About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture
Insights & Events

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
AI & Data Consulting Services Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Independent ERP Selection Consultants Fraud & Forensics Healthcare Consulting Services SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
Wealth Management Services by RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Financial Institutions Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to SOC Examinations, IT Audit, & Third-Party Risk

System and Organization Control (SOC) Reports

At RubinBrown, our team of professionals understand the value that System and Organization Controls (SOC) reports bring to both service organizations and user entities in today's marketplace to reduce third-party risk.

System and Organization Control (SOC) Reports

At RubinBrown, our team of professionals understand the value that System and Organization Controls (SOC) reports bring to both service organizations and user entities in today's marketplace to reduce third-party risk.

It is becoming increasingly common for businesses to outsource aspects of their operations to a trusted third party. At RubinBrown, our team of consultants understands the value that System and Organization Controls (SOC) reports bring to both service organizations and the user entities that rely on them. We help organizations navigate the requirements of SOC 1®, SOC 2®, SOC 3® and related examinations, reducing third party risk and easing audit fatigue along the way.

 

Which SOC Report Do You Need?

SOC 1

If an error in your systems could misstate your customers' financial statements, you likely need a SOC 1. SOC 1 reports address controls at a service organization that are relevant to a user entity's internal control over financial reporting (ICFR).

SOC 2

If your customers are asking whether they can trust you to securely handle their data, you likely need a SOC 2. SOC 2 reports address the security, availability, processing integrity, confidentiality, and/or privacy of the systems a service organization uses to process user data, and are generally restricted to parties with sufficient knowledge of the organization and the services it provides.

SOC 3

SOC 3 reports cover the same trust services criteria as a SOC 2 (security, availability, processing integrity, confidentiality, and/or privacy), but are written for general use, so you can share them publicly, for example on your website or in marketing materials, without restriction.

SOC for Supply Chain

SOC for Supply Chain examinations report on the controls within a manufacturing, production, or distribution system, communicating to stakeholders how an organization identifies, prevents, and responds to risks across its supply chain.

SOC 2+

Many organizations need to report against more than one framework at once. A SOC 2+ engagement layers additional criteria onto your SOC 2 examination, commonly the Cloud Controls Matrix, HITRUST, HIPAA, ISO 27001, or NIST 800-53, so you can satisfy multiple stakeholders through a single, unified reporting effort instead of repeating the process framework by framework.

When Do You Need a SOC Report?

  • You've been asked to provide a client, or a future client, a report on your controls or security.
  • A client requires a SOC report according to your contract with them.
  • A future client is requiring an independent assessment related to one or more control frameworks and you'd like to report under one unified framework.
  • Your compliance, finance, legal, or internal control and security groups are spending too much time filling out control questionnaires for prospects and customers.
  • Your sales cycle is slowing down because prospects are requiring proof of your security controls before they sign a contract for your services.

Timeline and Process

The timeline to get prepared for an initial SOC engagement is customized by RubinBrown to meet each client’s needs and is dependent on your report’s scope and the maturity of your organization’s current controls. We generally guide clients through four phases:
  • Readiness Assessment: We evaluate your current control environment against the applicable criteria, identify gaps, and build a prioritized remediation roadmap so you enter the examination period with fewer surprises.
  • Examination: Our team performs the testing required for your report type, a point in time review for a Type 1 report, or testing of operating effectiveness across a review period for a Type 2 report.
  • Reporting and Planning: We issue your formal SOC report and help you establish a plan for the next reporting cycle.
  • Management’s Ongoing Monitoring: Control owners embed control performance into their daily workflows, so subsequent examinations become a routine part of your compliance calendar rather than a recurring scramble.

Ways RubinBrown Can Help

  • Collaborate with your team while working remotely or on site.
  • Evaluate the various SOC report types and help you select the one that best fits your organization and your customers' needs.
  • Explain the time and resource commitments required for each SOC report.
  • Provide a hands-on risk assessment process, led by an experienced member of our SOC team, so you understand what each control objective or trust services criterion means for your business.
  • Reduce your ongoing audit burden through open communication, clear expectations, and transparent project tracking.

Why RubinBrown?

Audrey Katcher, CPA, CISA, CITP, CGMA
Partner | audrey.katcher@rubinbrown.com

Audrey has more than 30 years of IT audit and service organization control experience. She oversees RubinBrown's Information Technology Risk Services practice, including third party assurance, cyber attest, SOC services, and emerging services such as AI Governance and Risk Assessments. Audrey has been a contributing author of the American Institute of Certified Public Accountants (AICPA) SOC 2 Guide since its first release and serves as a signing partner for SOC 1 and SOC 2 engagements. She is a member of the AICPA's SOC 2 Working Group, served on the AICPA Board of Examiners, and sits on the International Board of Directors for Baker Tilly International Ltd.

Rob Rudloff, CISSP, ISSMP, CCSP, PMP
Partner | rob.rudloff@rubinbrown.com

Rob has more than 25 years of information security and cybersecurity experience across security reviews, mitigation, strategy, and architecture development. He is a Certified Information Systems Security Professional, Information Systems Security Management Professional, Certified Cloud Security Professional, and Project Management Professional.

Christine Figge, CPA, CGMA
Partner | christine.figge@rubinbrown.com

Christine has more than 20 years of public accounting and consulting experience. She brings a unique perspective to the SOC process, having used SOC reports as an auditor, assisted management in developing their system description and control identification, and performed the attestation services required to issue SOC reports for clients. Christine is a contributing author to the AICPA’s SOC for Service Organizations toolkit. She serves as a signing partner at RubinBrown and provides quality review services to CPA firms around the country for SOC 1, SOC 2 and SOC 3 engagements.

Katelyn Rattner, CISA
Partner | katelyn.rattner@rubinbrown.com

Katelyn Rattner has more than 13 years in public accounting, specializing in technology compliance and advisory services. She serves as a trusted advisor to both public and private sector clients, partnering with executive leadership to navigate complex regulatory environments, strengthen internal controls, and align technology strategies with broader business objectives.

Frequently Asked Questions

Start by identifying who is asking and why. Customers, prospects, and vendors typically request a SOC 2, while service organizations affecting a customer's financial reporting need a SOC 1. We can help you confirm the right report type and next steps.
A SOC 1 addresses controls relevant to your customers' financial reporting. A SOC 2 addresses the security, availability, confidentiality, processing integrity, and/or privacy of the systems you use to serve customers.
A Type 1 report evaluates whether your controls are suitably designed as of a specific point in time. A Type 2 report goes further, testing whether those controls actually operated effectively over a review period, typically six to twelve months. Most customers and prospects will eventually expect a Type 2 report.
A first time SOC engagement typically runs nine to fourteen months from readiness through report issuance, depending on the scope and how mature your current controls are.
If your customers store sensitive data with you, are asking for compliance reports, or your sales cycles are slowing down due to security reviews, a SOC 2 can remove that friction and speed up enterprise deals.
A SOC 2+ engagement layers an additional framework, such as HITRUST, HIPAA, ISO 27001, or NIST 800-53, onto your SOC 2 examination. It's worth considering if more than one of your customers or regulators require reporting against different standards, since it lets you satisfy multiple requirements through a single engagement.

Contact Us

Insights and Resources

View All Insights
Insight Article

What is a CPA Firm's Role in Cyber Security?

Read This Article
Insight Article

How to Build a Successful Cloud Security Strategy​

Read This Article
Insight Article

Cyber: Ransomware Meets the Supply Chain - Why "We Have Backups" Isn't Enough Anymore

Read This Article

SOC Examination Services

Audrey Katcher, CPA, CISA, CITP, CGMA Partner audrey.katcher@rubinbrown.com 314-290-3420
Christine Figge, CPA, CGMA Partner christine.figge@rubinbrown.com 314-290-3225
Katelyn Rattner Partner Katelyn.Rattner@RubinBrown.Com 312.705.1706
Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications

Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

1-800-678-3134
  • Services
  • Industries
  • Insights & Events
  • Careers & Culture
  • Contact
  • RubinBrown Advisors
  • RubinBrown Corporate Finance
  • RubinBrown Executive Recruiting
  • Firm News
  • Disclaimers
  • Privacy Policy
  • Client Payment
© 2026 RubinBrown LLP