SOC 2 Compliance in Reno, NV

SOC 2 is a report, issued by an independent CPA firm, on how well a company protects the customer data it stores or processes. Larger customers increasingly ask for one before they sign. We help Reno, Sparks and Carson City companies get ready by putting the security controls a SOC 2 audit looks for in place and keeping them running, including 24/7/365 monitoring by our SOC.

An attestation report, not a certificate.

SOC 2 (System and Organization Controls 2) is defined by the American Institute of Certified Public Accountants (AICPA). An independent CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria and issues a report describing what it found.1

There is no "SOC 2 certified" badge. What customers ask for is your current SOC 2 report, and the opinion inside it.

Companies that handle other companies' data.

  • Software and SaaS companies selling to larger businesses
  • Data processors, payroll and billing services, and hosting providers
  • Professional and outsourced service firms with access to client systems
  • Any vendor whose customers send security questionnaires before signing

No law requires SOC 2. Customers do, through their contracts and vendor reviews.

Five categories, one of them required.

Every SOC 2 report covers Security. You choose which of the other four to include, based on what you promise customers.

The AICPA Trust Services Criteria categories
CategoryWhat it coversIncluded
SecurityProtection against unauthorized access, disclosure and damage to systems; also called the common criteriaAlways
AvailabilitySystems are available for operation and use as committedOptional
Processing integrityProcessing is complete, valid, accurate and timelyOptional
ConfidentialityInformation designated as confidential is protectedOptional
PrivacyPersonal information is collected, used and disposed of as committedOptional

Designed well, or working over time.

SOC 2 Type 1 compared with Type 2
FeatureType 1Type 2
What the auditor examinesWhether controls are suitably designedWhether controls operated effectively
Time coveredA single point in timeA period, typically 3 to 12 months
What customers usually expectAccepted as a first stepThe standard most enterprise customers ask for
Evidence neededPolicies and system descriptionsRecords showing controls ran throughout the period

SOC 1 vs SOC 2

SOC 1 reports cover controls relevant to a customer's financial reporting, such as payroll or billing processing. SOC 2 covers security and the other Trust Services Criteria. Some service providers need both.

SOC 2 vs ISO 27001

ISO 27001 is an international certification of an information security management system. SOC 2 is a CPA firm's attestation report, most common in the United States. The controls overlap considerably.

From first conversation to report.

  1. Scope

    Decide which systems, services and Trust Services Criteria the report will cover, based on what customers are asking for.

  2. Find the gaps

    Compare current controls against the criteria. A free security assessment is a good starting point, though it is not the audit itself.

  3. Put controls in place

    Close the gaps: access control, monitoring, incident response, vendor management, training, policies and change management.

  4. Run them and keep evidence

    For Type 2, controls must operate, and leave a record, throughout the observation period.

  5. The CPA firm's examination

    Your chosen CPA firm tests the controls and issues the report. Most companies then renew every year.

Where our plans support common SOC 2 controls.

The Security category is where most SOC 2 work lives, and many of its controls are the same ones our plans run every day. Your company remains responsible for its policies, its system description and its relationship with the auditor.

Common SOC 2 control areas and the services that support them
SOC 2 control areaHow we support itPlan
Logical access, MFA and least privilegeZero trust architectureBoth
System monitoring and anomaly detectionManaged SIEM and MDR, watched by our SOC 24/7/365Both
Incident responseIncident responseBoth
Security awarenessSecurity awareness training with phishing simulationsBoth
Email and data protectionEmail security, including encrypted emailBoth
Risk assessment and vendor managementYour responsibility, with vCISO guidanceBoth
Vulnerability managementVulnerability scanning and managementSecurityPlus
Network access controlsZero trust network accessSecurityPlus
Penetration testingPenetration testing, often requested by auditors and customersSold separately

Reno Cybersecurity Company is not a CPA firm and does not issue SOC 2 reports or opinions. This page is general information, not legal or audit advice.

SOC 2 FAQ

SOC 2 is a report on a service organization's controls, defined by the American Institute of Certified Public Accountants (AICPA) and issued by an independent CPA firm. It matters because larger customers increasingly ask vendors that store or process their data for a SOC 2 report before they sign, instead of sending long security questionnaires.
A Type 1 report looks at whether your controls are suitably designed at a single point in time. A Type 2 report tests whether those controls actually operated effectively over a period, typically three to twelve months. Many companies start with Type 1 to show progress, but most enterprise customers expect a Type 2.
Only a licensed, independent CPA firm can perform a SOC 2 examination and issue the report. Reno Cybersecurity Company is not a CPA firm and does not issue SOC 2 reports. We help put security controls in place and keep them running so you are ready for the auditor.
No law requires SOC 2. But a report only covers a specific period, so customers usually ask for a current one, and most companies renew their Type 2 report every year.
Generally no. A SOC 2 report is intended for customers, prospects and other parties with a need to know, and is usually shared under a nondisclosure agreement. Companies that want a public-facing summary can ask their CPA firm about a SOC 3 report.
No. SOC 2 is an attestation report by a CPA firm against the AICPA Trust Services Criteria and is most common in the United States. ISO 27001 is an international certification of an information security management system. The controls overlap considerably, so work on one often helps with the other.
It depends on how mature your controls are. Companies typically spend time on readiness before an audit, and a Type 2 report then needs an observation period, often three to twelve months, before the CPA firm can issue it.
Costs depend on your size, scope, which Trust Services Criteria you include and your auditor. The main pieces are the CPA firm's audit fee, any compliance software you use, and the security controls themselves. Our plans cover many of those security controls at $100 or $130 per user per month.

Find out where your business is exposed.

Book a free, comprehensive cybersecurity risk assessment. See where your business is exposed and what to fix first. No cost, no contract.