About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture
Insights & Events

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
AI & Data Consulting Services Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Independent ERP Selection Consultants Fraud & Forensics Healthcare Consulting Services SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
Wealth Management Services by RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Financial Institutions Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to SOC Examinations, IT Audit, & Third-Party Risk

SOC Reporting Needs Assessment

SOC Reporting Needs Assessment

Which SOC Report Do You Need? Take the SOC Reporting Needs Assessment

Customers, prospects, and partners increasingly want independent proof that your controls work. Choosing among System and Organization Controls (SOC) reports comes down to three things: whether your services touch your customers’ financial statements, what kind of data you protect on their behalf, and whether the report will stay private or be shared publicly.

The Short Answer

If your customers rely on your services and reports from your system to book journal entries to their financial statements, you likely need a SOC 1® report. If your customers want independent evidence that you protect their systems and data, measured against the AICPA’s Trust Services Criteria for security, availability, processing integrity, confidentiality, and/or privacy, you likely need a SOC 2® report. Plenty of service organizations fall into both groups, needing SOC 1 and SOC 2 reports. A SOC 3® report is the shareable, general use version of a SOC 2 and is issued together with the SOC 2 report, not on its own.

If this will be your first SOC report, a readiness assessment is usually the best place to start.

Use the questions below to sort out which applies to you.

How to Use This Assessment

  1. Read through the 15 questions below and note your answers. Bring in your IT, security, or compliance lead for the questions in Sections 4 and 7, if you are unsure.
  2. Compare your answers to the guide in What Your Answers Point To.
  3. Send us a note through the Contact Us form on this page. Mention the SOC Reporting Needs Assessment and share a few of your answers, and a RubinBrown SOC specialist will follow up to talk through your recommendation.

Section 1: About Your Organization

1. Which best describes your organization?
  • Software as a Service (SaaS) provider
  • Managed services provider
  • Cloud hosting or data center provider
  • Data processing organization • Financial services provider
  • Healthcare services provider
  • Professional services firm
  • Other

2. What types of information do you handle for customers? Select all that apply.

  • Personally identifiable information (PII)
  • Financial information
  • Protected health information (PHI)
  • Payment card information 
  • Confidential business information
  • Intellectual property
  • We don’t handle sensitive customer data
  • Not sure

Section 2: Who’s Asking and Why

3. Has anyone asked you for independent assurance over your controls? If so, who? Select all that apply.
  • Existing customers
  • Prospective customers, during sales calls
  • Customer procurement or vendor risk teams, through security questionnaires
  • Regulators
  • Investors or board members
  • Business partners or vendors in your supply chain
  • No one has asked, but we expect it soon
  • No one has asked
  • Not sure
4. How would you describe the security questionnaires your team receives from customers and prospects?
Security questionnaires are the detailed checklists that customer procurement and vendor risk teams send before signing or renewing a contract. 
  • We rarely receive them
  • We receive a few each year and handle them without much trouble
  • Volume is growing, and they take significant time away from our security or IT team
  • They are slowing down sales cycles or contract renewals
  • Not sure
5. If a specific report type was requested, which one(s)?
  • SOC 1
  • SOC 2
  • SOC 3
  • SSAE 16, SSAE 18, or another SSAE report
  • Someone asked for “a SOC report” but didn’t specify
  • Not applicable, no specific request yet
6. Have you lost or delayed a sales opportunity because of a compliance or assurance requirement? 
  • Yes
  • No
  • Not sure

Section 3: Financial Reporting Impact

7. Do your services directly affect your customers’ internal controls over financial reporting?
Examples include payroll processing, transaction processing, claims administration, revenue processing, financial recordkeeping, fund administration and data centers hosting critical client (accounting) systems.
  • Yes, this is central to what we do
  • Possibly, but we’re not sure how our services map to our customers’ financial reporting
  • No, our services don’t touch financial reporting
  • Not sure Section

4: Security and Trust Services Scope

8. Setting financial reporting aside, how important is it to show customers that your security and other controls are designed and working effectively?
  • Critical, it’s a requirement to win or keep business
  • Important, it comes up often
  • Somewhat important, there’s occasional interest
  • Not important right now
9. Which Trust Services Criteria are your customers most interested in? Select all that apply. These five categories, defined by the AICPA, are the building blocks of SOC 2 and SOC 3 reports.
  • Security: protection against unauthorized access
  • Availability: systems are up and usable as committed
  • Processing integrity: processing is complete, accurate, and timely
  • Confidentiality: confidential information is protected
  • Privacy: personal information is collected, used, and disposed of properly
  • Not sure
10. What do customers ask about most? Select all that apply.
  • Cybersecurity controls
  • Security monitoring and logging
  • Incident response
  • Vulnerability and patch management
  • Access controls
  • Change management
  • Secure software development (SDLC)
  • Vendor and third-party risk management
  • Business continuity and disaster recovery
  • System availability
  • Data protection and encryption
  • Data retention and disposal
  • Data privacy
  • None of the above

Section 5: Report Distribution

11. If you pursue a SOC report, who needs to see it? 
  • Only specific customers, prospects, or partners, under a nondisclosure agreement
  • Anyone, including prospects, your website visitors, and the general public
  • Both: some customers need the detailed report, and others just need public assurance
  • Not sure

Section 6: Compliance Landscape

12. Is your organization subject to any of the following? Select all that apply. 
  • HIPAA
  • GDPR
  • PCI DSS
  • SOX
  • NIST frameworks
  • ISO 27001
  • State privacy regulations
  • Specific customer contract requirements
  • None
  • Other

Section 7: Current Readiness

13. Do you currently maintain documented, enforced policies and procedures? 
  • Yes, comprehensive and current
  • Partially, some policies exist but we have gaps
  • No, not yet formalized
14. Which of the following are in place at your organization today? For each area, note whether it is in place, partially in place, or not yet in place.
  • Information security policies
  • Incident response plan
  • Business continuity plan
  • Disaster recovery plan
  • Risk assessment process
  • Vendor management program
  • Security awareness training
  • Access management procedures
15. Has your organization previously completed any of the following? Select all that apply.
  • SOC 1 examination
  • SOC 2 examination
  • ISO 27001 certification
  • PCI DSS assessment
  • HITRUST certification
  • None

What Your Answers Point To

Every organization is different, and a SOC specialist will confirm the right fit with you. These are the patterns we look for.
SOC_Decision_Flow.png

Start with readiness
(Questions 13 through 15)

If this will be your first SOC 1 or SOC 2 report, a readiness assessment is almost always the right first step. It identifies control gaps and gives you time to close them before an auditor begins testing, which reduces the risk of exceptions in your final report. This is especially true if your policies are only partially documented or several control areas in Question 14 are not yet in place.

If you have completed a SOC 1 or SOC 2 examination before, you may be ready to move straight to an examination, and readiness becomes a conversation about any new systems, services, or criteria you plan to add.

Signs you need a SOC 1 report
(Question 7)

If your services affect how your customers record, process, or report financial information, their auditors will likely need a SOC 1 report. A “Yes” on Question 7 is a strong signal. A “Possibly” is worth a conversation, because deciding whether a service is relevant to a customer’s financial reporting is a judgment call best made with a specialist.

Signs you need a SOC 2 report
(Questions 3 - 5, 8 - 10)

A SOC 2 report is likely the right fit if any of these apply:

  • A customer, prospect, or procurement team has asked for SOC 2 by name (Questions 3 and 5)
  • Your team is spending significant time on security questionnaires, or questionnaires are slowing down deals (Question 4)
  • Security assurance is critical or important to winning and keeping customers (Question 8)
  • Customers care about one or more of the Trust Services Criteria (Question 9) or ask about the topics in Question 10
A note on security questionnaires:
Many organizations pursue a SOC 2 report specifically to get relief from questionnaire fatigue. Instead of answering hundreds of individual questions for every customer, you can share one independent report that addresses many of the same topics. Customers often accept a SOC 2 report in place of their questionnaire, or ask only a short set of follow up questions alongside it.

Signs you need both SOC 1 and SOC 2
SOC 1 and SOC 2 answer different questions, so look at each one on its own. If your services affect customers’ financial reporting and customers expect broader security assurance, you will likely need both. This is common for payment processors, payroll providers, and software platforms that handle financial transactions.

Signs you need a SOC 3
(Question 11)

A SOC 3 report covers the same Trust Services Criteria as a SOC 2 but is written for general use, so you can post it on your website or share it freely. It does not include the detailed description of controls and test results that a SOC 2 does. Because a quality SOC 3 requires all of the same procedures as a SOC 2, it is issued as a companion to a SOC 2 examination rather than as a replacement for one. If you answered “Anyone” or “Both” to Question 11, plan for a SOC 2 with a companion SOC 3.

If you have other compliance requirements
(Question 12)

If you are also subject to frameworks such as HIPAA, ISO 27001, or NIST, a SOC 2+ report can map those additional requirements into a single SOC 2 examination, which can reduce duplicate audit work.

If you lost or delayed a deal
(Question 6)

A lost or delayed opportunity does not change which report you need, but it does make timing important. A first SOC report, from readiness through examination and reporting, typically takes 9 to 14 months. Starting the conversation early helps you plan a realistic timeline and set expectations with customers who are waiting.

If your answers are mixed or you’re still not sure
That’s common, and it is exactly what a short scoping conversation is for. Requests that come through a customer contract, an ambiguous “SOC report” request, or a mix of financial and security needs are best sorted out together.

SOC 1 vs. SOC 2 vs. SOC 3 at a Glance

  SOC 1 SOC 2 SOC 3
What it covers Controls relevant to customers’ financial reporting Controls related to security, availability, processing integrity, confidentiality, and/or privacy Same criteria as SOC 2, in summary form
Who uses it Customers’ management and their financial statement auditors Customers, prospects, partners, and regulators who need detail Anyone, including prospects and the public
Distribution Restricted use Restricted use, often shared under NDA General use, can be posted publicly
Includes test results Yes (Type 2) Yes (Type 2) No
Common drivers Customer auditor requests, SOX compliance Security questionnaires, enterprise sales, vendor risk reviews Marketing and public trust, always alongside a SOC 2

Get Your Recommendation

Ready to talk through your answers? Complete the Contact Us form on this page and mention the SOC Reporting Needs Assessment in your message. It helps to include:

  • Who is asking for it (Question 3)
  • Which report, if any, was requested (Question 5)
  • Whether this would be your first SOC report (Question 15)
  • Any deadline you are working against

A RubinBrown SOC specialist will follow up to confirm the right report type, scope, and next step for your organization.

Learn more: System and Organization Control (SOC) Reports

SOC 1®, SOC 2®, and SOC 3® are registered trademarks of the American Institute of Certified Public Accountants.

 

Contact Us

Mention the SOC Reporting Needs Assessment and share a few of your answers, and a RubinBrown SOC specialist will follow up to talk through your recommendation.

SOC Examination Services

Audrey Katcher, CPA, CISA, CITP, CGMA Partner audrey.katcher@rubinbrown.com 314-290-3420
Christine Figge, CPA, CGMA Partner christine.figge@rubinbrown.com 314-290-3225
Katelyn Rattner Partner Katelyn.Rattner@RubinBrown.Com 312.705.1706
Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications

Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

1-800-678-3134
  • Services
  • Industries
  • Insights & Events
  • Careers & Culture
  • Contact
  • RubinBrown Advisors
  • RubinBrown Corporate Finance
  • RubinBrown Executive Recruiting
  • Firm News
  • Disclaimers
  • Privacy Policy
  • Client Payment
© 2026 RubinBrown LLP