly related to financial reporting, such as payroll processing or accounting services, then a SOC 1 report is likely the appropriate choice. This report assures clients that the internal controls related to financial reporting are effective and reliable.
On the other hand, if your organization provides services that are not directly related to financial reporting but involve handling sensitive data, such as healthcare or technology services, then a SOC 2 report is likely the appropriate choice. This report assures clients that the internal controls related to their data's security, availability, processing integrity, confidentiality, and privacy are effective and reliable.
It's important to note that determining which report is needed is ultimately up to the client or stakeholder requesting the information. They will need to evaluate the nature of the services provided by the service organization and determine which report will provide the necessary level of assurance.
In some cases, clients may request both SOC 1 and SOC 2 reports to ensure they have a comprehensive understanding of the internal controls. This may be particularly relevant for service organizations that provide both financial reporting and non-financial services.
Examples of organizations that may need a SOC 2 report:
- Cloud service providers:
Organizations that offer cloud computing services, including infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), or software-as-a-service (SaaS) models, often require a SOC 2 report. This report assures clients that appropriate security controls are in place to protect their data.
- Data centers:
Companies operating or providing colocation services may need a SOC 2 report. It demonstrates that they have implemented adequate security, availability, processing integrity, confidentiality, and privacy controls.
- Software-as-a-service (SaaS) providers:
SaaS companies that handle sensitive customer data, such as personal information or financial records, can benefit from obtaining a SOC 2 report. It verifies that its information security controls meet industry standards and customer expectations.
READ MORE: Why SOC 2 Auditing is Essential for SaaS Businesses
Examples of organizations that may need a SOC 1 report:
- Third-party service providers:
Companies that offer payroll processing, HR administration, or financial transaction processing for other organizations might require a SOC 1 report. This report assesses the effectiveness of their internal controls over financial reporting, which is crucial for their client's financial audits.
- Pension plan administrators:
Organizations responsible for managing pension plans may need a SOC 1 report. This report demonstrates that they have appropriate controls to ensure the accuracy, completeness, and confidentiality of financial information related to pension plans.
- Trust companies:
Financial institutions, such as trust companies, that manage assets on behalf of clients might require a SOC 1 report. It assures its clients that internal controls are in place to protect the assets and maintain accurate financial records.
Examples of organizations that may need both SOC 2 and SOC 1 reports:
- Data center and managed services provider:
Companies that offer data center and managed services, such as IT infrastructure management or network security, may require both SOC 2 and SOC 1 reports. The SOC 2 report covers the security controls for their services, while the SOC 1 report assesses their controls related to financial reporting.
- Cloud-based financial software provider:
Organizations that offer cloud-based financial software, which handles financial transactions and customer data, may need SOC 2 and SOC 1 reports. The SOC 2 report ensures the security and privacy of customer data, while the SOC 1 report addresses the controls over financial reporting within the software.
- Outsourced payroll and HR services provider:
Companies that offer outsourced payroll and HR services, including handling financial transactions and managing sensitive employee data, might require both SOC 2 and SOC 1 reports. The SOC 2 report verifies the security and privacy controls for customer data, while the SOC 1 report assesses controls related to financial reporting for payroll processing.
Who Should You Hire When Considering a SOC 1 or SOC 2 Audit and Report?
When seeking SOC 1 and SOC 2 assessments, audits, reports, and certification, partnering with a reputable third-party CPA firm is crucial. These firms possess the necessary expertise and experience to conduct thorough evaluations of a service organization's internal controls, assuring clients and stakeholders.
Why Third-Party CPA Firms for SOC 1 and SOC 2 Assessments and Certification Are Crucial for Compliance
Due to the differences between SOC 1 and SOC 2, engaging a qualified third-party CPA firm is essential for assessments, audits, reports, and certification.
These firms specialize in auditing services for businesses of all sizes, bringing integrity, efficiency, and flexibility to their auditing processes. They help clients demonstrate compliance with governance, risk management, and compliance (GRC) requirements.
The professionals in these firms have extensive experience in the GRC field and are committed to delivering a seamless engagement experience. Each client is assigned a dedicated auditor and a Customer Success team to ensure personalized and prompt service.
Clients can expect to receive their final report within 4 to 6 weeks from the start of the audit. These reports address the controls pertinent to the security, availability, and processing integrity of user systems. Additionally, they align with an organization's regulatory compliance needs, such as HIPAA Security and Breach Notification Rules.
These firms also offer readiness assessments for organizations seeking certification to the ISO/IEC 27001 standard.
By collaborating with a qualified third-party CPA firm, service organizations can fulfill internal control requirements and provide the necessary assurance to clients and stakeholders.
Understanding the differences between SOC 1 and SOC 2 reports is crucial for organizations seeking to establish control over their internal systems and processes. While SOC 1 reports attest to financial controls, SOC 2 reports address a wider range of control objectives, including security, availability, processing integrity, confidentiality, and privacy.
By selecting the appropriate compliance framework, businesses can meet the specific reporting requirements of their industry and provide confidence to clients, partners, and regulators.
It is important for organizations to engage with a qualified risk advisory professional CPA firm to determine the most suitable report for their needs.
By partnering with risk assessment and compliance experts, businesses can navigate the complexities of SOC reporting and develop a comprehensive strategy to demonstrate control effectiveness and instill trust in their operations.




