Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

An Introduction to SOC 2 Reports

·27 min·5 clips
The episode treats SOC 2 as a practical assurance report that can support compliance and still be useful to the business. Neil Beggin introduces the topic by asking what a SOC 2 report actually is and why it has become so common. Stephen Ursillo explains that SOC 1 and SOC 2 are both AICPA attestation reports used to assess reporting on controls tied to service organizations. He separates SOC 3 from SOC 2 by noting that SOC 3 is meant for broader distribution and public consumption. That difference matters because SOC 3 stays at a higher level, while SOC 2 goes deeper into an organization’s policies, procedures, users, people, process, and technology to show how service commitments are met. The discussion keeps returning to what makes the report useful for customers and stakeholders. The speakers argue that a well-run SOC 2 examination can support compliance needs while also helping clients move through an efficient audit process. They also note that the report format is fairly standardized, which helps users know what to expect. The first section covered is the independent auditor’s report. From there, the conversation moves through the scope of the engagement and the way subservice organizations and user entities may be referenced when relevant. The auditor’s responsibilities are explained alongside management’s responsibilities. That boundary is treated as a central part of the report’s logic. Management owns the design and performance of internal controls. The auditor’s role is to assess those controls and report on them. The episode then walks through the remaining required sections in broad terms. It notes that the report includes a description of the system and the controls in place. It also points listeners toward the criteria and testing elements that shape the final deliverable. The structure is presented as steady, practical, and built to make the report readable across organizations. The tone stays calm and professional throughout. The speakers take time with the basics, which makes the material easier to follow for listeners who are new to SOC reporting. They also stress that getting started matters, not just passing the examination. The episode closes by tying the report back to operational discipline, the right people carrying out the process, and communication to leadership and stakeholders.

As heard by us

A clear SOC 2 introduction that makes a compliance topic easy to follow.

This episode offers a clean, grounded introduction to SOC 2. It explains what the framework is, how it differs from SOC 1 and SOC 3, and why organizations and customers pay attention to it.

Read the full review in PlayNext →

Why you'd press play

If SOC 2 keeps showing up in meetings, start here.

Read the full recommendation in PlayNext →
Listen to the show on