SSAE 18 · Trust Services Criteria
SOC examination support for your practice
Your clients are being asked for SOC 1 and SOC 2 reports and your bench does not cover the criteria. We supply the delivery capacity for readiness fieldwork, control testing, and draft reports, without you referring the relationship somewhere else.
We do not issue examination reports and we do not express opinions. Your firm performs the examination, evaluates the evidence, and signs. We are not a CPA firm licensed in any US jurisdiction.
The arrangement
How a SOC engagement is split
Agreed before the first engagement. Everything that involves professional judgment about the opinion stays with your firm, because it has to.
You
Stays with your firm
- Client acceptance, the engagement letter, and independence for the examination
- Determining whether readiness and examination work can be performed by your firm
- Agreeing the system boundary, the criteria, and the report period with the client
- Direction, supervision, and review of every procedure we perform
- Evaluating exceptions and deciding what they mean for the opinion
- The examination report, the opinion, and the signature
Us
What we do
- Readiness fieldwork: control mapping, gap identification, and evidence design review
- Building and maintaining the control matrix against criteria or control objectives
- Requesting, tracking, and reviewing evidence through your portal
- Sample selection and testing of operating effectiveness across the period
- Drafting exception write-ups with condition, cause, and effect for your evaluation
- Preparing the draft report and system description review comments in your template
Scoping
Which SOC report does the client need?
Clients use these three names loosely, and what a customer asked for is often not what the customer needs. The distinction decides scope, cost, and whether the report answers the question.
| Attribute | SOC 1 | SOC 2 | SOC 3 |
|---|---|---|---|
| What it addresses | Controls at a service organization relevant to its user entities’ internal control over financial reporting. | Security, availability, processing integrity, confidentiality, and privacy, whichever of the five are in scope. | The same criteria as a SOC 2, reported at a summary level without the detailed control and testing matrix. |
| Who reads it | User entities and their financial statement auditors, who use it under AU-C 402. | Customer security, procurement, risk, and vendor management teams. Restricted use. | General use. It can be published on a website. |
| Where the hours go | Control objective design, transaction processing testing, and the reliance narrative. | Criteria mapping, evidence collection across a period, and exception evaluation. | Minimal incremental work where a SOC 2 already exists for the same period. |
Scoping conclusions are your firm’s. Where the client is a recordkeeper, payroll processor, or third-party administrator, note that its SOC 1 is read every season by plan audit teams, including ours, which is a useful check on whether the control objectives are written to be relied upon.
Then Type 1 or Type 2
A Type 1 reports on design and implementation as of a single date and can be issued as soon as the controls exist. A Type 2 reports on operating effectiveness over a period, typically three to twelve months, and is what enterprise procurement and user entities’ auditors actually ask for.
Path
From scoping call to issued report
Elapsed times are ranges, not commitments. Client remediation and the observation period are outside anyone's control and together they are most of the calendar.
- 01
Scoping call with your team
1 week·You lead
Your partner sets the boundary, the criteria, the period, and the report type with the client. We join to size the effort and identify what evidence will be hard to obtain, which is usually the thing that moves the estimate.
- 02
Readiness fieldwork
3–5 weeks·We execute
Where your firm is performing readiness, we map the control environment, test a sample the way an examination would, and produce a gap list ranked by what will actually cause an exception. Advisory work, no opinion.
- 03
Client remediation
4–12 weeks·Client leads
The client implements. Our role stays advisory and is constrained by your independence conclusion. We can describe what an adequate control looks like, we do not design or operate it. This stage is the largest variable in the whole timeline.
- 04
Observation period
3–12 months·Client leads
The window a Type 2 report covers. We check in during the period so that evidence is accumulating in a retrievable form, rather than discovering at testing that a control produced nothing to test.
- 05
Examination fieldwork
4–8 weeks·We execute
Evidence requests, sample selection, and operating effectiveness testing across the period, documented in your templates. Exceptions are raised to your in-charge as they surface.
- 06
Draft report and issuance
2–3 weeks·You lead
We prepare the draft report and our comments on the client’s system description. Your firm evaluates the exceptions, forms the opinion, and issues. Bridge letters, if needed, are the client’s management representation, not ours and not yours.
Scope
Four things that decide the scope and the fee
Settled at the scoping call, because each of them changes what the examination costs and how long it takes.
- Complementary user entity controls (CUECs)
- Controls the report assumes the client’s customers perform. They belong in the report only where an objective or criterion genuinely cannot be met without them. Padded CUEC lists are obvious to an experienced reader, and we flag them in review.
- Complementary subservice organization controls (CSOCs)
- The same idea pointed at the client’s vendors: controls relied on at a cloud provider or subprocessor that are necessary for the objectives or criteria to be met.
- Carve-out versus inclusive method
- Carve-out excludes a subservice organization’s controls and discloses the reliance. Inclusive brings them inside the examination, which requires that organization’s cooperation and assertion. Carving out major cloud providers is normal and expected.
- Bridge letters (gap letters)
- A letter from the client’s management covering the period between the end of the last report and today, stating that no material changes have occurred. It is management’s representation, not an auditor’s opinion, and it does not extend the examination.
Independence
Where the boundary sits, and who holds it
A firm cannot examine controls it designed or implemented. Where your firm performs a readiness assessment and then the examination for the same client, the readiness work has to remain advisory: identifying gaps and describing what an adequate control looks like, not designing, implementing, or operating one.
That boundary is your firm’s to set and your conclusion to document. Our people work inside whatever line you draw. When a client pushes across it, asking our team to write the policy rather than review it, or to configure the control rather than test it, we escalate to your in-charge instead of quietly obliging.
The same discipline governs our internal audit support, where the restrictions are stricter still.
Questions
SOC support FAQ
What partners ask before adding offshore delivery to a SOC practice, including the language question that costs credibility in procurement.
Who signs the SOC report?
Your firm. We are not a CPA firm licensed in any US jurisdiction, we do not perform examinations in our own name, and we do not express opinions. We perform procedures under your direction, supervision, and review, and we prepare drafts for your evaluation.
The practical consequence is that the client relationship, the opinion, and the report remain entirely yours. Firms use us to add delivery capacity to a SOC practice, not to outsource one.
How does our independence work if you do readiness and we do the examination?
The constraint sits on your firm, and the conclusion is yours to reach. A firm cannot examine controls it designed or implemented, so where your firm performs readiness and then the examination for the same client, the readiness work has to stay advisory: identifying gaps and describing what an adequate control looks like, not designing, implementing, or operating controls.
Our people work within whatever boundary you set, and we will tell you when a client request is drifting across it rather than quietly obliging. Where a client needs deeper remediation help than the boundary allows, the right answer is a different provider for that piece.
How long does a SOC 2 take, start to finish?
From a standing start with no formal control environment, six to twelve months to a first Type 2 report. The examination fieldwork is a matter of weeks. What consumes the calendar is client remediation and then the observation period, which cannot be compressed. A three-month period takes three months.
The variable worth managing is evidence design. Controls that operate but produce nothing retrievable are the reason periods get restarted, so we check in during the observation window rather than arriving at the end and finding out.
Can we use a compliance automation platform alongside you?
Yes. Vanta, Drata, Secureframe and similar tools are common on these engagements and they remove most of the evidence chasing. We work inside them where the client has one.
What they do not do is replace the examination. A platform dashboard showing every control green is not a report and carries no opinion. An independent practitioner still has to obtain and evaluate evidence and exercise judgment, and your firm still has to sign. Treat the platform as the evidence pipeline.
What happens when we find exceptions?
We draft the exception with condition, cause, effect, and the population it came from, and route it to your in-charge as it surfaces rather than saving it for the end. Nothing reaches a draft report before your team has evaluated it.
Whether an exception qualifies the opinion is your firm’s judgment. Exceptions are a normal feature of Type 2 reports and an experienced reader is not alarmed by a well-explained one, but the evaluation is not something a support provider should be making, and we do not.
Is a SOC 2 a certification?
No. A SOC 2 is an examination performed by a licensed CPA firm that results in a report containing an opinion on controls over a stated period. There is no certificate, no certifying body, and no pass mark. Phrases like “SOC 2 certified” or “SOC 2 compliant” are not correct usage, and procurement teams that read reports for a living notice. The right language is “a SOC 2 Type 2 report” or “an annual SOC 2 examination.”
ISO/IEC 27001 is a certification, issued by an accredited certification body against a management system standard. The two overlap in subject matter and are often pursued together, but they are different instruments with different audiences. We keep this distinction in every draft we hand you, including in client-facing language.
Do your people have the right background for SOC work?
SOC engagements need IT audit skill rather than financial audit skill: access management, change management, cloud infrastructure, and the ability to read evidence out of systems rather than out of a general ledger. The credentials that matter are the CISA and CISSP alongside the CPA and CA.
The credentials actually held by our team are listed in configuration and shown on our about page, and we name the individuals who would work your engagements in the proposal. If a credential is not shown on this site, we do not hold it.
Tell us what your SOC pipeline looks like.
Engagement count, report types, criteria in scope, and target issuance dates. We will tell you what we can absorb, what it costs, and which credentials the assigned team holds.