Baker Tilly’s webinar, SOC 2+: Enhancing SOC 2 compliance with additional frameworks, took a deep dive into extending SOC 2 compliance by integrating frameworks like (Health Information Portability Accountability Act (HIPAA), International Organization for Standardization (ISO), Health Information Trust Alliance (HITRUST) and National Institute of Standards and Technology (NIST). We hope the questions from attendees and our responses are insightful for everyone.
SOC 2 and SOC 2+ reports
If a company is Sarbanes-Oxley (SOX) compliant as part of an annual independent audit, will a SOC 2 or SOC 2+ report add any value?
- It absolutely can and does. SOX is primarily focused on internal controls that can impact your financial reporting, meaning SOX controls are often “business” or “operational” in nature. Technical controls do come into play, but generally only to the extent that they relate to your financial reporting. SOC 2, on the other hand, still relates to your internal control environment but it is over the security, availability, confidentiality, processing integrity and/or privacy of the systems specific to your customers’ data.





