Hello all,
I have an answering service company that handles sensitive data. They had a vendor assessment sent their way from a customer and in some footnotes, it said if they had a SOC, HITRUST, SSAE16 etc compliance, they didn’t have to fill this assessment out.
I have done some digging and found that there are different types of SOC, but clarification would be great.
SOC 1 is for financial companies (like a CPA?) SOC 2 is for hosting services SOC 3 ?
Each have a type associated as well.
TYPE 1 - is the current state TYPE 2 - is taken over 6-12 months and is working and future state TYPE 3 - ?
I am also looking to understand what SOC they need and where to start? And suggestions on providers for these services would be great. Do we start with asking for a SOC assessment from some governing body? Or go through a SOC readiness service to prepare for an audit? How important or how much weight would it hold for an answering service? How much weight will it hold in the next 5 years?
Thanks
submitted by [comments]
SOCIAL SHARE CARD GENERATOR