Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Learning Center
Learning Center
Articles
Articles
Whitepapers
Whitepapers
Case Studies
Case Studies
Events & Live Webinars
Events & Live Webinars
On-Demand Webinars
On-Demand Webinars
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility

Can a SOC 1 be leveraged for a SOC 2?

SOC

Technology based service organizations have seen the SOC 2 report gain immense traction over the past couple years.

As a result, service organizations that have successfully completed SOC 1 examinations are now being asked [by their clients] to undergo a SOC 2 examination as well. Performing an additional examination can seem daunting, yet essential to maintain and potentially win new customers.

Fortunately many of the controls between the SOC 1 and SOC 2 may overlap. In these instances, the service auditor should be able to leverage the documents for certain controls/criteria used to complete the SOC 1 for use in the SOC 2. The necessary work required to complete the additional report will be incremental (assuming the time periods overlap).

New Call-to-action

About TERRY O'BRIEN

Terry O’Brien is a Senior Manager with Schellman. He is responsible for the management and execution of engagements across multiple service lines. Since joining in 2013, Terry has participated in business development activities and supported practice development initiatives via his participation in both the SOC and Cybersecurity Task Force. Terry has 10 years of IT compliance and attestation experience. Prior to his time at Schellman, he worked in the Advisory Services division of Grant Thornton in Chicago, Illinois.