SOC 2 and Compliance Reporting Editing and Proofreading Services

Three parties have an interest in a SOC 2 report, and each wants something different from it. The company writes the report about itself and would like its controls to sound impressive. The auditor will attest only to what the company actually does. The customer, usually a security reviewer working through fifty reports, wants to find the exceptions and the complementary user entity controls and then move on. A report written to satisfy the first of those readers satisfies none of them, and it slows the sales it was produced to speed up.

The documents we edit for SOC 2 and Compliance Reporting

System descriptions for SOC 2 and SOC 1, control descriptions mapped to the trust services criteria, management assertions, and complementary user entity control statements make up most of what we are sent. Subservice organization descriptions and carve-out disclosures, exception and management response text, ISO 27001 statements of applicability, information security policies and procedures, and risk assessment and treatment documentation follow closely behind. Business continuity and incident response plans, vendor and third-party risk assessments, customer security questionnaires, trust center content, and readiness and remediation plans complete the set. Our editors check that a control described in the report is described the way it is actually operated, because anything else is a finding waiting to happen.

What the editing involves

The system description is the section that does the real work, and it is the one most often filled in from a template. It has to tell a reader what the system is, what it does, who operates it, where its boundaries fall, and which controls the customer is responsible for. A description reading "the Company provides a cloud-based platform for enterprise customers" could belong to any of the fifty reports on the reviewer's desk, and a reviewer unable to tell which product is in scope cannot rely on anything that follows. The boundary is worth stating in both directions: the products, environments, and regions covered by the examination, and the ones excluded from it.

Subservice organizations belong in the description by name, with a statement of whether each is carved out or included, and a note on what the reader must then verify elsewhere. Complementary user entity controls read better as instructions the customer has to carry out, such as enforcing multi-factor authentication on its own administrator accounts, than as a paragraph of disclaimer. An exception is best written as a fact with a date attached, such as a control that failed on three occasions between March and June, with the management response saying what changed, when, and who performs the control now. Companies fear that a specific description invites scrutiny, while security reviewers read a vague one as evasion and escalate it to a questionnaire, which costs more of the company's time than the specific version would have.

Confidentiality and the limits of our role

Everything you send us is treated in strict confidence, including draft reports, exceptions, and internal policies. We are editors, not auditors or security assessors, and nothing we produce is an assurance opinion or compliance advice. Your service auditor and your advisors remain responsible for that. What we can do is make the documents accurate, specific, and quick for a reviewer to work through.

Key SOC 2 and Compliance Reporting vocabulary

SOC 2 and Compliance Reporting Word Challenge

Even seasoned pros miss these — give it a shot.

Get a Free Estimate

« More Finance, Banking and Investment editing  |  All editing services