Skip to content
FAQ

Questions, answered.

Everything a first-time buyer needs to know about SOC audits, what DES does, how billing works, and how long it all takes — in plain English. Still unsure about something? A 30-minute call clears up the rest.

Start here

New to SOC compliance

What is a SOC audit, in plain English?

SOC stands for System and Organization Controls — a set of audit frameworks created by the AICPA (the body that governs CPAs in the US). In a SOC audit, an independent licensed CPA firm examines the controls your company uses to protect the data and processes your customers rely on, then issues a formal report your customers can trust.

In practice, it usually starts like this: a large customer or prospect says "we need your SOC report" before they'll sign or renew. The report is how you prove — once, credibly, in a format their auditors and security teams accept — that your company does what it says it does. Instead of filling out a different security questionnaire for every customer, you hand over one report.

SOC 1 vs SOC 2 — which one do I need?

It comes down to what your service touches:

  • SOC 1 is about your customers' financial reporting. If the numbers you process end up in your clients' financial statements — payroll, billing, claims processing, fund administration, loan servicing — their auditors will want a SOC 1.
  • SOC 2 is about data security and operations. If you store or process customer data — SaaS platforms, cloud services, managed IT — their security and procurement teams will want a SOC 2.

Some companies need both. If you're not sure, that's exactly what the first call is for — we'll tell you which report (and which type) your customers are actually asking for, at no cost. Full AICPA-level detail on each is in the "The reports, in depth" section below.

What's the difference between Type 1 and Type 2?

Both SOC 1 and SOC 2 come in two types:

  • Type 1 looks at your controls at a single point in time — are they suitably designed and in place today?
  • Type 2 covers a period of time (commonly 3–12 months) and tests whether your controls actually operated effectively throughout it.

Most customers ultimately want a Type 2, because it proves your controls work over time rather than on one good day. A common first-year path is a Type 1 to get a report in customers' hands quickly, then a Type 2 covering the following period. We'll recommend the sequence that fits your deadlines.

We're not ready for an audit. Is that a problem?

No — it's the normal starting point. Most first-time clients aren't audit-ready, and our process is built for that. We begin with a readiness assessment: a customized set of controls mapped to the SOC requirements that shows exactly where you stand and what's missing. Then, during gap remediation, we provide the plan, templates, and examples to close those gaps efficiently — before the audit ever starts.

You don't need to arrive prepared. You need to arrive. The eight-step process shows how we take you from "where do we even start" to a finished report.

About DES

What DES is — and isn't

What exactly is DES?

DES is a licensed CPA firm, founded in 2013 by veterans of large CPA firms who believed the SOC process could be faster, clearer, and more affordable. We perform the full journey ourselves: readiness assessments, gap remediation guidance, the SOC examination, and the final report — with CPAs, CISAs, and CIAs on staff.

We're family owned, and the work is never outsourced: the team you meet on the first call is the team on your engagement. Because SOC reports can only be issued by a licensed CPA firm, the report you hand your customers comes from us directly — not a partner firm you've never met.

What is DES not?

Knowing what we're not matters just as much:

  • Not a software company. Fieldguide (the compliance platform included with every engagement) is a tool we provide — our product is the audit and the expertise behind it.
  • Not a broker. The team you meet on the first call is the licensed CPA firm that performs your examination and signs your report — never a handoff to a firm you've never met.
  • Not a checkbox factory. We don't run thousands of clients through a template. Each engagement is scoped to your actual environment — that's the "Better Compliance Experience."
  • Not an outsourcing shop. No offshore review teams, no rotating strangers. Real people you can name, for the life of the engagement.
Do I need to buy compliance software (Drata, Vanta, etc.) first?

No. This surprises people: a GRC platform is normally its own five-figure annual subscription that companies buy before ever paying for the audit itself. Every DES engagement includes Fieldguide — the modern audit and compliance platform — and we pay for the subscription. Requests, evidence, progress, and communication all live there, and your access is year-round, not just during audit season.

Already invested in another platform? That's fine too — we work with clients on OneTrust, Drata, Hyperproof, Secureframe, Vanta, and others. See the Technology page for what's included.

Cost & timeline

Billing and how long it takes

How does billing work?

Simply. After the first call — where we scope your environment, frameworks, and deadlines — you get a fair, flat quote for the engagement. No hourly meters running in the background, no surprise line items at the end.

  • One quote covers the engagement — readiness through final report, as scoped.
  • Your Fieldguide subscription is included — we pay it, so there's no separate software bill.
  • 100% Risk-Free engagement — we stand behind the outcome we scope with you.

The scoping call itself is free, and the quote is transparent — you'll know exactly what you're paying for before you commit to anything.

How long does a SOC audit take?

Honest answer: it depends on your environment — and anyone who quotes a fixed number before looking at it is guessing. The main variables:

  • How mature your controls are today — a company with policies and processes in place moves much faster than one starting from scratch.
  • Type 1 vs Type 2 — a Type 2 report includes an observation window (commonly 3–12 months) that a Type 1 doesn't.
  • How quickly evidence comes back — responsive teams (helped a lot by Fieldguide's automated collection) compress the calendar dramatically.
  • Scope — number of frameworks, locations, and systems in play.
On the first call we'll map your environment against engagements like yours and give you a realistic timeline range — plus the fastest sequence to get a report into your customers' hands.
Is this a one-time thing, or every year?

SOC reports cover a period, so customers expect a fresh report annually. The good news: year one is the hard one. After that, your controls exist, your evidence largely re-collects itself through Fieldguide's integrations, and renewals become maintenance instead of a project.

That's also why your Fieldguide access is year-round — between audits you can monitor progress, manage tasks, upload evidence as it's generated, and stay connected with our team, so the next report never sneaks up on you.

The reports, in depth

SOC 1 and SOC 2, per the AICPA

SOC 1, in depth

A SOC 1 examination is performed under the AICPA's attestation standards (SSAE No. 18) and reports on controls at a service organization that are relevant to user entities' internal control over financial reporting (ICFR). Translation: if your service affects the numbers in your clients' books, SOC 1 is how their auditors get comfort over your part of the chain.

The report includes management's description of your system, your control objectives and the controls that meet them, and the independent auditor's opinion — plus, in a Type 2, the tests performed and their results over the review period. It's a restricted-use report: intended for your clients' management and their financial statement auditors, not the general public.

Who typically needs one: payroll processors, billing and claims administrators, third-party administrators (TPAs), fund administrators, loan servicers, and any service whose output flows into clients' financial statements.

SOC 2, in depth

A SOC 2 examination reports on a service organization's controls against the AICPA's Trust Services Criteria. There are five categories: Security (required in every SOC 2 — the "common criteria"), plus Availability, Processing Integrity, Confidentiality, and Privacy, which are included based on the commitments you make to customers. Part of scoping is choosing the categories that match what your customers actually need — more isn't automatically better.

The report contains management's description of the system (boundaries, infrastructure, people, processes, data), the auditor's opinion on whether controls were suitably designed (Type 1) and operating effectively over the period (Type 2), and the detailed tests and results. Like SOC 1, it's a restricted-use report for customers and their stakeholders evaluating you as a vendor.

Who typically needs one: SaaS and cloud providers, data centers, MSPs, and any technology vendor that stores or processes customer data — it's the report enterprise security and procurement teams ask for by name.

Who's allowed to perform a SOC audit?

Only a licensed, independent CPA firm can perform a SOC examination and issue the report — it's an attestation engagement governed by AICPA professional standards, independence requirements, and peer review. Consultants and software platforms can help you prepare, but they cannot issue the report your customers are asking for.

That's why it matters who you choose: your customers will rely on the auditor's opinion, so the firm signing it should be one you actually know — independent, accountable, and with you for the life of the engagement.

Still have questions?

Ask a person, not a page.

Thirty minutes, no obligation, no pressure — just clear answers about your situation and a fair, flat quote if you want one.

Book a Call