| SOC for Cybersecurity | SOC 2 | |
| Scope: | Entire Cyber Security Risk Management Program for an organization | Scoped to a specific service organization, business unit within the service organization, or specific service line(s). |
| Baseline for Evaluation: | Can rely on any major security framework (ISO/NIST) | Limited to the Trust Service Criteria (note the 2017 TSC are aligned to COSO) |
| Intended Audience: | Broad audience - this is a general use report and may be acceptable/beneficial for many parties | Specific audience - this is a restricted report usually intended for the customers utilizing the service from the service organization |
| Third party risk: | Must be addressed in the report – cannot carve out – if a third party has access to company data, they must be included in the report | Can carve out sub-service organizations, but must communicate due diligence and vendor management processes in place |
| Sensitive Information: | Does not include the Controls Matrix section because this is very sensitive; audit work is completed but not included in the report | Controls matrix is included in the report and may include sensitive information (thus a restricted report) |
| Distribution: | General distribution | Restricted distribution |