CPA assurance reportsUnited States

SOC 1 and SOC 2 Assurance Readiness

Turn recurring security operations into controls and evidence an independent service auditor can examine for distinct financial-reporting and trust-services audiences.

View the control mapping

Where we contribute

A managed security layer within a broader compliance program.

SOC 1 and SOC 2 serve different assurance purposes, and many MSPs, SaaS providers, and technology-dependent service organizations may legitimately need both. Network Box can operate and evidence substantial technical controls, while management defines the system, risks, commitments, objectives or criteria, control design, and assertion for examination by an independent CPA firm.

Assurance positioning

Reviewed September 2, 2026

SOC 1 and SOC 2 are examination reports, not certifications.

A qualified, independent CPA firm examines management's description of a defined service-organization system and the related controls against the engagement's objectives or criteria, as of a date or throughout a specified period.

Review AICPA's SOC reporting resources ↗
  • SOC 1 addresses controls likely to be relevant to user entities' internal control over financial reporting.
  • SOC 2 addresses controls relevant to security, availability, processing integrity, confidentiality, or privacy.
  • A SOC 2 report does not replace a SOC 1 report when customers and their financial-statement auditors need ICFR-focused assurance.
  • The reports can cover related systems but may have different boundaries, periods, controls, provider treatments, and exceptions.
  • Management makes the assertion and owns the controls; the independent service auditor performs the attestation examination and issues the report.

Choose the right report

Different audiences need different assurance.

The organization should choose SOC 1, SOC 2, or both based on customer dependencies, user-auditor needs, service commitments, and the risks addressed by each report, not simply which acronym is more familiar.

SOC 1

Financial-reporting relevance

Addresses service-organization controls likely to matter to customers' ICFR, including financially significant processing, access, changes, operations, interfaces, and supporting IT controls.

SOC 2

Trust services controls

Addresses Security and any included Availability, Processing Integrity, Confidentiality, or Privacy criteria relevant to the system and user needs.

Type 1

Design at a specified date

Examines whether the system description is fairly presented and controls are suitably designed as of a specified date; it does not cover operating effectiveness over a period.

Type 2

Operation throughout a period

Also examines whether controls operated effectively throughout the specified period and includes the service auditor's tests and results.

SOC 1 readiness

Protect financially relevant services and dependencies.

SOC 1 does not prescribe one universal control catalog. Management defines suitable objectives and controls based on its services and the needs of user entities and user auditors; these are common technology-dependent areas.

Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Service roles, operating procedures, reporting, reviews, and awareness evidence support the managed-security control environment.
Service documentationOperating proceduresSecurity reportingService reviewsSecurity Awareness Training
Supporting
Threats, vulnerabilities, incidents, architecture, and service performance provide technical risk inputs.
Vulnerability ManagementThreat intelligenceSIEMNBX: MDR, EDR, XDRSecurity reviews
Partial
Managed enforcement, segmentation, secure remote access, MFA support, and telemetry restrict and evidence access.
UTM+Network segmentationVPNMFA/TOTP supportDirectory integrationManaged administrative accessSIEM
Strong
Managed firewalls, SD-WAN, VPN, routing, IDS/IPS, gateways, controlled changes, and monitoring protect in-scope environments.
UTM+FirewallsSecure SD-WANVPNNetwork segmentationIDS/IPSSecure Web Gateway24/7 SOC
Strong
Continuous security and managed-device monitoring can evidence operation and escalation for the security layer.
24/7 SOCManaged-device healthAvailability observationsAlertingIncident tickets
Partial
Controlled managed-service changes, configurations, updates, implementation records, and rollback evidence support change control.
Managed change controlConfiguration recordsSecurity updatesChange historyMonitoring
Partial
Recurring findings, managed protections, exploit detection, SOC analysis, and reporting support remediation governance.
Vulnerability ManagementWAFIDS/IPSNBX: MDR, EDR, XDR24/7 SOCSecurity reporting
Partial
Secure connectivity, segmentation, gateway controls, WAF, and monitoring protect financially relevant data flows.
VPNNetwork segmentationSecure SD-WANSecure Web GatewayWAFSIEM
Partial
Security controls reduce disruption and unauthorized manipulation but do not establish the accuracy of business transactions.
WAFNetwork controlsSIEMNBX: MDR, EDR, XDRAvailability monitoring
Supporting
Connected telemetry, correlation, 24/7 review, investigation, escalation, and reporting create recurring security evidence.
SIEMNBX: MDR, EDR, XDRManaged-device logging24/7 SOCCorrelationSecurity reporting
Strong
The SOC detects, validates, investigates, documents, escalates, and supports containment for in-scope security incidents.
24/7 SOCSIEMNBX: MDR, EDR, XDRIncident investigationContainment assistanceIncident reporting
Strong
Managed-service resilience, protected configurations, monitoring, incident support, and recovery procedures protect security functions.
Managed-service monitoringConfiguration protectionIncident responseService restoration supportResilient service options
Supporting
Available service and assurance information supports evaluation of facilities used to deliver managed services.
Service documentationAssurance documentationNetwork segmentationRemote monitoring
Supporting
Contracted scope, responsibilities, controls, performance, incidents, and assurance information support provider oversight.
Service documentationResponsibility assignmentsSecurity reportingService reviewsAssurance documentation
Partial
Technical records can form repeatable evidence populations for controls performed by or with Network Box.
ConfigurationsChange recordsLogsIncident recordsVulnerability findingsTraining metricsService reports
Partial

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Control mapping

SOC 2 Common Criteria and additional categories.

Security and the Common Criteria form the foundation of a SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are included only when relevant to commitments, system requirements, risks, and user needs.

Authoritative sourceAICPA System and Organization Controls suite ↗
Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Documented roles, qualified security personnel, procedures, awareness, reporting, and accountability support a disciplined environment.
Service documentation24/7 SOCOperating proceduresSecurity Awareness TrainingSecurity reporting
Supporting
Alerts, reports, vulnerabilities, incidents, reviews, intelligence, and contact paths provide timely security information.
Security reportingSIEM dashboardsIncident notificationsVulnerability reportsService reviewsThreat intelligence
Partial
Threat, vulnerability, incident, architecture, and performance information supplies current technical risk inputs.
Threat intelligenceVulnerability ManagementSIEMNBX: MDR, EDR, XDRSecurity reviews
Partial
Continuous telemetry, correlation, source-health monitoring, analyst review, investigations, and reports evaluate security-control operation.
SIEMNBX: MDR, EDR, XDR24/7 SOCLog-source monitoringDashboardsService reviews
Strong
Managed enforcement, standardized configurations, controlled changes, response procedures, and recurring evidence support selected control activities.
Managed security policiesTechnical enforcementSecure configurationsChange recordsResponse procedures
Partial
Layered network, remote-access, identity-support, application, email, web, endpoint, and monitoring controls restrict access.
UTM+Network segmentationVPNMFA/TOTP supportDirectory integrationSecure Web GatewayWAFNBX: MDR, EDR, XDRSIEM
Strong
Managed prevention, vulnerability monitoring, SIEM, MDR/XDR, and 24/7 investigation detect and respond to anomalies and incidents.
UTM+IDS/IPSVulnerability ManagementSIEMNBX: MDR, EDR, XDR24/7 SOCIncident response
Strong
Controlled changes, secure configurations, managed updates, implementation records, and monitored results support service change control.
Managed change controlConfiguration recordsSecurity updatesChange historyMonitoring
Partial
Layered defenses, vulnerability reduction, monitoring, response, intelligence, and provider information help reduce technology risk.
UTM+Secure SD-WANVulnerability ManagementThreat intelligenceSIEMNBX: MDR, EDR, XDRService documentation
Partial
Health monitoring, resilient security options, SD-WAN controls, attack prevention, alerting, response, and restoration support commitments.
Managed-service monitoringSecure SD-WANResilient service optionsAttack prevention24/7 SOCService restoration support
Partial
Protected communications, WAF, threat prevention, logging, and monitoring reduce unauthorized processing disruption or manipulation.
WAFNetwork controlsSecure connectivitySIEMNBX: MDR, EDR, XDR
Supporting
Segmentation, access restriction, secure connectivity, gateways, WAF, monitoring, and incident response protect designated information.
UTM+Network segmentationVPNSecure Web GatewayWAFManaged Cloud Email SecuritySIEMNBX: MDR, EDR, XDR
Partial
Access, secure transmission, monitoring, response, email/web protection, awareness, and evidence support selected safeguards for personal information.
Access controlsSecure connectivityManaged Cloud Email SecuritySecure Web GatewaySIEMNBX: MDR, EDR, XDRSecurity Awareness Training
Supporting

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

System description and scope

Describe the system that actually operated, not a desired future state.

Management must accurately describe covered services, commitments and requirements, boundaries, infrastructure, software, people, procedures, data, material changes, relevant incidents, subservice organizations, complementary controls, and exclusions. Network Box can document its managed architecture and operations, but contracts, policies, diagrams, auditor narratives, marketing claims, and operational reality must agree.

Complementary controls

Make every customer and provider dependency explicit.

A control can appear well designed yet fail if a required customer or subservice-organization activity is vague, missing, outside the report period, or unsupported by evidence.

01

CUECs

Complementary user-entity controls should identify specific customer activities necessary to achieve objectives or criteria, rather than operate as generic disclaimers.

02

CSOCs

Complementary subservice-organization controls identify provider controls assumed necessary when relevant services are not fully included in the examination.

03

Inclusive method

Relevant provider systems and controls are included in the description and examination, requiring advance coordination and sufficient evidence for auditor testing.

04

Carve-out method

Relevant provider services are described while detailed provider controls are excluded; management must monitor the provider and support its assertion about assumed controls.

05

Report coverage

Review legal entity, services, products, locations, infrastructure, period, opinion, tests, deviations, CUECs, CSOCs, providers, changes, and subsequent events.

06

Bridge information

A management-issued bridge letter may describe post-period changes, but it is not an independent auditor opinion or an automatic substitute for a current Type 2 report.

Assessment evidence

Show that safeguards are operating.

Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.

  1. 01Service descriptions, scope documents, architecture information, and responsibility assignments
  2. 02Inventories of managed devices, services, protected endpoints, and connected log sources
  3. 03Network diagrams and descriptions of managed boundaries and segmentation
  4. 04Firewall, VPN, SD-WAN, IDS/IPS, secure web, email, WAF, and remote-access policies
  5. 05Managed secure-configuration records and configuration-review information
  6. 06Change tickets, approvals, implementation records, and managed change history
  7. 07Administrative accounts, authentication, MFA, and access-review evidence for managed services
  8. 08Centralized logs, source health, time synchronization, searches, dashboards, and reports
  9. 09SOC alerts, investigations, escalations, incident tickets, timelines, and containment records
  10. 10Vulnerability findings, authenticated-scan details, risk priorities, trends, recommendations, and rescans
  11. 11Malware, phishing, email, web, endpoint, identity, network, and application-security events
  12. 12WAF and IDS/IPS coverage, detections, blocks, policy changes, and update information
  13. 13Security-awareness participation, campaign results, and phishing-simulation metrics
  14. 14Service availability, monitoring, escalation, performance, and restoration information
  15. 15Operational reviews, complete evidence populations, exceptions, remediation, and management reports
  16. 16Incident-response procedures, contact paths, exercise support, and post-incident documentation
  17. 17Available independent-assurance and bridge information where applicable

Coverage key

What each label means.

Strong

Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.

Partial

Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.

Supporting

Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.

Client responsibility

This area primarily remains with the MSP and client, their assessors, or other qualified parties.

Shared responsibility

Network Box helps operate the controls. The organization owns the compliance program.

Service-organization management owns report selection, the system description and boundaries, SOC 1 control objectives, SOC 2 categories and criteria, control design and ownership, evidence populations, CUECs and CSOCs, subservice-organization treatment, management assertion, exception handling, remediation, restricted distribution, and the independent CPA relationship.

SOC I and II FAQ

Questions about scope, evidence, and responsibility.

What is SOC I and II?

Turn recurring security operations into controls and evidence an independent service auditor can examine for distinct financial-reporting and trust-services audiences.

How can Network Box USA support SOC I and II?

Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable SOC I and II requirements.

Does using Network Box USA make an organization SOC I and II compliant?

No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.

How should the SOC I and II control mapping be used?

Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.

What evidence may be available for a SOC I and II assessment?

Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.

What remains the organization's responsibility under SOC I and II?

Service-organization management owns report selection, the system description and boundaries, SOC 1 control objectives, SOC 2 categories and criteria, control design and ownership, evidence populations, CUECs and CSOCs, subservice-organization treatment, management assertion, exception handling, remediation, restricted distribution, and the independent CPA relationship.

Explore another frameworkReturn to the Compliance Center →

Security stack review

Map the technical foundation before the assessment starts.

Request a Security Stack Review