HomeFrameworksAssurance ReportsSOC for Cybersecurity

Framework  Assurance Reports

SOC for Cybersecurity

SOC for Cybersecurity is an AICPA examination in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program rather than on a specific service delivered to customers. It was introduced in 2017 and is the one SOC examination designed for any organization, not just service providers.

The report is general use and can be shared with boards, investors, insurers, regulators and business partners.

The organization must write a description of its cybersecurity risk management program that satisfies the AICPA description criteria (nature of the business, information assets, governance, risk assessment, control processes, monitoring), and it must select control criteria (commonly the Trust Services Criteria, but NIST CSF or ISO 27001/27002 are permitted) against which the CPA evaluates whether the controls were effective.

Written governance, risk assessment and control documentation is therefore the backbone of the engagement.

AI-compiled
Share
Sponsored
SOC
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with SOC for Cybersecurity
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Used by organizations that want independent assurance over the whole security program to show boards, investors, cyber insurers or customers. No statute or contract standard requires it by name.

What the assessor asks to see

Program description written to the description criteria; management assertion; governance documents (board reporting, policies, roles); risk assessment and asset inventory; control inventory mapped to the selected control criteria; evidence of control operation over the period (access reviews, vulnerability management, incident records, awareness training, vendor management); monitoring and remediation records.

Assessors

Who assesses SOC for Cybersecurity

A licensed CPA firm performing the examination under the AICPA attestation standards. Accredited by State board CPA licensure and the AICPA peer review program. No scheme-level accreditor.

No firm has claimed a SOC for Cybersecurity assessor listing yet. Claim yours →

Consultants

Who helps with SOC for Cybersecurity

A readiness ecosystem exists among cybersecurity advisory firms and CPA advisory arms: drafting the program description to the description criteria, mapping controls to the chosen control criteria, running gap assessments and preparing evidence. Engagements typically run a readiness phase then the examination.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

Silent SectorScottsdale, AZ, USANot yet verified
What they do
Cybersecurity programme
Who they help
Silent Sector is a cybersecurity programme based in Scottsdale, AZ, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
vCISO.comPittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Tranquility Cybersecurity (TCSA)Gurugram, IndiaNot yet verified
What they do
ISO 27001 auditor-led consultancy
Who they help
Tranquility Cybersecurity (TCSA) is an ISO 27001 auditor-led consultancy based in Gurugram, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
VISTA InfoSecMumbai / US / Singapore, IndiaNot yet verified
What they do
InfoSec + compliance consultancy
Who they help
VISTA InfoSec is an infoSec + compliance consultancy based in Mumbai / US / Singapore, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IsecurionBangalore, IndiaNot yet verified
What they do
ISO 27001 / SOC 2
Who they help
Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Illume IntelligenceCalicut, Kerala, IndiaNot yet verified
What they do
Pentest + SOC 2 readiness
Who they help
Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Precursor SecurityLeeds, UKNot yet verified
What they do
ISO 27001 + CREST pentest
Who they help
Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. Cybersecurity: a new engagement opportunityExplains the description criteria and control criteria behind the examination and how it differs from a SOC 2.Journal of Accountancy
  2. New opportunities for firms in SOC reportingUseful on why practitioner supply is thin and what expertise a firm needs before it can run these engagements.Journal of Accountancy

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for SOC for Cybersecurity

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with SOC for Cybersecurity

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.