SOC 2 Audit Reports

Organizations that store, process, or transmit customer data are increasingly expected to demonstrate that their information security controls are properly designed and operating effectively. Packer Thomas performs SOC 2 examinations to help organizations validate their control environment, strengthen customer trust, and satisfy growing security and compliance expectations.

Whether you’re pursuing your first SOC 2 report or preparing for an annual examination, our professionals guide your organization through the engagement while helping you strengthen security practices and demonstrate your commitment to protecting sensitive information.

Strengthen Security

Demonstrate strong controls to protect customer data and systems.

Build Customer Confidence

Show customers and partners you take security, availability, and privacy seriously.

Improve Operations and Compliance

Identify risks and strengthen controls to improve efficiency and reduce exposure.

Gain a Competitive Advantage

Stand out in the marketplace and streamline vendor security reviews.

IT professional monitoring security systems and dashboards during a SOC 2 audit report assessment.

What Is a SOC 2 Report?

A SOC 2 report is the result of an independent SOC 2 audit performed under standards established by the American Institute of Certified Public Accountants (AICPA). A SOC 2 audit evaluates an organization’s controls related to security, availability, processing integrity, confidentiality, and privacy using the Trust Services Criteria. These controls help organizations demonstrate their commitment to protecting customer data and maintaining secure business operations.

SOC 2 reports are commonly requested by customers, business partners, and vendors before sharing sensitive information or entering into service agreements. According to the AICPA’s guidance on SOC 2 reports, these examinations are designed for organizations that store, process, or transmit customer information.

Who Needs a SOC 2 Report?

Organizations responsible for protecting customer information often benefit from undergoing a SOC 2 audit. While a SOC 2 examination is generally not required by law, many customers, business partners, and procurement teams expect service providers to demonstrate that appropriate security controls are in place through an independent SOC 2 audit.

Organizations that commonly undergo SOC 2 audits include:

  • Software-as-a-Service (SaaS) providers
  • Cloud service providers
  • Managed service providers (MSPs)
  • Data centers
  • Healthcare technology companies
  • Cybersecurity firms
  • Payment processing companies
  • Business software providers
  • Organizations that host, process, or store customer data

While technology companies are among the most common organizations pursuing a SOC 2 audit, Packer Thomas also works with organizations in manufacturing, financial services, healthcare and medical practices, construction, nonprofit, wholesale and distribution, and other industries that store, process, or transmit sensitive customer information.

A successful SOC 2 audit results in a SOC 2 report that can streamline vendor security reviews, satisfy contractual requirements, strengthen customer confidence, and provide a competitive advantage during the sales process.

SOC 2 Type I Reports vs. SOC 2 Type II Reports

Both SOC 2 report types evaluate controls related to the Trust Services Criteria, but they differ in what is examined.

Report Type What It Evaluates Best For
SOC 2 Type I
Reviews the design of controls at a specific point in time.
Organizations obtaining their first SOC 2 report or responding to immediate customer requirements.
SOC 2 Type II
Reviews both the design and operating effectiveness of controls over a defined review period.
Organizations demonstrating ongoing security and operational effectiveness to customers and business partners.

Many organizations begin with a Type I examination before transitioning to a Type II report as their control environment matures.

Which SOC Report Is Right for You?

Not every organization needs the same SOC report. The right examination depends on the services you provide and what your customers need to verify.

Report Best For Common Industries & Organizations Primary Focus
Service organizations that affect their customers’ financial reporting
Payroll providers, benefits administrators, fintech companies, investment administrators, claims processors, outsourced accounting providers
Internal controls over financial reporting
SOC 2
Organizations that store, process, or transmit customer data
SaaS companies, cloud service providers, managed IT providers, data centers, healthcare technology, cybersecurity firms
Security, availability, processing integrity, confidentiality, and privacy
Organizations that want to publicly demonstrate their commitment to security
Technology companies, SaaS providers, cloud platforms, managed service providers, and other businesses that have completed a SOC 2 examination
Public-facing summary of a SOC 2 report without detailed testing results

Not sure which report fits your organization? Our professionals can help determine whether a SOC 1 Report, SOC 2 Report, or SOC 3 Report best aligns with your customers’ expectations and compliance requirements.

What Are the Trust Services Criteria?

Every SOC 2 examination is based on the AICPA’s Trust Services Criteria, which establish the framework used to evaluate an organization’s controls over customer data and information systems. Depending on the scope of the engagement, your examination may include one or more of these criteria.

Trust Services Criterion What It Evaluates
Security
Protection of systems and information against unauthorized access and other security threats.
Availability
Whether systems are available for operation and use as committed or agreed.
Processing Integrity
Whether system processing is complete, valid, accurate, timely, and authorized.
Confidentiality
Protection of confidential business information from unauthorized disclosure.
Privacy
Collection, use, retention, disclosure, and disposal of personal information in accordance with established commitments and privacy principles.

The Trust Services Criteria provide a flexible framework that allows organizations to demonstrate the effectiveness of their security controls while addressing the specific risks associated with their services and technology environment.

Benefits of a SOC 2 Report

A SOC 2 report demonstrates that your organization has implemented controls to protect customer data and maintain secure operations. Beyond satisfying customer requests, a SOC 2 examination can improve internal processes, reduce business risk, and strengthen your organization’s reputation in the marketplace.

Benefit How Your Organization Benefits
Build Customer Trust
Demonstrates your commitment to protecting sensitive customer information.
Simplify Vendor Reviews
Reduces the time spent completing customer security questionnaires and due diligence requests.
Strengthen Security Controls
Identifies opportunities to improve policies, procedures, and operational controls.
Competitive Advantage
Helps differentiate your organization during sales and procurement processes.
Support Compliance Efforts
Complements other security and regulatory initiatives by validating your control environment.
Improve Risk Management
Provides independent insight into risks that could affect your systems and customers.

A well-executed SOC 2 examination not only helps satisfy customer expectations but also reinforces your organization’s long-term commitment to security, transparency, and operational excellence.

Why Choose Packer Thomas for SOC 2 Audit Reports?

A successful SOC 2 examination requires more than technical knowledge. It requires professionals who understand internal controls, business operations, information technology, and the expectations of customers, vendors, and stakeholders. At Packer Thomas, we work closely with organizations to provide practical guidance throughout the SOC 2 process while delivering an independent examination you can confidently share with customers.

Our professionals bring experience in audit, risk management, and technology consulting to help organizations strengthen their control environment before, during, and after the examination. Whether you’re pursuing your first SOC 2 report or maintaining annual compliance, we tailor our approach to your organization’s services, systems, and business objectives.

Additional services that often complement a SOC 2 engagement include:

Our SOC Team

Principal & Director of Information Technology Consulting

Areas of Expertise:

  • SOC Engagements
  • Acumatica – The Cloud ERP
  • Sage 300 & Sage CRM
  • Third Party Applications for Acumatica and Sage 300
  • Information Systems Security Reviews
  • System Evaluation and Implementation/Project Management
  • QuickBooks

Jeffrey R. Sheets, CPA

Consultant

Areas of Expertise:

  • Information Security Audits
  • PCI DSS Audit
  • Information Security Program Development
  • Cloud Security
  • GDPR, NIST 800-53, ISO 27001, and Hitrust

William Long, CISA, CISM, CGEIT, GSEC, GSNA, CSF, PCI QSA

Request Our Services

Name(Required)

FAQ

About Packer Thomas

Packer Thomas is a full-service CPA and business advisory firm serving businesses, nonprofit organizations, government entities, and individuals throughout Ohio and beyond. Since 1923, our professionals have provided practical guidance designed to help clients navigate complex financial, operational, technological, and regulatory challenges.

Our services include accounting and attest, tax consulting, client accounting services, business valuations, forensic accounting, IT consulting, and SOC examinations. By bringing together professionals from multiple disciplines, we provide coordinated solutions tailored to each client’s industry, goals, and risk environment.

With offices in Canfield and New Castle, Ohio, Packer Thomas combines the capabilities of an experienced advisory firm with responsive, personalized service. Contact us to learn how our team can help your organization strengthen internal controls, meet customer expectations, and prepare for a successful SOC 2 examination.