SOC 1 · SOC 2 · SOC 3 · ISO 27001 · HIPAA

A SOC report only counts
if a CPA firm signs it.

Readiness tools can prepare you for an audit. Under AICPA standards, only a licensed CPA firm can examine your controls and issue the report your customers are asking for. That examination is our practice.

Licensed to issue
One team, start to finish
Scoped, not templated
A Assurion
Independent service auditor's report
SOC 2 Type II
Description of the system and the suitability of the design and operating effectiveness of controls.
Period covered1 Jan – 31 Dec
Criteria in scopeSecurity, availability
OpinionUnqualified
Issued in the firm's name
AT-C 205
AICPA
Frameworks we work in
SOC 1 SOC 2 SOC 3 ISO 27001 ISO 27701 HIPAA HITRUST GDPR US GAAP
Start here

Which report is your customer actually asking for?

Most requests arrive as "send us your SOC report" with no detail. The right answer depends on who is asking and what they need to rely on.

SOC 1

You touch their numbers.

Controls over financial reporting, for the auditors who rely on your processing.

Who asks Controllers, CFOs, their external auditors
Typical of Payroll, payments, claims, loan servicing, BPO
Driven by Their audit calendar, not a sales cycle
How a SOC 1 runs →
SOC 2 Most requested

You hold their data.

An examination of your security controls against the trust services criteria.

Who asks Security teams, procurement, vendor risk
Typical of SaaS, fintech, health tech, infrastructure
Driven by A deal, a renewal or a diligence deadline
See how a SOC 2 runs →
SOC 3

You want it public.

A general-use summary of the same examination, with no NDA required.

Who asks Marketing, sales, self-serve prospects
Typical of Product-led companies with high inbound volume
Driven by Wanting to answer once, publicly
Add a SOC 3 →
Type I or Type II

Type I tests whether your controls are designed properly on one date. Type II tests whether they actually operated over a period, usually three to twelve months. Buyers who read reports carefully want Type II — but a Type I issued now buys you the room to get there.

Talk it through →
What we do

Three practices that keep handing evidence to each other.

A pen test finding becomes audit evidence. A control gap becomes a remediation plan. Nothing gets explained twice to three different vendors.

Audit and Attestation

The signed work: SOC 1, SOC 2 and SOC 3 examinations, plus ISO 27001 and 27701 internal audit and certification support. We scope to the criteria your buyers named, not to a maximal checklist.

SOC 1 / 2 / 3 ISO 27001 Readiness Bridge letters
Scope an engagement →

Security & privacy

Penetration testing, risk assessments, HIPAA security risk analysis and privacy program work — sequenced so findings are remediated before the observation window opens, not during it.

Pen testing HIPAA GDPR Policy design
Book a risk review →

Accounting & tax

US GAAP statements, month-end close, payroll, and federal and multi-state filings. Useful when the same team that audits your controls also understands how your books are actually kept.

US GAAP Multi-state Payroll Close support
Get a fee estimate →
How it works

How an examination actually runs.

Five stages under AICPA attestation standards, with the evidence requests batched so your team is never blocked twice.

01 · Week 1

Scoping call

A call with the practitioner who would lead the work, for as long as it takes. You leave with a scope, a timeline and a fee.

02 · Weeks 2–4

Planning & walkthroughs

We walk through each process with your owners, document the system description and agree the evidence for every control.

03 · Before testing

Assertion & period

Management signs its written assertion, the description is finalized and the reporting period is fixed.

04 · 8–10 weeks

Fieldwork & testing

Samples selected and tested against each control, with results and any exceptions discussed as we go.

05 · Issued

Report & next cycle

Signed report, a summary your sales team can send, and next year's dates in the calendar already.

The firm

Small enough to answer the phone. Licensed to issue the report.

Assurion Services LLC is a certified public accounting firm based in Cheyenne, Wyoming. We are deliberately small, and take on the number of examinations the firm can run properly — which is why the people who scope your engagement are the people who finish it. Reports are issued in the firm’s name.

One engagement lead, start to finish

You meet your engagement lead before the letter is signed, and the same team stays on the work until the report is issued.

Tested once, reported to each standard

Where SOC 2, HIPAA and ISO 27001 ask for the same control, we test it once and report it separately — which is cheaper and less disruptive than three engagements.

CPA
Licensed public accountants — required to issue any SOC report
Peer review
Enrolled in the AICPA Peer Review Program
CISA
Certified information systems auditors on every IT engagement
1 day
Our reply standard on any inbound inquiry

We would rather publish credentials that can be verified than a client count that cannot. Ask at scoping and we will introduce you to clients in your sector.

Ask for references →
What you receive

Deliverables, not a portal login.

Everything below is included in a standard examination. Nothing here is an upsell.

PDF

The signed report

Full examination report under our firm's name, formatted the way vendor-risk teams expect to read it.

In report

Exceptions in plain language

Each exception sits next to its context and management's response, so a reader can weigh it.

XLSX

Your control matrix, back in your hands

The matrix your team maintained through fieldwork, returned at close-out with each control tied to the criteria it was tested against.

XLSX

A framework crosswalk

Where the Trust Services Criteria overlap with ISO 27001 and NIST 800-53, so you can see what your next audit won't make you rebuild.

DOCX template

Bridge letter template

The wording your team issues on your own letterhead between report periods, so you aren't drafting it the day a prospect asks.

At close-out

Next year's calendar

Observation window and fieldwork dates agreed at close-out, so renewal never becomes a scramble.

Pricing

How we price.

Every engagement is quoted individually and in writing. We do not work from a rate card, because the fee for an examination is driven by scope rather than by a product line — so here is exactly what moves it, and exactly how you get your number.

What determines your fee

Systems and locations in scope

How many products, environments and physical sites the report covers.

Criteria or control objectives

How many trust services criteria you select, or how many control objectives your SOC 1 states.

Report type and period

A point-in-time Type I is materially less work than a Type II across a 3–12 month period.

Subservice organizations

Whether third parties are carved out or tested inside your report.

State of your evidence

Whether controls are already documented and monitored, or need to be established first.

First cycle or renewal

Renewals cost materially less, because the control matrix and evidence sources carry over.

How you get your price
01 · No charge

Submit a service request

Tell us what your buyer or your client's auditor has asked for. Nothing is payable and no card details are taken.

02 · No charge

Scoping call

We work through the drivers above with the practitioner who would lead the work.

03 · Within 3 business days

Written fixed-fee proposal

A single fixed fee in US dollars, with the scope, deliverables and timeline it covers, and what would change it.

04 · First payment

Engagement letter, then invoice

You are invoiced only after you sign, and only for the fee stated there. No amount is ever charged before that point.

We do not publish a rate card because these are examinations, not products — two firms asking for the same report can differ several-fold in the work required, and a headline number would mislead one of them. What we do commit to: a fixed fee agreed in writing before any work starts, quoted in US dollars and exclusive of applicable taxes, held for the scope described, with any change agreed in writing before it is incurred. No subscriptions and no automatic renewals.

Payment terms, refunds and cancellation are set out in our fees, payment, refunds and cancellation policy and terms of service. Please read both before submitting a request or making a payment.

In a client's words

Anonymized at the client's request.

We will introduce you to referenceable clients in your sector during scoping.

Our previous auditor sent a 400-line evidence request and disappeared for six weeks. Assurion walked our processes with us first, batched the requests, and the one exception in our report came with wording we could actually explain to a prospect.

HD
Head of Engineering
B2B SaaS · second SOC 2 Type II cycle
Questions

The things people ask on the first call.

If yours is not here, email us. We answer within one business day and we will tell you if we are not the right firm for the work.

contact@assurionservices.com
We already use a compliance platform. Do we still need you?

Yes, and the two work well together. Platforms collect evidence and monitor controls; under AICPA standards the examination and the report itself must come from an independent licensed CPA firm. If you are already on a platform, tell us which one — we work from its exports rather than asking you to re-gather everything.

A customer needs a report next month. Is that possible?

Sometimes, with a Type I. Type II requires an observation window of at least three months, so it cannot be compressed honestly. The usual move is a Type I to unblock the deal, then a Type II covering the following period. Any firm promising a Type II in weeks is describing something a careful reviewer will reject.

What happens if you find something serious?

You hear it from us as soon as we see it, during walkthroughs or testing rather than at the end. What we cannot do is leave a known deficiency out of the report — our independence is the only reason the report is worth anything to your customer. An exception is not fatal; it gets described with context and with management’s response beside it.

Can you do the readiness work and the audit?

We can help you get ready and we can examine you, but we keep the roles separate and we will not design a control and then issue an opinion on it. Where that line falls depends on the engagement — we set it out in writing before you sign, so there is no independence question later.

How much of our engineers' time will this take?

For a first SOC 2, budget a few hours a week during fieldwork for one technical owner, concentrated in two or three batched evidence rounds rather than a continuous drip. Second cycles are materially lighter because the control matrix and most evidence sources carry over.

Is a SOC 2 a certification?

No — and reviewers notice when a vendor says it is. SOC 2 is an attestation: a CPA firm examines your controls and issues an opinion for a stated period. ISO 27001 is a certification, issued by an accredited body. If your buyer used the word loosely, we will help you work out which one they actually need.

Get started

Request a service.

You will speak with the practitioner who would lead the work. Bring the request your customer sent and you will leave with a scope, a timeline and a written fixed-fee proposal.

Phone · Mon–Fri, 9–6 ET
+1 (307) 393-9419
Corporate office
Suite 413, 1603 Capitol Ave
Cheyenne, WY 82001
Website Inquiry Form