by Assurion Services | Sep 2, 2026 | SOC 2
Somewhere in the middle of almost every SOC report there is a table that readers skim past on their way to the test results. It lists things the customer is expected to do. Those are complementary user entity controls, and they are the part of the report that quietly...
by Assurion Services | Sep 2, 2026 | SOC 2
Your SOC 2 Type 2 covers 1 January to 31 December. It is now March, a prospect is in a security review, and their vendor risk team wants to know what happened in the eleven weeks since the period ended. The usual answer is a bridge letter, and it will probably satisfy...
by Assurion Services | Sep 2, 2026 | SOC 2
If your platform runs on a cloud provider, uses a managed data centre, or hands part of the service to a specialist partner, your SOC report has to say something about them. You have two options for how. The carve-out method names the vendor, describes what you rely...
by Assurion Services | Sep 2, 2026 | Compliance Readiness
The single biggest driver of a painful SOC 2 fieldwork is not the number of controls. It is whether the evidence already exists in a form the auditor can use, or whether your team has to go and manufacture it after the period has closed. Reconstructed SOC 2 evidence...
by Assurion Services | Aug 26, 2026 | SOC 1
If an email lands from your customer’s external auditor asking for your SOC 1 report, something specific has happened: they have concluded that your service is part of their client’s internal control over financial reporting, and they cannot audit what...