Financial-reporting relevance
Addresses service-organization controls likely to matter to customers' ICFR, including financially significant processing, access, changes, operations, interfaces, and supporting IT controls.
Turn recurring security operations into controls and evidence an independent service auditor can examine for distinct financial-reporting and trust-services audiences.
View the control mappingWhere we contribute
SOC 1 and SOC 2 serve different assurance purposes, and many MSPs, SaaS providers, and technology-dependent service organizations may legitimately need both. Network Box can operate and evidence substantial technical controls, while management defines the system, risks, commitments, objectives or criteria, control design, and assertion for examination by an independent CPA firm.
Assurance positioning
Reviewed September 2, 2026A qualified, independent CPA firm examines management's description of a defined service-organization system and the related controls against the engagement's objectives or criteria, as of a date or throughout a specified period.
Review AICPA's SOC reporting resources ↗Choose the right report
The organization should choose SOC 1, SOC 2, or both based on customer dependencies, user-auditor needs, service commitments, and the risks addressed by each report, not simply which acronym is more familiar.
Addresses service-organization controls likely to matter to customers' ICFR, including financially significant processing, access, changes, operations, interfaces, and supporting IT controls.
Addresses Security and any included Availability, Processing Integrity, Confidentiality, or Privacy criteria relevant to the system and user needs.
Examines whether the system description is fairly presented and controls are suitably designed as of a specified date; it does not cover operating effectiveness over a period.
Also examines whether controls operated effectively throughout the specified period and includes the service auditor's tests and results.
SOC 1 readiness
SOC 1 does not prescribe one universal control catalog. Management defines suitable objectives and controls based on its services and the needs of user entities and user auditors; these are common technology-dependent areas.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Service roles, operating procedures, reporting, reviews, and awareness evidence support the managed-security control environment. | Supporting | ||
Detailed mapping2 mapping notes Establish the organization, competence, accountability, policies, oversight, and management controls necessary to achieve financially relevant control objectives. Network Box contributionSupportingNetwork Box documents managed-service roles, escalation paths, procedures, reports, reviews, and selected workforce security activities. Service organization responsibilityClient responsibilityDefine the complete control environment, ICFR relevance, governance, competence, control owners, oversight, policies, and management assertion. | |||
| Threats, vulnerabilities, incidents, architecture, and service performance provide technical risk inputs. | Partial | ||
Detailed mapping2 mapping notes Identify risks that could prevent controls over financially relevant services, transactions, systems, reports, and dependencies from achieving their objectives. Network Box contributionPartialNetwork Box provides vulnerability findings, incidents, attack patterns, architecture observations, service risks, and managed-control performance information. Service organization responsibilityClient responsibilityIdentify transaction classes, fraud and error risks, customer ICFR dependencies, material changes, subservice organizations, business impact, and suitable control objectives. | |||
| Managed enforcement, segmentation, secure remote access, MFA support, and telemetry restrict and evidence access. | Strong | ||
Detailed mapping2 mapping notes Restrict access to financially relevant systems and data to authorized users and services, with appropriate authentication, privilege, segregation, review, and removal. Network Box contributionStrongNetwork Box controls access to managed systems and network paths, supports authentication integrations, logs activity, and monitors for suspicious access. Service organization responsibilityClient responsibilityGovern identities across financial applications, databases, operating systems, cloud platforms, code repositories, and service accounts; approve and review access; enforce segregation; and remove access promptly. | |||
| Managed firewalls, SD-WAN, VPN, routing, IDS/IPS, gateways, controlled changes, and monitoring protect in-scope environments. | Strong | ||
Detailed mapping2 mapping notes Protect the networks and connections supporting financially relevant services and restrict communication according to authorized business need. Network Box contributionStrongNetwork Box designs and operates managed boundaries, segmentation, connectivity, inspection, policies, configurations, changes, logging, and monitoring. Service organization responsibilityClient responsibilityDefine the in-scope networks and applications, approve traffic, maintain accurate diagrams, secure infrastructure outside scope, review access paths, and remediate exceptions. | |||
| Continuous security and managed-device monitoring can evidence operation and escalation for the security layer. | Partial | ||
Detailed mapping2 mapping notes Operate and monitor the technology processes, jobs, schedules, interfaces, and dependencies that support complete, accurate, and timely financial processing. Network Box contributionPartialNetwork Box monitors managed-service health and security events, raises alerts, records incidents, and escalates failures or suspicious activity within scope. Service organization responsibilityClient responsibilityMonitor application jobs, transaction schedules, databases, middleware, storage, interfaces, capacity, backups, and business operations and resolve failed or incomplete processing. | |||
| Controlled managed-service changes, configurations, updates, implementation records, and rollback evidence support change control. | Partial | ||
Detailed mapping2 mapping notes Authorize, test, approve, deploy, validate, and document changes that could affect financially relevant systems and controls. Network Box contributionPartialNetwork Box controls changes to subscribed services, preserves relevant configuration and change records, updates managed protections, and monitors results. Service organization responsibilityClient responsibilityOperate complete application, infrastructure, database, cloud, code, emergency-change, testing, approval, migration, segregation, and post-implementation processes and assess financial-reporting impact. | |||
| Recurring findings, managed protections, exploit detection, SOC analysis, and reporting support remediation governance. | Partial | ||
Detailed mapping2 mapping notes Identify and correct weaknesses that could affect financially relevant systems, data, availability, or supporting controls. Network Box contributionPartialNetwork Box assesses agreed assets, prioritizes findings, manages its protections, detects attempted exploitation, monitors threats, and provides remediation guidance. Service organization responsibilityClient responsibilityInventory and patch every relevant asset, remediate findings, document risk decisions and exceptions, verify correction, and ensure scanner scope and credentials are complete. | |||
| Secure connectivity, segmentation, gateway controls, WAF, and monitoring protect financially relevant data flows. | Partial | ||
Detailed mapping2 mapping notes Protect interfaces and transmissions supporting financial processing from unauthorized access, modification, loss, duplication, or incomplete transfer. Network Box contributionPartialNetwork Box secures managed network paths, restricts connections, monitors traffic, protects applications, and detects unexpected communications. Service organization responsibilityClient responsibilityDefine all financially relevant interfaces and implement application-level authentication, encryption, sequencing, completeness, accuracy, duplicate, rejection, reconciliation, certificate, and key controls. | |||
| Security controls reduce disruption and unauthorized manipulation but do not establish the accuracy of business transactions. | Supporting | ||
Detailed mapping2 mapping notes Ensure transactions and reports are authorized, complete, accurate, timely, classified correctly, and processed according to defined business rules. Network Box contributionSupportingNetwork and application protection, logging, protected communications, availability observations, and incident detection help defend transaction systems. Service organization responsibilityClient responsibilityDesign and operate controls over authorization, input, calculations, processing, files, interfaces, exceptions, reconciliations, output, correction, accounting treatment, and retention. | |||
| Connected telemetry, correlation, 24/7 review, investigation, escalation, and reporting create recurring security evidence. | Strong | ||
Detailed mapping2 mapping notes Record and review activity capable of affecting financially relevant systems and investigate and resolve unauthorized or anomalous events. Network Box contributionStrongNetwork Box centralizes connected logs, correlates activity, monitors source health, investigates alerts, records actions, and produces reports. Service organization responsibilityClient responsibilityEnable and connect every relevant source, preserve user attribution and time integrity, define review and alert requirements, retain the full examination-period evidence, and cover systems outside scope. | |||
| The SOC detects, validates, investigates, documents, escalates, and supports containment for in-scope security incidents. | Strong | ||
Detailed mapping2 mapping notes Identify, respond to, resolve, and document incidents that could affect control objectives, financial processing, customers, or reporting. Network Box contributionStrongNetwork Box provides continuous detection, triage, investigation, timelines, escalation, documentation, and available response actions. Service organization responsibilityClient responsibilityOwn the enterprise incident process, financial-reporting impact analysis, transaction correction, evidence preservation, customer and auditor communication, legal duties, root cause, recovery, and remediation. | |||
| Managed-service resilience, protected configurations, monitoring, incident support, and recovery procedures protect security functions. | Supporting | ||
Detailed mapping2 mapping notes Recover financially relevant processing, data, configurations, and dependencies within commitments and maintain complete and accurate operations through disruption. Network Box contributionSupportingNetwork Box can monitor and restore its managed security functions, protect relevant managed configurations, and support incidents under the contracted service design. Service organization responsibilityClient responsibilityBack up and recover applications, financial data, databases, infrastructure, keys, and interfaces; define objectives; test restoration and continuity; and address processing backlogs. | |||
| Available service and assurance information supports evaluation of facilities used to deliver managed services. | Supporting | ||
Detailed mapping2 mapping notes Protect facilities, equipment, media, infrastructure, and supporting environments that could affect financially relevant services. Network Box contributionSupportingNetwork Box can provide available information about relevant managed-service facilities, while network controls may reduce consequences of unauthorized physical access. Service organization responsibilityClient responsibilityControl offices, processing sites, equipment, wiring, media, backup locations, visitors, environmental risks, and relevant hosting or colocation providers. | |||
| Contracted scope, responsibilities, controls, performance, incidents, and assurance information support provider oversight. | Partial | ||
Detailed mapping2 mapping notes Identify, evaluate, contract with, monitor, and report on providers whose services or controls are necessary to achieve the control objectives. Network Box contributionPartialNetwork Box can document its services, operational responsibilities, security processes, escalation, evidence, performance, and available assurance information. Service organization responsibilityClient responsibilityInventory providers, assess risk, perform due diligence, negotiate control and audit terms, determine inclusive or carve-out presentation, define CSOCs, monitor reports and performance, and address gaps. | |||
| Technical records can form repeatable evidence populations for controls performed by or with Network Box. | Partial | ||
Detailed mapping2 mapping notes Generate, review, retain, and reconcile complete control evidence and identify, investigate, disclose, and remediate deviations throughout the examination period. Network Box contributionPartialNetwork Box can supply recurring configurations, changes, alerts, investigations, vulnerabilities, incidents, training results, and service reports for the contracted scope. Service organization responsibilityClient responsibilityMap every control to an owner, frequency, population, reviewer, evidence source, retention rule, and objective; preserve complete populations; evaluate deviations; and communicate exceptions to the auditor. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Control mapping
Security and the Common Criteria form the foundation of a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are included only when relevant to commitments, system requirements, risks, and user needs.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Documented roles, qualified security personnel, procedures, awareness, reporting, and accountability support a disciplined environment. | Supporting | ||
Detailed mapping2 mapping notes Establish integrity, ethical values, governance oversight, organizational structure, authority, competence, accountability, and supporting people controls. Network Box contributionSupportingNetwork Box documents its roles, qualified operations, procedures, escalation, awareness activities, reporting, and accountability within the managed service. Service organization responsibilityClient responsibilityOwn governance, ethics, board oversight, organizational design, human-resources controls, competence, authority, and accountability for the complete examined system. | |||
| Alerts, reports, vulnerabilities, incidents, reviews, intelligence, and contact paths provide timely security information. | Partial | ||
Detailed mapping2 mapping notes Obtain, generate, use, and communicate quality information internally and externally so the control system can function and responsibilities are understood. Network Box contributionPartialNetwork Box provides operational dashboards, alerts, incident escalation, findings, service reviews, threat information, and defined contacts for managed controls. Service organization responsibilityClient responsibilityDefine stakeholder needs, system documentation, policies, commitments, internal reporting, customer communication, escalation channels, and communication with providers, regulators, and auditors. | |||
| Threat, vulnerability, incident, architecture, and performance information supplies current technical risk inputs. | Partial | ||
Detailed mapping2 mapping notes Specify suitable objectives, identify and analyze risks, including fraud, change, and provider risk, and determine how those risks should be managed. Network Box contributionPartialNetwork Box identifies technical threats, weaknesses, attack trends, incidents, architecture concerns, and managed-control performance within scope. Service organization responsibilityClient responsibilityDefine objectives and risk tolerance; assess business, fraud, technology, privacy, provider, and change risks; determine likelihood and impact; select treatments; and maintain the enterprise process. | |||
| Continuous telemetry, correlation, source-health monitoring, analyst review, investigations, and reports evaluate security-control operation. | Strong | ||
Detailed mapping2 mapping notes Perform ongoing or separate evaluations, identify control deficiencies, communicate them to responsible parties, and track corrective action. Network Box contributionStrongNetwork Box continuously monitors managed services and connected telemetry, investigates alerts, identifies interrupted sources, produces dashboards, and reviews trends and findings. Service organization responsibilityClient responsibilityMonitor the complete control system, perform management and independent evaluations, assess deficiency severity, communicate issues, remediate promptly, and cover controls outside Network Box scope. | |||
| Managed enforcement, standardized configurations, controlled changes, response procedures, and recurring evidence support selected control activities. | Partial | ||
Detailed mapping2 mapping notes Select and develop control activities through policies and procedures, including technology controls, that mitigate risks to acceptable levels. Network Box contributionPartialNetwork Box operates defined technical policies, configurations, changes, monitoring, and response activities and generates evidence for recurring managed controls. Service organization responsibilityClient responsibilityTranslate all risk responses into appropriately designed business and technology controls with clear owners, approvals, segregation, review, reconciliation, and exception handling. | |||
| Layered network, remote-access, identity-support, application, email, web, endpoint, and monitoring controls restrict access. | Strong | ||
Detailed mapping2 mapping notes Protect information and system resources through logical and physical access restriction, authentication, authorization, encryption, asset handling, and removal controls. Network Box contributionStrongNetwork Box enforces managed network and remote-access policy, supports authentication integrations, protects web and email paths, monitors endpoints and telemetry, and detects unauthorized activity. Service organization responsibilityClient responsibilityOwn identity lifecycle, least privilege, access reviews, privileged and service accounts, endpoints, applications, databases, cloud platforms, cryptography and keys, physical access, media, and disposal. | |||
| Managed prevention, vulnerability monitoring, SIEM, MDR/XDR, and 24/7 investigation detect and respond to anomalies and incidents. | Strong | ||
Detailed mapping2 mapping notes Detect anomalies and security events, evaluate and respond to incidents, recover affected systems, and correct vulnerabilities and deficiencies. Network Box contributionStrongNetwork Box blocks threats, monitors telemetry and vulnerabilities, triages alerts, investigates incidents, escalates findings, supports containment, and records activity. Service organization responsibilityClient responsibilityEnsure complete telemetry, define severity and decision authority, manage enterprise incidents and recovery, remediate every affected system, fulfill notification duties, conduct lessons learned, and operate functions outside scope. | |||
| Controlled changes, secure configurations, managed updates, implementation records, and monitored results support service change control. | Partial | ||
Detailed mapping2 mapping notes Authorize, design, develop or acquire, configure, test, approve, deploy, and monitor changes to infrastructure, data, software, procedures, and services. Network Box contributionPartialNetwork Box controls changes to its subscribed services, retains relevant history, manages security updates, and monitors results within the service scope. Service organization responsibilityClient responsibilityOperate complete application, infrastructure, cloud, database, code, vendor, and emergency-change processes; enforce segregation; protect development environments; test and approve changes; and assess security impact. | |||
| Layered defenses, vulnerability reduction, monitoring, response, intelligence, and provider information help reduce technology risk. | Partial | ||
Detailed mapping2 mapping notes Identify and select risk-mitigation activities, including those addressing business disruption and the use of vendors and business partners. Network Box contributionPartialNetwork Box operates managed safeguards, reduces exposures, monitors threats, responds to events, and documents its services and dependencies. Service organization responsibilityClient responsibilitySelect enterprise risk responses; manage business disruption, insurance, fraud, acquisitions, concentration, emerging technology, subservice organizations, and other risks; perform due diligence; and monitor third parties. | |||
| Health monitoring, resilient security options, SD-WAN controls, attack prevention, alerting, response, and restoration support commitments. | Partial | ||
Detailed mapping2 mapping notes Design and operate controls supporting the availability commitments and system requirements included in the engagement. Network Box contributionPartialNetwork Box monitors managed security and connectivity, supports resilient designs where contracted, prevents attacks, escalates outages, and restores managed functions. Service organization responsibilityClient responsibilityDefine measurable commitments and design resilient applications, infrastructure, cloud, power, capacity, backups, continuity, disaster recovery, and vendor arrangements; test recovery and address exceptions. | |||
| Protected communications, WAF, threat prevention, logging, and monitoring reduce unauthorized processing disruption or manipulation. | Supporting | ||
Detailed mapping2 mapping notes Ensure system processing is complete, valid, accurate, timely, and authorized in accordance with commitments and requirements. Network Box contributionSupportingNetwork Box can defend processing systems, monitor activity, protect interfaces, and detect attacks or anomalous behavior within scope. Service organization responsibilityClient responsibilityOwn input, calculation, interface, queue, rejection, duplicate, reconciliation, output, correction, authorization, timeliness, and quality controls; security telemetry alone does not prove processing integrity. | |||
| Segmentation, access restriction, secure connectivity, gateways, WAF, monitoring, and incident response protect designated information. | Partial | ||
Detailed mapping2 mapping notes Protect information designated as confidential from collection or creation through use, retention, disclosure, and disposal according to commitments and requirements. Network Box contributionPartialNetwork Box controls access paths, secures managed transmissions, protects web and email channels, detects unauthorized activity, and supports incident response. Service organization responsibilityClient responsibilityClassify confidential information, minimize collection and retention, govern access and disclosure, implement encryption and key management at rest and across all paths, and control applications, databases, backups, media, disposal, and providers. | |||
| Access, secure transmission, monitoring, response, email/web protection, awareness, and evidence support selected safeguards for personal information. | Supporting | ||
Detailed mapping2 mapping notes Collect, use, retain, disclose, and dispose of personal information and provide notice, choice, access, and other handling consistent with commitments and applicable privacy criteria. Network Box contributionSupportingNetwork Box can operate selected technical safeguards, monitor for unauthorized access or disclosure, support incidents, train users, and provide evidence within scope. Service organization responsibilityClient responsibilityDefine privacy commitments and applicable law; govern notices, consent, collection, use, retention, disclosure, access, correction, disposal, requests, transfers, processors, complaints, and breach decisions; SOC 2 does not replace legal analysis. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
System description and scope
Management must accurately describe covered services, commitments and requirements, boundaries, infrastructure, software, people, procedures, data, material changes, relevant incidents, subservice organizations, complementary controls, and exclusions. Network Box can document its managed architecture and operations, but contracts, policies, diagrams, auditor narratives, marketing claims, and operational reality must agree.
Complementary controls
A control can appear well designed yet fail if a required customer or subservice-organization activity is vague, missing, outside the report period, or unsupported by evidence.
Complementary user-entity controls should identify specific customer activities necessary to achieve objectives or criteria, rather than operate as generic disclaimers.
Complementary subservice-organization controls identify provider controls assumed necessary when relevant services are not fully included in the examination.
Relevant provider systems and controls are included in the description and examination, requiring advance coordination and sufficient evidence for auditor testing.
Relevant provider services are described while detailed provider controls are excluded; management must monitor the provider and support its assertion about assumed controls.
Review legal entity, services, products, locations, infrastructure, period, opinion, tests, deviations, CUECs, CSOCs, providers, changes, and subsequent events.
A management-issued bridge letter may describe post-period changes, but it is not an independent auditor opinion or an automatic substitute for a current Type 2 report.
Assessment evidence
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
Coverage key
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
Service-organization management owns report selection, the system description and boundaries, SOC 1 control objectives, SOC 2 categories and criteria, control design and ownership, evidence populations, CUECs and CSOCs, subservice-organization treatment, management assertion, exception handling, remediation, restricted distribution, and the independent CPA relationship.
SOC I and II FAQ
Turn recurring security operations into controls and evidence an independent service auditor can examine for distinct financial-reporting and trust-services audiences.
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable SOC I and II requirements.
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
Service-organization management owns report selection, the system description and boundaries, SOC 1 control objectives, SOC 2 categories and criteria, control design and ownership, evidence populations, CUECs and CSOCs, subservice-organization treatment, management assertion, exception handling, remediation, restricted distribution, and the independent CPA relationship.
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.
Security stack review