By:
Chad Goubeaux
August 27th, 2025
If you’re considering a SOC 2 audit, be it due to a customer request or to strengthen your security posture, you may already understand that this examination will include an evaluation of your product or service on a more operational and security-oriented level. You may even already grasp that during a SOC 2, your scope will be evaluated against a set of trust services criteria (TSC) that provide the backbone of the assessment. But what are the trust services categories, the criteria that make up each category, and which ones will you actually need for your SOC 2 audit? At Schellman, we have over two decades of experience in SOC 2 examinations, and we want to help you navigate what can be a complex process. Read on to discover what inclusion of each category will mean for your SOC 2 examination. From there, we’ll give you some guidelines for your internal conversations when making your choice. Afterwards, you’ll be that much closer to pinning down what you need from your upcoming SOC 2 report.
SOC Examinations | Artificial Intelligence | SOC 2
By:
Avani Desai
August 4th, 2025
Have you read the recently released America’s AI Action Plan yet? If so, you know that it’s full of ambitious goals to strengthen the country’s leadership in artificial intelligence. For me, one part in particular stood out immediately, the White House issued a clear call to action to the data center industry.
Cybersecurity Assessments | Cloud Computing | SOC Examinations | SOC 2
By:
Nate Kocan
April 29th, 2025
As cloud services continue to expand globally, service providers are increasingly expected to demonstrate compliance with a variety of frameworks depending on where their customers operate. Two commonly requested assurance reports include the American Institute of Certified Public Accountants (AICPA) SOC 2 attestation report and the German Federal Office for Information Security (Bundesmat fur Sicherheit in der Informationstechnik, or “BSI”) Cloud Computing Compliance Criteria Catalogue (C5) attestation report.
SOC Examinations | Audit Readiness | SOC 2
By:
Hunter Meacham
February 4th, 2025
Opting for a readiness assessment ahead of your SOC 2 examination is—while optional—a beneficial extra step when seeking compliance. Do you remember taking a practice test while preparing for an exam in school? Such a move could never hurt your chances of success. That being said, there are some things you should understand ahead of your readiness assessment that can help demystify your experience.
ISO Certifications | SOC Examinations | SOC 2 | ISO 27001
By:
KRISTEN WILBUR
September 10th, 2024
As they’re now two of the most popular compliance initiatives in the world, many organizations often choose to pursue either SOC 2 or ISO 27001, and others are tackling both. In fact, there are strategic benefits to be gained in undergoing both a SOC 2 examination and achieving ISO 27001 certification, especially as you can do both at the same time.
By:
RYAN MACKIE
June 13th, 2024
As the need for SOC 2 examinations continues to grow domestically as well as internationally, many organizations now either find themselves taking on more and more assessments or trying to appease a client base that requires a SOC 2 examination when the typical product or platform approach may not apply. When these situations crop up, we are seeing more adoption of what’s known as an enterprise services SOC 2 examination.
By:
Chad Goubeaux
January 18th, 2022
We’ve provided all types of SOC services since the emergence of the brand back in 2011, and over the years, we’ve often received questions specifically about the difference between SOC 2 and SOC 3 reports. Whether or not you work with us on these services, you deserve to know which option is best for your organization and why.
Healthcare Assessments | SOC Examinations | HITRUST | SOC 2
By:
Brody Price
May 1st, 2017
HITRUST Certification is a globally recognized program that validates an organization’s compliance with the HITRUST Common Security Framework (CSF). An alternative to obtaining a HITRUST CSF Certification is the SOC 2 + HITRUST report, which serves as a collaboration between HITRUST and the AICPA.