TL;DR
SOC (Service Organization Control) reports are independent audits conducted by certified public accountants (CPAs) to verify that an organization properly protects the data it handles for customers. Governed by the American Institute of Certified Public Accountants (AICPA), these reports come in several types — SOC 1 for financial data, SOC 2 for broader security criteria, and SOC 3 for a publicly shareable seal of approval. Organizations in finance, healthcare, loan processing, and SaaS are among those most likely to require one. The audit process involves a readiness assessment, selecting a qualified CPA partner, and acting on the findings to close security gaps.
What is a SOC report?
A Service Organization Control (SOC) report is performed by a certified public accountant (CPA) qualified by the American Institute of Certified Public Accountants (AICPA).
An audit starts the process, and while no one likes to think about having an outsider riffle through sensitive items, the benefits are clear. If you deal with sensitive information and you want to prove that you're qualified, SOC reports could help.
What are the different types of SOC reports?
The AICPA developed SOC report frameworks. The organization continues to add audit options based on client need. Multiple types exist.
So-called "service organizations" that handle some type of data for customers have three SOC reports available:
| Report Type | Focus Area | Key Details | Shareable? |
|---|---|---|---|
| SOC 1 | Financial data | Outline how you protect and safeguard information regarding finances, and see if an auditor agrees that your plans are sufficient. | No |
| SOC 2 | Broader security criteria | Prove that you meet some or all of five identified criteria. They include privacy, confidentiality, processing integrity, availability, and security. | No |
| SOC 3 | Public seal of approval | Move through much of the same audits as you do for a SOC 2, but obtain a report that's less technical and includes a seal of approval. You can share this report in a public space, such as a website. | Yes |
What about cybersecurity and supply chain SOC reports?
You may also tap into cybersecurity SOC reports. You'll detail how you take a proactive approach to risk management. And the auditor could help you spot gaps in your plan that leave you vulnerable.
Manufacturing groups may also use SOC supply chain reports. Here, auditors look over your systems and controls to understand the risks within your supply chains.
How does the SOC audit process work?
To begin, you must choose the report that is right for your organization. Remember that this isn't an either/or endeavor. If your company works with both financial data and other information, you could need more than one report.
When you've chosen the report you need, you will:
- Create a SOC Readiness Assessment. You'll prepare for your audit by examining your gaps and deficiencies.
- Find a partner. You will need a CPA to do the work for you.
- Be open and honest. You'll need to provide your team with full access to do the work. Don't hide anything.
- Read the report. You'll get the information from your CPA filled with data. You may have items on your to-do list to fix after reading the report.
Should you get a SOC report?
Any company hoping to spot security gaps could benefit from a SOC report. But some organizations are required to do them.
Which industries typically require a SOC report?
You could need a SOC report if you work in:
- Finance
- Medical claims
- Loan processing
- Software as a Service (SaaS)
If you handle data for customers, no matter the type, you could also benefit from a SOC report. It's the only way to assure your new clients that you take security seriously.
At Okta, we specialize in helping organizations just like yours keep information safe and secure. Contact us to find out how we can help.
Frequently asked questions
What is a SOC report and who conducts it?
A SOC report gives customers independent, third-party assurance that the organizations handling their data have the controls in place to protect it. These audits are conducted by certified public accountants (CPAs) who are qualified by the American Institute of Certified Public Accountants (AICPA), making the findings credible and verifiable.
What is the difference between SOC 1, SOC 2, and SOC 3?
SOC 1 focuses exclusively on financial data controls. SOC 2 evaluates an organization against up to five criteria: security, availability, processing integrity, confidentiality, and privacy. SOC 3 covers similar ground as SOC 2 but produces a less technical report that includes a seal of approval suitable for public sharing, such as on a company website.
Does my organization need more than one SOC report?
Yes, it is possible. If your organization handles both financial data and other types of customer information, you may need to obtain multiple SOC reports simultaneously. The choice of report depends on the nature of the data you manage.
What does the SOC audit process involve?
The SOC audit process is designed to surface gaps before they become liabilities. It begins with a Readiness Assessment to identify weaknesses, followed by engaging a qualified CPA who is given full access to your systems. The resulting report not only confirms your current controls but also provides a remediation roadmap for any areas that need improvement.
Are there SOC reports for cybersecurity and supply chain risks?
Yes. Cybersecurity SOC reports allow organizations to document their proactive approach to risk management and can help identify vulnerabilities. Supply chain SOC reports are used by manufacturing groups to have auditors review systems and controls related to supply chain risks.
Which types of organizations are most likely to require a SOC report?
Organizations operating in finance, medical claims processing, loan processing, and Software as a Service (SaaS) are among those most commonly required to obtain SOC reports. More broadly, any organization that handles customer data can benefit from a SOC report as a way to demonstrate a serious commitment to security.
References
System and Organization Controls: SOC Suite of Services. AICPA.