A SOC report only counts
if a CPA firm signs it.
Readiness tools can prepare you for an audit. Under AICPA standards, only a licensed CPA firm can examine your controls and issue the report your customers are asking for. That examination is our practice.
AICPA
Which report is your customer actually asking for?
Most requests arrive as "send us your SOC report" with no detail. The right answer depends on who is asking and what they need to rely on.
Type I tests whether your controls are designed properly on one date. Type II tests whether they actually operated over a period, usually three to twelve months. Buyers who read reports carefully want Type II — but a Type I issued now buys you the room to get there.
Talk it through →Three practices that keep handing evidence to each other.
A pen test finding becomes audit evidence. A control gap becomes a remediation plan. Nothing gets explained twice to three different vendors.
Audit and Attestation
The signed work: SOC 1, SOC 2 and SOC 3 examinations, plus ISO 27001 and 27701 internal audit and certification support. We scope to the criteria your buyers named, not to a maximal checklist.
Security & privacy
Penetration testing, risk assessments, HIPAA security risk analysis and privacy program work — sequenced so findings are remediated before the observation window opens, not during it.
Accounting & tax
US GAAP statements, month-end close, payroll, and federal and multi-state filings. Useful when the same team that audits your controls also understands how your books are actually kept.
How an examination actually runs.
Five stages under AICPA attestation standards, with the evidence requests batched so your team is never blocked twice.
Scoping call
A call with the practitioner who would lead the work, for as long as it takes. You leave with a scope, a timeline and a fee.
Planning & walkthroughs
We walk through each process with your owners, document the system description and agree the evidence for every control.
Assertion & period
Management signs its written assertion, the description is finalized and the reporting period is fixed.
Fieldwork & testing
Samples selected and tested against each control, with results and any exceptions discussed as we go.
Report & next cycle
Signed report, a summary your sales team can send, and next year's dates in the calendar already.
Small enough to answer the phone. Licensed to issue the report.
Assurion Services LLC is a certified public accounting firm based in Cheyenne, Wyoming. We are deliberately small, and take on the number of examinations the firm can run properly — which is why the people who scope your engagement are the people who finish it. Reports are issued in the firm’s name.
You meet your engagement lead before the letter is signed, and the same team stays on the work until the report is issued.
Where SOC 2, HIPAA and ISO 27001 ask for the same control, we test it once and report it separately — which is cheaper and less disruptive than three engagements.
We would rather publish credentials that can be verified than a client count that cannot. Ask at scoping and we will introduce you to clients in your sector.
Ask for references →Deliverables, not a portal login.
Everything below is included in a standard examination. Nothing here is an upsell.
How we price.
Every engagement is quoted individually and in writing. We do not work from a rate card, because the fee for an examination is driven by scope rather than by a product line — so here is exactly what moves it, and exactly how you get your number.
Submit a service request
Tell us what your buyer or your client's auditor has asked for. Nothing is payable and no card details are taken.
Scoping call
We work through the drivers above with the practitioner who would lead the work.
Written fixed-fee proposal
A single fixed fee in US dollars, with the scope, deliverables and timeline it covers, and what would change it.
Engagement letter, then invoice
You are invoiced only after you sign, and only for the fee stated there. No amount is ever charged before that point.
We do not publish a rate card because these are examinations, not products — two firms asking for the same report can differ several-fold in the work required, and a headline number would mislead one of them. What we do commit to: a fixed fee agreed in writing before any work starts, quoted in US dollars and exclusive of applicable taxes, held for the scope described, with any change agreed in writing before it is incurred. No subscriptions and no automatic renewals.
Payment terms, refunds and cancellation are set out in our fees, payment, refunds and cancellation policy and terms of service. Please read both before submitting a request or making a payment.
Anonymized at the client's request.
We will introduce you to referenceable clients in your sector during scoping.
Our previous auditor sent a 400-line evidence request and disappeared for six weeks. Assurion walked our processes with us first, batched the requests, and the one exception in our report came with wording we could actually explain to a prospect.
The things people ask on the first call.
If yours is not here, email us. We answer within one business day and we will tell you if we are not the right firm for the work.
contact@assurionservices.comWe already use a compliance platform. Do we still need you?
Yes, and the two work well together. Platforms collect evidence and monitor controls; under AICPA standards the examination and the report itself must come from an independent licensed CPA firm. If you are already on a platform, tell us which one — we work from its exports rather than asking you to re-gather everything.
A customer needs a report next month. Is that possible?
Sometimes, with a Type I. Type II requires an observation window of at least three months, so it cannot be compressed honestly. The usual move is a Type I to unblock the deal, then a Type II covering the following period. Any firm promising a Type II in weeks is describing something a careful reviewer will reject.
What happens if you find something serious?
You hear it from us as soon as we see it, during walkthroughs or testing rather than at the end. What we cannot do is leave a known deficiency out of the report — our independence is the only reason the report is worth anything to your customer. An exception is not fatal; it gets described with context and with management’s response beside it.
Can you do the readiness work and the audit?
We can help you get ready and we can examine you, but we keep the roles separate and we will not design a control and then issue an opinion on it. Where that line falls depends on the engagement — we set it out in writing before you sign, so there is no independence question later.
How much of our engineers' time will this take?
For a first SOC 2, budget a few hours a week during fieldwork for one technical owner, concentrated in two or three batched evidence rounds rather than a continuous drip. Second cycles are materially lighter because the control matrix and most evidence sources carry over.
Is a SOC 2 a certification?
No — and reviewers notice when a vendor says it is. SOC 2 is an attestation: a CPA firm examines your controls and issues an opinion for a stated period. ISO 27001 is a certification, issued by an accredited body. If your buyer used the word loosely, we will help you work out which one they actually need.
Written for the person doing the work.
How to read the exceptions section of a SOC 2 report
Not every exception is a problem. Here is how experienced reviewers weigh them.
Read →Choosing trust services criteria without over-scoping
Security is required. The other four are a decision, and each one adds cost.
Read →When your client's auditor asks for a SOC 1
What complementary user entity controls are, and why they end up in your report.
Read →