The AICPA recently issued new guidance, clarifying and expanding the use of the SSAE-16 Report and how it can be leveraged to show adherence with any set of agreed-upon procedures. The SSAE-18 requirements are now effective as of May 1, 2017 and bring new changes you can learn about here on our SSAE 18 Report overview page.

SOC 2 – Top Resources

Recent Posts

The SSAE 18 Audit Standard (Updates and Replaces SSAE-16)

SSAE 18 is a series of enhancements aimed to increase the usefulness and quality of SOC reports, now, superseding SSAE 16, and, obviously the relic of audit reports, SAS 70. The changes made to the standard this time around will require companies to take more control and ownership of their own internal controls around the …

0 comments

SOC 2 Report – Trust Services Criteria and Categories

The System and Organization Controls (SOC) 2 Report will be performed in accordance with AT-C 205 (formerly under AT-101) and based upon the Trust Services Principles, with the ability to test and report on the design (Type I) and operating (Type II) effectiveness of a service organization’s controls (just like SOC 1 / SSAE 18). …

1 comment

What is a SOC 2?

The Service and Organization Controls 2 Report, formally known as a Service Organization Controls Report as of the most recent update to the SSAE 18 audit standard. A SOC 2 report can cover the design (type 1 report) or operating effectiveness (type 2 report) of controls around a Company’s system over any number of categories, including, …

SOC 2 + Additional Subject Matter (SOC2 Plus)

The AICPA recently made efforts to expand the use of SOC 2 in two significant ways – additional reporting Criteria and alignment with other significant and at times, required, IT Security regulations. This expansion increases the utility of a SOC 2 report and overall compliance costs and efforts of Businesses small, medium, and large. The Additional …

Comments are closed.