How are SOC 1 and SOC 2 different?
SOC 1 addresses controls at a service organization that are relevant to its customers’ internal control over financial reporting. SOC 2 addresses controls against the applicable Trust Services Criteria, covering security and other categories selected for the engagement. The appropriate report and scope depend on the services involved and the needs of report users.
CyberVault helps organizations prepare for the agreed scope. We keep readiness work aligned with the independent examining firm’s requirements rather than treating every SOC engagement as the same checklist.
What does readiness support involve?
Readiness begins with understanding the services, systems, control owners and evidence already in place. We review documentation, identify gaps and help connect each control with an owner and a repeatable way to demonstrate that it operates. Policies and narratives should describe actual practices, not an idealized version of the environment.
The work can include an evidence inventory, control documentation review, remediation planning and preparation for auditor requests. Where controls depend on vendors or customer responsibilities, those dependencies need to be understood and documented within the agreed scope.
How do you help with evidence?
We help teams organize supporting records, track requests and identify missing or inconsistent documentation. Evidence should be relevant to the control and period being evaluated. An organized request tracker can make it easier to see which items are ready, which need follow-up and who owns the response.
Automation may support collection and organization where appropriate, but it does not replace judgment about whether the evidence supports the control. Sensitive material is handled through an agreed process with access limited to authorized participants.
What do we receive?
Depending on scope, deliverables can include a readiness gap assessment, control and evidence inventory, remediation tracker, control-owner guidance and management briefings. These outputs help leadership understand unresolved issues and the effort needed before or during an examination.
We can support follow-up by reviewing remediation evidence and clarifying outstanding requests. The goal is an accountable readiness process, with known limitations documented and priorities visible to the people responsible for resolving them.
Does CyberVault issue the SOC report?
CyberVault provides readiness and advisory support. The formal SOC examination and report are performed by an independent CPA firm. Our support does not guarantee an audit outcome, and the examining firm determines the work and evidence required for its engagement.
What experience informs the work?
CyberVault’s leadership brings extensive SOC 1 and SOC 2 audit experience, former CISO and IT Audit Director roles, and more than 30 years of enterprise technology and security experience. Leadership qualifications include a Master of Science in Cybersecurity and CISSP, CISA and CISM credentials.
That background connects audit preparation with security operations, governance and management decision-making. We focus on helping control owners understand what they need to maintain, demonstrate and improve.
How do we begin?
Tell us whether this is a first examination, a recurring audit or a targeted readiness issue. Useful starting points include the intended scope, current documentation, any known gaps and the examining firm’s schedule. We agree on responsibilities and a realistic plan after understanding those conditions; there is no universal timeline that fits every organization.
Further reading: AICPA resources on SOC reporting.
