2017 Trust Services Criteria (With Revised Points of Focus – 2022)
SOC 2 readiness
Get your controls, evidence, and system description ready for a SOC 2 examination by an independent, licensed CPA firm that you select and engage directly.
Compliance
Compliance readiness for SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, and CMMC.
Readiness and formal assessment are different jobs, done by different organizations. Knowing which is which helps you plan the work, budget for both, and avoid paying for a “certificate” the program doesn’t recognize.
Getting ready: finding out where you stand and closing the gaps before anyone formally judges you.
The official outcome: a report, a certificate, or an assessment result that your customers, acquirer, or contracting officer relies on.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Each framework has its own formal outcome and its own rules about who may issue it. Versions and program status were last checked on .
| Framework | What it is | Formal outcome | Who can issue it | What Security Inspect does |
|---|---|---|---|---|
| SOC 2 | SOC 2 is an attestation report on a service organization's controls, issued by a licensed CPA firm after an examination and measured against the AICPA Trust Services Criteria. It isn't a certification. | SOC 2 Type 1 or Type 2 report (an attestation report, not a certification) | A licensed CPA firm, under AICPA attestation standards | SOC 2 readiness — preparation for an examination performed by an independent licensed CPA firm. |
| ISO/IEC 27001 | ISO/IEC 27001 is an international standard that sets requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). | Certificate for your information security management system | A certification body, accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 for accredited certification | ISO/IEC 27001 readiness — preparation for certification by an independent accredited certification body. |
| HIPAA Security Rule | The HIPAA Security Rule (45 CFR Part 164, Subpart C) is a federal regulation that sets security standards for the electronic protected health information (ePHI) that covered entities and business associates create, receive, maintain, or transmit. | None. There is no official HIPAA certification. | Not applicable. HHS doesn't recognize private certifications; its Office for Civil Rights enforces the rule. | HIPAA Security Rule readiness — risk analysis support, safeguards review, and remediation planning. |
| PCI DSS | PCI DSS, the Payment Card Industry Data Security Standard, is a baseline of technical and operational requirements designed to protect payment account data. The PCI Security Standards Council (PCI SSC) maintains it, and it applies to entities that store, process, or transmit cardholder data or sensitive authentication data, or that could affect the security of the cardholder data environment. | Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ), as your acquirer or the payment brands direct | A PCI SSC-listed QSA Company for a ROC; a listed ASV for external scans; your own organization for an SAQ | PCI DSS readiness — scoping support, gap assessment, and remediation planning before a QSA assessment or self-assessment. |
| CMMC | CMMC, the Cybersecurity Maturity Model Certification program, is a Department of Defense program that verifies how contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). | Self-assessment results in SPRS, or a Certificate of CMMC Status after a Level 2 certification assessment | Your own organization for Level 1 and Level 2 self-assessments; a C3PAO authorized by the Cyber AB for Level 2 certification | CMMC Level 1 and Level 2 readiness — preparation for self-assessment or a certification assessment by an authorized C3PAO. |
Each guide covers the current version, who needs it, who performs the formal assessment, what our readiness work includes and excludes, and published starting prices.
2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Get your controls, evidence, and system description ready for a SOC 2 examination by an independent, licensed CPA firm that you select and engage directly.
ISO/IEC 27001:2022, including Amendment 1:2024
Design and tune an information security management system (ISMS) that's ready for a certification audit by an independent, accredited certification body.
45 CFR Part 164, Subpart C, as last substantively revised in 2013
Risk analysis support, a safeguards review against the HIPAA Security Rule, and a remediation plan, with a clear line between the rule in force and changes HHS has only proposed.
PCI DSS v4.0.1
Scoping support, a gap assessment against PCI DSS v4.0.1, and a remediation plan before your assessment by a PCI SSC-listed QSA Company or your own Self-Assessment Questionnaire.
CMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2
Readiness for CMMC Level 1 and Level 2 against FAR 52.204-21 and NIST SP 800-171 Rev 2, with support for self-assessments and for a certification assessment by an authorized C3PAO if you need one.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Tell us who is asking for evidence and what they’ve asked for. We’ll help you work out which framework and formal outcome fit, and what readiness work would help.