An assurance report, with a defined scope
AICPA describes SOC services as assurance reporting by CPAs. SOC 2 concerns controls relevant to security, availability, processing integrity, confidentiality or privacy, depending on the engagement scope.
Read the request carefully
Identify the service and system, criteria, report period, exceptions and customer expectations. Do not substitute a generic claim of “SOC compliance” for the actual report and its boundaries.
Prepare evidence without overclaiming
Organise existing policies, responsible owners and operating records. Mark gaps and planned work honestly. Independent examination and report issuance require an appropriate assurance engagement.
- Confirm what may be shared and with whom.
- Avoid disclosing unnecessary personal data or security detail.
- Ensure the response describes the service the customer will actually receive.
Common questions
Is SOC 2 a privacy-law certificate?
No. An assurance report has its own scope and does not settle every legal obligation.
Can advisory preparation guarantee a report outcome?
No. Preparation and the independent examination are different activities; the examiner evaluates the relevant evidence.
Discuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
References
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Framework guides