By
Cera Adams
February 21, 2022
•
1
min read

The rapid advances in technology have created opportunities for businesses to realize new efficiencies and increased profitability. The ease of use, transparency, and functionality available has led many to embrace outsourcing as a solution to managing non-essential functions. Not only does this save money and minimize waste, but it also allows management to focus on core business processes. As more turn to outsourcing, it has become important to understand the data risk management policies protecting shared customer data. Typically, this can be demonstrated through a System and Organization Controls (SOC) report, SOC 1 or SOC 2, depending on specifics. For those who need to comply with additional frameworks, it can be costly to undergo both a SOC report and additional independent testing. Based on this, the AICPA created the new SOC 2+ report which incorporates multiple frameworks and standards in the assurance reporting process. To help clients, prospects, and others, OCD Tech has provided a summary of the key details below.
SOC 2 report assesses additional controls related to each framework beyond the AICPA’s Trust Service Principles (TSP). This includes other regulatory frameworks such as PCI-DSS and HIPAA.
The examples listed below are the additional frameworks examined during a SOC 2+ engagement which have formal mappings developed with a SOC report as outlined by the AICPA.
SOC 2+ reports provide a streamlined method, for service organizations and outsourced providers to concurrently demonstrate compliance with TSPs and industry specific frameworks. If you have questions about the information outlined above, or need assistance with a SOC 2+ Report, OCD-Tech can help. For additional information call us at 844-OCD-Tech or click here to contact us. We look forward to speaking with you soon.

Audit. Security. Assurance.
IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.
Contact Info
OCD Tech
25 BHOP, Suite 407, Braintree MA, 02184
844-623-8324
https://ocd-tech.com
Follow Us
Videos
Check Out the Latest Videos From OCD Tech!
Services
SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®
IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review
IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO