SOC 2 Compliance in Reno, NV
SOC 2 is a report, issued by an independent CPA firm, on how well a company protects the customer data it stores or processes. Larger customers increasingly ask for one before they sign. We help Reno, Sparks and Carson City companies get ready by putting the security controls a SOC 2 audit looks for in place and keeping them running, including 24/7/365 monitoring by our SOC.
An attestation report, not a certificate.
SOC 2 (System and Organization Controls 2) is defined by the American Institute of Certified Public Accountants (AICPA). An independent CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria and issues a report describing what it found.1
There is no "SOC 2 certified" badge. What customers ask for is your current SOC 2 report, and the opinion inside it.
Companies that handle other companies' data.
- Software and SaaS companies selling to larger businesses
- Data processors, payroll and billing services, and hosting providers
- Professional and outsourced service firms with access to client systems
- Any vendor whose customers send security questionnaires before signing
No law requires SOC 2. Customers do, through their contracts and vendor reviews.
Five categories, one of them required.
Every SOC 2 report covers Security. You choose which of the other four to include, based on what you promise customers.
| Category | What it covers | Included |
|---|---|---|
| Security | Protection against unauthorized access, disclosure and damage to systems; also called the common criteria | Always |
| Availability | Systems are available for operation and use as committed | Optional |
| Processing integrity | Processing is complete, valid, accurate and timely | Optional |
| Confidentiality | Information designated as confidential is protected | Optional |
| Privacy | Personal information is collected, used and disposed of as committed | Optional |
Designed well, or working over time.
| Feature | Type 1 | Type 2 |
|---|---|---|
| What the auditor examines | Whether controls are suitably designed | Whether controls operated effectively |
| Time covered | A single point in time | A period, typically 3 to 12 months |
| What customers usually expect | Accepted as a first step | The standard most enterprise customers ask for |
| Evidence needed | Policies and system descriptions | Records showing controls ran throughout the period |
SOC 1 vs SOC 2
SOC 1 reports cover controls relevant to a customer's financial reporting, such as payroll or billing processing. SOC 2 covers security and the other Trust Services Criteria. Some service providers need both.
SOC 2 vs ISO 27001
ISO 27001 is an international certification of an information security management system. SOC 2 is a CPA firm's attestation report, most common in the United States. The controls overlap considerably.
From first conversation to report.
Scope
Decide which systems, services and Trust Services Criteria the report will cover, based on what customers are asking for.
Find the gaps
Compare current controls against the criteria. A free security assessment is a good starting point, though it is not the audit itself.
Put controls in place
Close the gaps: access control, monitoring, incident response, vendor management, training, policies and change management.
Run them and keep evidence
For Type 2, controls must operate, and leave a record, throughout the observation period.
The CPA firm's examination
Your chosen CPA firm tests the controls and issues the report. Most companies then renew every year.
Where our plans support common SOC 2 controls.
The Security category is where most SOC 2 work lives, and many of its controls are the same ones our plans run every day. Your company remains responsible for its policies, its system description and its relationship with the auditor.
| SOC 2 control area | How we support it | Plan |
|---|---|---|
| Logical access, MFA and least privilege | Zero trust architecture | Both |
| System monitoring and anomaly detection | Managed SIEM and MDR, watched by our SOC 24/7/365 | Both |
| Incident response | Incident response | Both |
| Security awareness | Security awareness training with phishing simulations | Both |
| Email and data protection | Email security, including encrypted email | Both |
| Risk assessment and vendor management | Your responsibility, with vCISO guidance | Both |
| Vulnerability management | Vulnerability scanning and management | SecurityPlus |
| Network access controls | Zero trust network access | SecurityPlus |
| Penetration testing | Penetration testing, often requested by auditors and customers | Sold separately |
Reno Cybersecurity Company is not a CPA firm and does not issue SOC 2 reports or opinions. This page is general information, not legal or audit advice.
SOC 2 FAQ
Find out where your business is exposed.
Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.