Webinar
SOC 2+: Enhancing SOC 2® compliance with additional frameworks
Feb. 26, 2025 · Authored by Garrett Gosh, Kelly Bourbon, Jacob Mahkorn
Cybersecurity risks and technological threats become more evolved – and more dangerous – every day, putting questions surrounding client data security, transactional process integrity and data availability during potential downtimes at the heart of successful risk management. System and Organizational Controls (SOC) 2 and SOC 2+ examinations can help address these critical issues.
In this recent webinar, Baker Tilly SOC specialists broke down SOC 2+ preparedness, pros, cons and authoritative guidance use cases.
A SOC 2 refresher
As SOC 2+ builds upon the original framework of SOC 2 with additional components, it is important to first begin with an understanding of SOC 2 and how the two differ.
SOC 2 is a framework that evaluates a service organization’s ability to protect data belonging to its user entities (i.e., customers). It focuses on the security, availability, confidentiality, processing integrity and privacy of the customer data in the system. This evaluation is performed by an independent Certified Public Accountant (CPA) firm which provides a reasonable assurance opinion over the design, implementation and operating effectiveness of the internal controls.
A SOC 2 is:
- An examination providing reasonable assurance
- Intended to promote trust between a service organization and its user entities
- Inclusive of an opinion provided by an independent CPA firm
And a SOC 2 is not:
- Absolute assurance
- A guarantee that commitments made to customers are met
- A one-size-fits-all report
- A replacement for internal controls