- What they do
- Cybersecurity programme
- Who they help
- Silent Sector is a cybersecurity programme based in Scottsdale, AZ, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Assurance Reports
SOC for Cybersecurity
SOC for Cybersecurity is an AICPA examination in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program rather than on a specific service delivered to customers. It was introduced in 2017 and is the one SOC examination designed for any organization, not just service providers.
The report is general use and can be shared with boards, investors, insurers, regulators and business partners.
The organization must write a description of its cybersecurity risk management program that satisfies the AICPA description criteria (nature of the business, information assets, governance, risk assessment, control processes, monitoring), and it must select control criteria (commonly the Trust Services Criteria, but NIST CSF or ISO 27001/27002 are permitted) against which the CPA evaluates whether the controls were effective.
Written governance, risk assessment and control documentation is therefore the backbone of the engagement.
help
Who has to comply
Voluntary. Used by organizations that want independent assurance over the whole security program to show boards, investors, cyber insurers or customers. No statute or contract standard requires it by name.
What the assessor asks to see
Program description written to the description criteria; management assertion; governance documents (board reporting, policies, roles); risk assessment and asset inventory; control inventory mapped to the selected control criteria; evidence of control operation over the period (access reviews, vulnerability management, incident records, awareness training, vendor management); monitoring and remediation records.
Assessors
Who assesses SOC for Cybersecurity
A licensed CPA firm performing the examination under the AICPA attestation standards. Accredited by State board CPA licensure and the AICPA peer review program. No scheme-level accreditor.
No firm has claimed a SOC for Cybersecurity assessor listing yet. Claim yours →
Consultants
Who helps with SOC for Cybersecurity
A readiness ecosystem exists among cybersecurity advisory firms and CPA advisory arms: drafting the program description to the description criteria, mapping controls to the chosen control criteria, running gap assessments and preparing evidence. Engagements typically run a readiness phase then the examination.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 auditor-led consultancy
- Who they help
- Tranquility Cybersecurity (TCSA) is an ISO 27001 auditor-led consultancy based in Gurugram, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- InfoSec + compliance consultancy
- Who they help
- VISTA InfoSec is an infoSec + compliance consultancy based in Mumbai / US / Singapore, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 / SOC 2
- Who they help
- Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Pentest + SOC 2 readiness
- Who they help
- Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 + CREST pentest
- Who they help
- Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for SOC for Cybersecurity
Tools that name this framework in their own material.
Related reading
- Cybersecurity: a new engagement opportunityExplains the description criteria and control criteria behind the examination and how it differs from a SOC 2.Journal of Accountancy
- New opportunities for firms in SOC reportingUseful on why practitioner supply is thin and what expertise a firm needs before it can run these engagements.Journal of Accountancy
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SOC for Cybersecurity
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SOC for Cybersecurity
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.