[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-191470-105":53,"doc-detail-191470-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","understanding-soc-reports","Understanding SOC Reports","","This document provides an overview of SOC (System and Organization Controls) reports, essential for businesses to demonstrate their internal controls to stakeholders. It outlines various types of SOC reports, including SOC 1, SOC 2, and SOC 3, detailing their respective scopes and purposes. The document explains that SOC 1 reports focus on controls relevant to a user entity's internal control over financial reporting (ICFR), while SOC 2 and SOC 3 reports address controls related to information security, availability, processing integrity, confidentiality, and privacy. It emphasizes the importance of these reports for building trust and ensuring compliance in today's increasingly digital and interconnected business environment. The content further elaborates on the criteria used for each report type, such as the Trust Services Criteria (TSC) for SOC 2. Understanding these reports is crucial for service organizations that handle customer data or provide services impacting financial reporting, enabling them to assure their clients and partners of the robustness of their control environments.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/understanding-soc-reports/191470/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/understanding-soc-reports/191470.png","ImageObject",442,249,{"name":88,"@type":89},"Theodore","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-10-04","2026-09-03",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",6,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What are SOC reports?","Question",{"text":109,"@type":110},"SOC reports, or System and Organization Controls reports, are internal control reports provided by a service organization to its customers. They provide assurance about a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy of the system used by the organization to process users' data; or controls at a service organization that are relevant to the user entities' internal control over financial reporting.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"What is the main difference between SOC 1 and SOC 2 reports?",{"text":114,"@type":110},"SOC 1 reports focus on controls relevant to a user entity's internal control over financial reporting (ICFR). SOC 2 reports, on the other hand, focus on a broader set of criteria related to information security, availability, processing integrity, confidentiality, and privacy, as defined by the Trust Services Criteria (TSC).",{"name":116,"@type":107,"acceptedAnswer":117},"Who typically uses SOC reports?",{"text":118,"@type":110},"SOC reports are used by service organizations to demonstrate the effectiveness of their internal controls to their clients (user entities) and stakeholders. Clients of these service organizations rely on these reports to assess the risks associated with outsourcing services.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},191470,1789968258,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":32,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":140,"read_time":40},7971461740886,"https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2","| Software as a Service (SaaS) | Social Media / Content Tagging and Aggregators | Online Fulfillment |\n| --- | --- | --- |\n| Application Service Providers (ASP) | Data Center and Co-Location Providers | Rebate Processing / Online and Mail |\n| Credit Card Processing Platforms | Managed Services | Transportation Services |\n| Cloud Computing / Virtualization | Third Party Administrators (TPA) | Tax Processing and Filing Services |\n| Internet Service Providers (ISP) | Medical Billing | Payroll Services |\n| Web Design and Development | Print and Mail Delivery | Registered Investment Advisors (RIA) |\n| Web Hosting | Security as a Service | Financial Statement XBRL Tagging |","cbCaiq7zOlRnB5EW","https://ap.wps.com/l/cbCaiq7zOlRnB5EW","pdf",1823073,"English","# SOC Report Types\n## SOC 1 Reports\n## SOC 2 Reports\n## SOC 3 Reports\n# Criteria for SOC Reports\n## Trust Services Criteria (TSC)","[{\"question\":\"What are SOC reports?\",\"answer\":\"SOC reports, or System and Organization Controls reports, are internal control reports provided by a service organization to its customers. They provide assurance about a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy of the system used by the organization to process users' data; or controls at a service organization that are relevant to the user entities' internal control over financial reporting.\"},{\"question\":\"What is the main difference between SOC 1 and SOC 2 reports?\",\"answer\":\"SOC 1 reports focus on controls relevant to a user entity's internal control over financial reporting (ICFR). SOC 2 reports, on the other hand, focus on a broader set of criteria related to information security, availability, processing integrity, confidentiality, and privacy, as defined by the Trust Services Criteria (TSC).\"},{\"question\":\"Who typically uses SOC reports?\",\"answer\":\"SOC reports are used by service organizations to demonstrate the effectiveness of their internal controls to their clients (user entities) and stakeholders. Clients of these service organizations rely on these reports to assess the risks associated with outsourcing services.\"}]","Understanding SOC Reports | PDF",1788408760]