SOC Engagements, Service Auditor Reporting, and Cybersecurity Assurance

ISC SOC coverage for engagement types, SOC 1, SOC 2, planning, reporting, and cybersecurity examinations.

This part is the most assurance-specific segment of ISC. The chapters explain how SOC engagements are scoped, performed, and reported, and how the different report types serve different user needs.

In This Part

How to Use This Part

  • Read this part after Parts I through IV so the system and control background is already in place.
  • Pay attention to the purpose, users, and reporting consequences of each engagement type.
  • Return here whenever an ISC question turns on which SOC framework or report is appropriate.

In this section

Revised on Friday, April 24, 2026