- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Assurance Reports
SOC 1
SOC 1 is the AICPA's report on controls at a service organization that are relevant to its customers' internal control over financial reporting. It is performed under the attestation standards (SSAE No. 18, AT-C section 320) and is meant for two audiences: the customer organizations that outsource a process, and the CPA firms that audit those customers' financial statements.
Payroll, claims processing, fund accounting, transaction processing and hosting of financial systems are the usual subjects.
To get one, the service organization must write a description of its system, define control objectives, map the controls that achieve them, and sign a management assertion. A Type 1 report covers design at a point in time; a Type 2 report also covers operating effectiveness across a period.
Because the auditor tests exactly what is described, the written procedures, approval chains and control owners have to be current and evidenced.
help
Who has to comply
Voluntary and contractual. Any service organization whose service affects a customer's financial statements will be asked for it by customers or by the customer's financial statement auditor, especially where the customer is publicly traded or regulated.
What the assessor asks to see
System description and management assertion; control objectives and control matrix; organization chart with control owners; policies and procedures for the in-scope processes; population lists (transactions, changes, access grants, terminations); sampled evidence per control (approvals, reconciliations, tickets, logs, access reviews); subservice organization SOC reports and complementary user entity controls; management review and exception handling records.
Assessors
Who assesses SOC 1
A licensed CPA firm (a firm of independent certified public accountants) that performs the examination and issues the service auditor's report. Accredited by AICPA membership and state board CPA licensure; firms performing attestation engagements are subject to the AICPA peer review program. No separate scheme accreditor.
No firm has claimed a SOC 1 assessor listing yet. Claim yours →
Consultants
Who helps with SOC 1
Yes. Readiness consultants (advisory firms, the consulting arms of CPA firms, GRC platform vendors) help write the system description, set control objectives, build the control matrix, and rehearse evidence collection. Typical engagement is a readiness assessment, remediation, then the examination, with the readiness firm kept independent from the signing firm.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 / SOC 2
- Who they help
- Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Pentest + SOC 2 readiness
- Who they help
- Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 + CREST pentest
- Who they help
- Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for SOC 1
Tools that name this framework in their own material.
Related reading
- What is a SOC 1 report and who needs one?A CPA firm explains control objectives, Type 1 versus Type 2, and the complementary user entity controls that trip clients up.Linford & Co
- SOC reports explained: building trust in the services you provideSets SOC 1 next to the other SOC reports so you can tell which one a customer's finance auditor is actually asking for.Warren Averett
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SOC 1
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SOC 1
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.